I. THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
II. IT IS MY LEGAL DUTY TO SAFEGUARD YOUR PROTECTED HEALTH INFORMATION (PHI). By law I am required to ensure that your PHI is kept private. The PHI constitutes information created or noted by me that can be used to identify you. It contains data about your past, present, or future health or condition, the provision of health care services to you, or the payment for such health care. I am required to provide you with this Notice about my privacy procedures. This Notice must explain when, why, and how I would use and/or disclose your PHI. Use of PHI means when I share, apply, utilize, examine, or analyze information within my practice; PHI is disclosed when I release, transfer, give, or otherwise reveal it to a third party outside my practice. With some exceptions, I may not use or disclose more of your PHI than is necessary to accomplish the purpose for which the use or disclosure is made; however, I am always legally required to follow the privacy practices described in this Notice.
Please note that I reserve the right to change the terms of this Notice and my privacy policies at any time as permitted by law. Any changes will apply to PHI already on file with me. Before I make any important changes to my policies, I will immediately change this Notice and post a new copy of it in my office and on my website.You may also request a copy of this Notice from me, or you can view a copy of it in my office or on my website, which is located at www.jeannecarusomft.com.
III. HOW I WILL USE AND DISCLOSE YOUR PHI. I will use and disclose your PHI for many different reasons. Some of the uses or disclosures will require your prior written authorization; others, however, will not. Below you will find the different categories of my uses and disclosures, with some examples.
A. Uses and Disclosures Related to Treatment, Payment, or Health Care Operations Do Not Require Your Prior Written Consent. I may use and disclose your PHI without your consent for the following reasons:
B. Certain Other Uses and Disclosures Do Not Require Your Consent. I may use and/or disclose your PHI without your consent or authorization for the following reasons:
PLEASE NOTE: The above list is not an exhaustive list, but informs you of most circumstances when disclosures without your written authorization may be made. Other uses and disclosures will generally (but not always) be made only with your written authorization, even though federal privacy regulations or state law may allow additional uses or disclosures without your written authorization. Uses or disclosures made with your written authorization will be limited in scope to the information specified in the authorization form, which must identify the information “in a specific and meaningful fashion.” You may revoke your written authorization at any time, provided that the revocation is in writing and except to the extent that I have taken action in reliance on your written authorization. Your right to revoke an authorization is also limited if the authorization was obtained as a condition of obtaining insurance coverage for you. If state law protects your confidentiality or privacy more than the federal “Privacy Rule” does, or if state law gives you greater rights than the federal rule does with respect to access to your records, I will abide by state law. In general, uses or disclosures by me of your PHI (without your authorization) will be limited to the minimum necessary to accomplish the intended purpose of the use or disclosure. Similarly, when I request your PHI from another healthcare provider, health plan or health care clearinghouse, I will make an effort to limit the information requested to the minimum necessary to accomplish the intended purpose of the request. As mentioned above, in the section dealing with uses or disclosures for treatment purposes, the “minimum necessary” standard does not apply to disclosures to or requests by a healthcare provider for treatment purposes because healthcare providers need complete access to information in order to provide quality care.
C. Certain Uses and Disclosures Require You to Have the Opportunity to Object. I may provide your PHI to a family member, friend, or other individual who you indicate is involved in your care or responsible for the payment for your health care, unless you object in whole or in part. Retroactive consent may be obtained in emergency situations.
D. Other Uses and Disclosures Require Your Prior Written Authorization. In any other situation not described in Sections IIIA, IIIB, and IIIC above, I will request your written authorization before using or disclosing any of your PHI. Even if you have signed an authorization to disclose your PHI, you may later revoke that authorization, in writing, to stop any future uses and disclosures (assuming that I haven't taken any action subsequent to the original authorization) of your PHI by me.
IV. WHAT RIGHTS YOU HAVE REGARDING YOUR PHI. These are your rights with respect to your PHI:
A. The Right to See and Get Copies of Your PHI. In general, you have the right to see your PHI that is in my possession, or to get copies of it; however, you must request it in writing. If I do not have your PHI, but I know who does, I will advise you how you can get it. You will receive a response from me within 30 days of my receiving your written request. Under certain circumstances, I may feel I must deny your request, but if I do, I will give you, in writing, the reasons for the denial. I will also explain your right to have my denial reviewed. If you ask for copies of your PHI, I will charge you not more than $.25 per page. I may see fit to provide you with a summary or explanation of the PHI, but only if you agree to it, as well as to the cost, in advance.
B. The Right to Request Limits on Uses and Disclosures of Your PHI. You have the right to ask that I limit how I use and disclose your PHI. While I will consider your request, I am not legally bound to agree. If I do agree to your request, I will put those limits in writing and abide by them except in emergency situations. You do not have the right to limit the uses and disclosures that I am legally required or permitted to make.
C. The Right to Choose How I Send Your PHI to You. It is your right to ask that your PHI be sent to you at an alternate address (for example, sending information to your work address rather than your home address) or by an alternate method (for example, via e-mail instead of by regular mail). I am obliged to agree to your request providing that I can give you the PHI, in the format you requested, without undue inconvenience. I may not require an explanation from you as to the basis of your request as a condition of providing communications on a confidential basis.
D. The Right to Get a List of the Disclosures I Have Made. You are entitled to a list of disclosures of your PHI that I have made. The list will not include uses or disclosures to which you have already consented, i.e., those for treatment, payment, or health care operations, sent directly to you, or to your family; neither will the list include disclosures made for national security purposes, to corrections or law enforcement personnel, or disclosures made before April 15, 2003. After April 15, 2003, disclosure records will be held for six years. I will respond to your request for an accounting of disclosures within 60 days of receiving your request. The list I give you will include disclosures made in the previous six years unless you indicate a shorter period. The list will include the date of the disclosure, to whom PHI was disclosed (including their address, if known), a description of the information disclosed, and the reason for the disclosure. I will provide the list to you at no cost, unless you make more than one request in the same year, in which case I will charge you a reasonable sum based on a set fee for each additional request.
E. The Right to Amend Your PHI. If you believe that there is some error in your PHI or that important information has been omitted, it is your right to request that I correct the existing information or add the missing information. Your request and the reason for the request must be made in writing. You will receive a response within 60 days of my receipt of your request. I may deny your request, in writing, if I find that: the PHI is (a) correct and complete, (b) forbidden to be disclosed, (c) not part of my records, or (d) written by someone other than me. My denial must be in writing and must state the reasons for the denial. It must also explain your right to file a written statement objecting to the denial. If you do not file a written objection, you still have the right to ask that your request and my denial be attached to any future disclosures of your PHI. If I approve your request, I will make the change(s) to your PHI. Additionally, I will tell you that the changes have been made, and I will advise all others who need to know about the change(s) to your PHI.
F. The Right to Get This Notice by Email. You have the right to get this Notice by email. You have the right to request a paper copy of it, as well.
V. HOW TO COMPLAIN ABOUT MY PRIVACY PRACTICES. If, in your opinion, I may have violated your privacy rights, or if you object to a decision I made about access to your PHI, you are entitled to file a complaint with the person listed in Section VI below. You may also send a written complaint to the Secretary of the U.S. Department of Health and Human Services. If you file a complaint about my privacy practices, I will take no retaliatory action against you.
VI. PERSON TO CONTACT FOR INFORMATION ABOUT THIS NOTICE OR TO COMPLAIN ABOUT MY PRIVACY PRACTICES. If you have any questions about this Notice or any complaints about my privacy practices, or would like to know how to file a complaint with the Secretary of the U.S. Department of Health and Human Services, please contact me.
VII. NOTIFICATIONS OF BREACHES. In the case of a breach, Jeanne Caruso, MFT requires to notify each affected individual whose unsecured PHI has been compromised. Even if such a breach was caused by a business associate, Jeanne Caruso, MFT is ultimately responsible for providing the notification directly or via the business associate. If the breach involves more than 500 persons, OCR must be notified in accordance with instructions posted on its website. Jeanne Caruso, MFT bears the ultimate burden of proof to demonstrate that all notifications were given or that the impermissible use or disclosure of PHI did not constitute a breach and must maintain supporting documentation, including documentation pertaining to the risk assessment.
VIII. PHI AFTER DEATH. Generally, PHI excludes any health information of a person who has been deceased for more than 50 years after the date of death. Jeanne Caruso, MFT may disclose deceased individuals' PHI to non-family members, as well as family members, who were involved in the care or payment for healthcare of the decedent prior to death; however, the disclosure must be limited to PHI relevant to such care or payment and cannot be inconsistent with any prior expressed preference of the deceased individual.
IX. INDIVIDUALS’ RIGHT TO RESTRICT DISCLOSURES; RIGHT OF ACCESS. To implement the 2013 HITECH Act, the Privacy Rule is amended. Jeanne Caruso, MFT is required to restrict the disclosure of PHI about you, the client, to a health plan, upon request, if the disclosure is for the purpose of carrying out payment or healthcare operations and is not otherwise required by law. The PHI must pertain solely to a healthcare item or service for which you have paid the covered entity in full. (OCR clarifies that the adopted provisions do not require that covered healthcare providers create separate medical records or otherwise segregate PHI subject to a restrict healthcare item or service; rather, providers need to employ a method to flag or note restrictions of PHI to ensure that such PHI is not inadvertently sent or made accessible to a health plan.)
The 2013 Amendments also adopt the proposal in the interim rule requiring Jeanne Caruso, MFT, to provide you, the client, a copy of PHI if you, the client, requests it in electronic form. The electronic format must be provided to you if it is readily produced. OCR clarifies that Jeanne Caruso, MFT must provide you only with an electronic copy of their PHI, not direct access to their electronic health record systems. The 2013 Amendments also give you the right to direct Jeanne Caruso, MFT to transmit an electronic copy of PHI to an entity or person designated by you. Furthermore, the amendments restrict the fees that Jeanne Caruso, MFT may charge you for handling and reproduction of PHI, which must be reasonable, cost-based and identify separately the labor for copying PHI (if any). Finally, the 2013 Amendments modify the timeliness requirement for right of access, from up to 90 days currently permitted to 30 days, with a one-time extension of 30 additional days.
X. NOTICES OF PRIVACY PRACTICES. Jeanne Caruso, MFT Notice of Privacy Practices must contain a statement indicating that most uses and disclosures of psychotherapy notes, marketing disclosures and sale of PHI do require prior authorization by you, and you have the right to be notified in case of a breach of unsecured PHI.
XI. EFFECTIVE DATE OF THIS NOTICE. This Notice went into effect on March 3, 2020.
Copyright © 2020 Jeanne Caruso, LMFT - All Rights Reserved.
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.