Privacy Policy


**Policy Owner: ** Compliance and Practice Data Management  

Effective Date: January 1, 2023

PURPOSE

This Privacy Policy outlines the privacy practices of Compounding Pharmacy LLC, doing business as Waters Wellness (“we,” “us,” or “our”).   References to “Compounding Pharmacy LLC” in this Privacy Policy refer to Compounding Pharmacy LLC d/b/a Waters Wellness.   It is the intent of Compounding Pharmacy LLC to comply with all applicable provisions of the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and the regulations promulgated under these laws (collectively, “HIPAA”).   To support this compliance, Compounding Pharmacy LLC has developed and implemented a comprehensive set of written privacy and security policies and procedures.

MINIMUM NECESSARY USE AND DISCLOSURE OF PROTECTED HEALTH INFORMATION

When using or disclosing PHI, or when requesting PHI from another organization covered by HIPAA, reasonable efforts will be taken to limit the PHI to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request. This means, that to the extent practicable, the information contained in a Limited Data Set must be used, disclosed, or requested.

  1. Limited Data Set is PHI that excludes direct identifiers of the individual or of relatives, employers, or household members of the individual. A Limited Data Set excludes all of the following:     

    1. Names;

    2. Address information, other than town or city, state, and zip code;

    3. Telephone numbers;

    4. Fax numbers;    

    5. E-mail addresses;   

    6. Social security numbers; 7.   

    7. Medical record numbers; 8.  

    8. Health plan beneficiary numbers; 9.   

    9. Account numbers; 10.                   

    10. Certificate/license numbers; 11.  

    11. Vehicle identifiers and serial numbers, including license plate numbers; 12.

    12. Device identifiers and serial numbers; 13.

    13. Web Universal Resource Locators (URLs); 14.                   

    14. Internet Protocol (IP) address numbers; 15.

    15. Biometric identifiers, including finger and voice prints; and 16.

    16. Full face photographic.

  2. If it is not practical to limit the information to a Limited Data Set, PHI beyond a Limited Data Set may be used, disclosed, or requested, as long as the PHI is limited to the minimum necessary to accomplish the intended purpose of the use, disclosure or request.

  3. The minimum necessary standard DOES NOT apply to:     

    1. Disclosures to or requests by healthcare providers for treatment;    

    2. Disclosures to the individual who is the subject of the information;   

    3. Uses or disclosures made in compliance with an authorization by the individual;   

    4. Disclosures to the Department of Health and Human Services; and    

    5. Uses or disclosures required by

  4. The minimum necessary standard DOES apply to:     

    1. Employees who access PHI in the performance of their duties;

    2. Requests for PHI from other organizations governed by HIPAA;  

    3. Disclosures that occur on a recurring basis; and 

    4. Unless or disclosures of PHI that fall outside the scope of section “C”.  

  5. Unless a specific justification is given, requests for an entire medical record should not be granted. 

     

  6. You can rely on the judgment of the party requesting the disclosure to limit the amount of PHI to the minimum necessary when the request is made by:  

    1. A public official;   

    2. Another organization governed by HIPAA;    

    3. A professional who is a workforce member or business associate of an organization governed by HIPAA and is seeking the information to provide services for that organization; and  

    4. A researcher with appropriate documentation from an institutional review board or privacy board.  

  7. Disclosures made on a non-routine basis are reviewed individually to determine that the disclosure or the request is the minimum necessary to accomplish the purpose of the disclosure.

  8. PHI may be used to verify an individual’s

USE AND DISCLOSURE OF PROTECTED HEALTH INFORMATION FOR MARKETING PURPOSES AND PROHIBITION OF THE SALE OF PHI

Marketing is a communication about a product or service that encourages recipients of the communication to purchase or use the product or service. Marketing does not include a communication made: (i) face to face by a provider at Water Wellness
Group to an individual; (ii) in the form of a promotional gift of nominal value by Water Wellness
Group; (iii) to provide refill reminders or otherwise communicate about a biologic that is currently being prescribed for the individual, only if any financial remuneration received by Water Wellness
Group in exchange for making the communication is reasonably related to Water Wellness
Group’s cost of making the communication; (iv) for the following treatment and health care operations purposes, except where Water Wellness
Group receives financial remuneration in exchange for making the communication:

  1. For treatment of an individual by a healthcare provider, including case management or care coordination for the individual, or to direct or recommend alternative treatments, therapies, health care providers, or settings of care to the individual;

  2. To describe a health-related product or service (or payment for such product or service) that is provided by, or included in a plan of benefits of, Water Wellness
    Group Pharmacy making the communication, including communications about: the entities participating in a health care provider network or health plan network; replacement of, or enhancements to, a health plan; and health-related products or services available only to a health plan enrollee that add value to, but are not part of, a plan of benefits; or

  3. For case management or care coordination, contacting of individuals with information about treatment alternatives, and related functions to the extent these activities do not fall within the definition of treatment. 

    However, marketing does mean any communication from Water Wellness
    Groups Pharmacy or a business associate of Water Wellness
    Groups Pharmacy to a patient about a product or service that encourages the patient to purchase or use the product or service if Water Wellness Group receives financial remuneration from the other entity or its affiliate to make such a communication.

    Financial remuneration means direct or indirect payment from or on behalf of a third party whose product or service is being described. Direct or indirect payment does not include any payment for treatment of an individual. Water Wellness
    Groups Pharmacy can only use PHI for marketing purposes if Water Wellness Groups obtains an individual’s authorization.


    The individual must authorize these marketing communications before they occur. Water Wellness
    Groups Pharmacy may not receive any financial remuneration in exchange for any PHI of an individual unless Water Wellness
    Groups Pharmacy obtains an authorization from the individual which indicates that the individual’s PHI can be exchanged for remuneration to the Water Wellness
    Groups Pharmacy from the entity receiving the PHI. The following exceptions apply:

  1. For treatment of an individual by a healthcare provider, including case management or care coordination for the individual, or to direct or recommend alternative treatments, therapies, health care providers, or settings of care to the individual;   

  2. To describe a health-related product or service (or payment for such product or service) that is provided by, or included in a plan of benefits of, Water Wellness
    Group making the communication, including communications about: the entities participating in a health care provider network or health plan network; replacement of, or enhancements to, a health plan; and health-related products or services available only to a health plan enrollee that add value to, but are not part of, a plan of benefits; or   

  3. For case management or care coordination, contacting of individuals with information about treatment alternatives, and related functions to the extent these activities do not fall within the definition of treatment.

    However, marketing does mean any communication from Water Wellness Group or a business associate of Water Wellness
    Group to a patient about a product or service that encourages the patient to purchase or use the product or service if Water Wellness
    Group receives financial remuneration from the other entity or its affiliate to make such a communication.

    Financial remuneration means direct or indirect payment from or on behalf of a third party whose product or service is being described. Direct or indirect payment does not include any payment for treatment of an individual. Water Wellness
    Group can only use PHI for marketing purposes if Water Wellness
    Groupg obtains an individual’s authorization. The individual must authorize these marketing communications before they occur. Water Wellness Group may not receive any financial remuneration in exchange for any PHI of an individual unless Water Wellness
    Group obtains an authorization from the individual which indicates that the individual’s PHI can be exchanged for remuneration to the Water Wellness
    Group from the entity receiving the PHI. The following exceptions apply:

    1. When the purpose of the exchange is for public health purposes pursuant to 45 CFR 164.512(b) or 45 CFR 164.514(e);   

    2. When the purpose of the exchange is for research purposes pursuant to 45 CFR 164.512(i) or 164.512(e), where the only remuneration received by Water Wellness
      Group is a reasonable cost-based fee to cover the cost to prepare and transmit the PHI for such purposes;    

    3. When the purpose of the exchange is for treatment and payment purposes pursuant to 45 CFR 164.506(a);

    4. Where the purpose of the exchange is for the sale, transfer, merger, or consolidation of all or part of Water Wellness
      Group and for related due diligence and pursuant to 45 CFR 164.506(a);   

    5. Where the exchange is to or by a business associate for activities that the business associate undertakes on behalf of Water Wellness
      Group, pursuant to 45 CFR 502(e) and 164.504(e), and the only remuneration provided is by Water Wellness
      Group to the business associate for the performance of such activities;  

    6. Where the exchange is to an individual when requested under 45 CFR 164.524 or 164.528;  

    7. Where the exchange is required by law as permitted under 45 CFR 164.512(a); and 8.  

    8. Where the exchange is for any other purpose permitted by and in accordance with the applicable requirements of Subpart E of Part 164 of Title 45 of the Code of Regulations, where the only remuneration received by Water Wellness
      Group is a reasonable, cost-based fee to cover the cost to prepare and transmit the PHI for such purpose or a fee otherwise expressly permitted by other law.

  4. Any communication that could be construed as being marketing will be evaluated by the Privacy Officer prior to the communication being sent. Legal counsel may also evaluate these communications.

    If it is determined that the communication falls within the definition of marketing, a patient’s authorization will be obtained as required by 45 CFR 164.508.No

    PHI may be provided to any third party in exchange for financial remuneration unless one of the exceptions listed above in Section D is applicable. The Service is owned and operated by Sponsor. The visual interfaces, graphics, design, compilation, information, data, computer code (including source code or object code), products, Software, services, and all other elements of the Service (the “Materials”) provided by Sponsor are protected by all relevant intellectual property and proprietary rights and applicable laws. All Materials contained in the Service are the property of Sponsor or our third party licensors. Except as expressly authorized by Sponsor, you may not make use of the Materials. Sponsor reserves all rights to the Materials not granted expressly in this Terms of Use.

INDEMNITY

You agree that you will be responsible for your use of the Service, and you agree to defend, indemnify, and hold harmless Sponsor and each of their officers, directors, employees, consultants, affiliates, subsidiaries, agents, and distributors (collectively, the “Sponsor Entities”) from and against any and all claims, liabilities, damages, losses, and expenses, including reasonable attorneys’ fees and costs, arising out of or in any way connected with (i)your access to, use of, or alleged use of the Service; (ii)your violation of this Terms of Use or any representation, warranty, or agreements referenced in this Terms of Use, or any applicable law or regulation; (iii)your violation of any third party right, including without limitation any intellectual property right, publicity, confidentiality, property or privacy right; or (iv) any disputes or issues between you and any third party. Sponsor reserves the right, at its own expense, to assume the exclusive defense and control of any matter otherwise subject to indemnification by you (and without limiting your indemnification obligations with respect to such matter), and in such case, you agree to cooperate with our defense of such claim.

Disclaimers; No Warranties

An individual who believes his/her privacy rights have been violated may file a complaint with the Privacy Officer of Water Wellness
Group or with the United States.

Secretary of the Department of Health and Human Services. Furthermore, all members of the workforce who believe that any HIPAA policies have been violated shall report such suspected violations to the Privacy Officer.

  1. The Privacy Officer shall investigate all complaints in a timely manner. The investigation may include reviewing documents and conducting interviews of relevant witnesses. At the conclusion of the investigation, the Privacy Officer will prepare a written report which states the findings of the investigation and if there was a violation, any plan to address the violation. The Privacy Officer will then communicate that information in writing to the complaining party. 2.   

  2. The Privacy Officer will maintain a log documenting the results of the investigation and resolution of all complaints. 3.   

  3. Complaints may be submitted to the Privacy Officer via S. mail, fax, or e-mail: 4.  

  4. Mail: 310 Bluff City Hwy., Bristol, TN 37620 5.   

  5. E-mail: trey@waterwellness. 6.   

  6. Individuals who wish to file a complaint with the Secretary of the Department of Health and Human Services must send their complaint to the Office of Civil Rights (OCR) headquarters: 7.

  7. Office for Civil Rights

    U.S. Department of Health and Human Services 200 Independence Avenue, S.W.

  8. Room 509F HHH Bldg. Washington, D.C. 20201 No person filing a complaint or providing information relevant to the investigation with the Privacy Officer or the OCR will be subject to retaliation or intimidation.

USES AND DISCLOSURES OF PROTECTED HEALTH INFORMATION FOR WHICH AN AUTHORIZATION IS REQUIRED

Protected health information (PHI) will not be used or disclosed without a written authorization to do so from the individual or a person authorized to act on behalf of the individual in making health care decisions unless HIPAA allows disclosure without an authorization. (See Policy Number 7: Uses and Disclosures of Protected Health Information For Which An Authorization Is Not Required).

PROCEDURE

This Terms of Use is governed by the laws of the State of Texas without regard to conflict of law principles. To the extent that any lawsuit or court proceeding is permitted hereunder, you and Sponsor agree to submit to the personal and exclusive jurisdiction of the state courts and federal courts located within the state of Texas for the purpose of litigating all such disputes. Sponsor operates the Service from its offices in Texas and it makes no representation that Materials included in the Service are appropriate or available for use in other locations.

USES AND DISCLOSURES OF PROTECTED HEALTH INFORMATION FOR WHICH AN AUTHORIZATION IS NOT REQUIRED

Protected health information (PHI) may be used or disclosed without the written authorization from the individual, and without providing notice to an individual only in very specific situations.

PROCEDURE

Water Wellness Group may use and disclose PHI without a patient authorization in all of the situations listed below. If you receive a request to release PHI outside of the organization and you are not typically involved in releasing such information you must contact the Privacy Officer before any PHI can be released.


  1. 1.      In accordance with the Policy on Uses and Disclosures for Treatment, Payment and Health Care Operations.    

  2. When the use or disclosure is required by law and is limited to the relevant requirements of such law.    

  3. Disclosures for public health activities to:   

  4. A public health authority that is authorized by law to collect, receive, or report such information for the purpose of preventing or controlling disease, injury or disability as well as to conduct public health surveillance, investigations, and interventions;    

  5. A public health authority authorized by law to receive reports of child abuse or neglect;    

  6. A person subject to the authority of the FDA because that person is responsible for the quality, safety or effectiveness of a FDA-regulated product or activity. The purposes of these disclosures include:    

  7. To collect or report adverse events, product defects, or biological product deviations;  

  8. To track FDA-regulated products;    

  9. To allow and notify individuals about product recalls, repairs, replacements, or lookbacks; or                  

  10. To conduct post-market   

  11. A person who may have been exposed to or may be at risk of contracting or spreading a communicable disease or condition; or .

  12. An employer about an individual who is a member of the employer’s workforce if:

  13. Water Wellness Group provides health care to the workforce member at the request of the employer to conduct an evaluation relating to medical surveillance of the workplace or to evaluate whether the individual has a work-related illness or injury;                  

  14. The PHI that is disclosed contains findings that indicate a work-related illness or injury or workplace-related medical surveillance;

  15. The employer needs such findings in order to comply with federal and state labor regulations which require the recording of work-related illnesses or injuries or the carrying out of responsibilities for workplace medical surveillance; and

  16. Written notice of the disclosure is given to the individual at the time that health care is provided or by posting the notice prominently where the health care is provided, if the care is provided at the work site.

  17. A school, about an individual who is a student or prospective student of the school, if:

  18. The PHI that is disclosed is limited to proof of immunization;

  19. The school is required by state or other law to have such proof of immunization prior to admitting the individual; and                

    1. Water Wellness Group obtains and documents the agreement to the disclosure from either: a parent, guardian or other person acting in loco parentis of the individual, if the individual is an unemancipated minor; or the individual, if the individual is an adult or emancipated minor.

      Disclosures about victims of abuse, neglect or domestic

      1. PHI about an individual who is believed to be a victim of abuse, neglect, or domestic violence may be disclosed to a governmental authority, including a social or protective services agency:

      2. The disclosure must be limited to the extent required by law;  

      3. The individual must agree to the disclosure;   

      4. The disclosure must only be to the extent that is expressly authorized by statute or regulation; and    

      5. There is a belief that the disclosure is necessary to prevent serious harm to the individual or others; or    

      6. If the individual does not have the capacity to agree, a law enforcement, or other public official authorized to receive the report, represents that the PHI to be disclosed is not intended to be used against the individual and that an immediate enforcement activity that depends on disclosure would be significantly adversely affected by waiting until the individual is able to agree to the.   

      7. The individual must be promptly informed that the report concerning the suspected abuse, neglect, or domestic violence has been or will be made, except if:   

      8. There is a reasonable belief that informing the individual would place the individual at risk of serious harm; or   

      9. The disclosure would be made to a personal representative and there is a reasonable belief that the personal representative is responsible for the abuse, neglect, or other injury.


      Uses and disclosures for health oversight activities

      1. PHI may be disclosed to a health oversight agency for oversight activities authorized by law including audits, inspections, licensure, or disciplinary actions, or other activities necessary for the appropriate oversight of:    

      2. The health care system;   

      3. Government benefit programs for which health information is relevant to beneficiary eligibility; or  

      4. Entities subject to government regulatory programs and civil rights laws for which health information is required to determine compliance.    

      5. Health oversight activities do not include:    

      6. An investigation or other activity in which the individual is the subject of the investigation;    

      7. An investigation or activity that is not related to:  

      8. The receipt of health care;   

      9. A claim for public health benefits; or                    

      10. Qualification for, or receipt of, public benefits or services when a patient’s health is integral to the claim for those benefits or services.


      Uses and disclosures about decedents

      1. PHI may be disclosed to coroners, medical examiners, and funeral directors to carry out their duties.   

      2. Disclosures made to funeral directors include those made in reasonable anticipation of the individual’s death.   

      3. PHI may be disclosed to a family member, other relative, or close personal friend if such person was involved in the deceased’s care or payment for health care prior to decedent’s death, if the PHI is relevant to such person’s involvement, unless doing so is inconsistent with any prior expressed preference of the decedent that is known to Water Wellness Group.


      Uses and disclosures for cadaveric organ, eye or tissue donation purposes

      1. PHI may be disclosed to an organ procurement organization to facilitate organ, eye or tissue donation and transplantation.


      Uses and disclosures for research purposes

      1. PHI may be disclosed for research purposes only in accordance with 45 C.F.R. 164.512(i).


      Uses and disclosures to avert a serious threat to health or safety

      1. PHI may be used or disclosed if there:    

      2. Is a good faith belief that the use or disclosure is necessary, and is to a person who is reasonably able, to prevent or lessen a serious and imminent threat to the health or safety of a person or the public; or    

      3. Is necessary for law enforcement authorities to identify or apprehend an individual who made a statement admitting participation in a violent crime that may have caused serious physical harm to the victim.  

      4. Disclosure may not be made if:   

      5. The information to be disclosed was discovered during treatment to mitigate the propensity to commit the criminal conduct that is the base

      6. s for the disclosure, such as counseling or therapy; or     Through the request by the individual to initiate or to be referred for the treatment.    

      7. The information to be disclosed is limited to:   

      8. The statement of the individual who is believed to have participated in a violent crime that may have caused serious harm to the victim;   

      9. Name and address;                   

      10. Date and place of birth;   

      11. Social security number;

      12. ABO blood type and Rh factor;

      13. Type of injury;                    

      14. Date and time of treatment;

      15. Date and time of death, if applicable; and

      16. A description of distinguishing physical

      17. If PHI is used or disclosed in accordance with section “I” then there is a presumption that the use or disclosure was done in good faith and based on actual knowledge or in reliance on a credible representation by a person with apparent knowledge or


      Uses and disclosures for specialized government functions

      1. PHI may be used or disclosed for military and veterans.   

      2. PHI may be used by or disclosed to Armed Services personnel or foreign military personnel for activities deemed necessary by military command authorities to assure the proper execution of the military mission.  

      3. PHI may be disclosed to federal officials for lawful intelligence, counter-intelligence, and other national security activities.

      4. PHI may be disclose to federal officials for the protective services of the President or foreign heads of state.    

      5. PHI may be disclosed to a correctional institution or a law enforcement official who has lawful custody of an inmate if such PHI is necessary for:    

      6. Providing health care to such individual;    

      7. The health and safety of such individual or other inmates;

      8. The health and safety of the officers or employees of or others at the correctional institution;  

      9. The health and safety of those responsible for transporting inmates;                  

      10. Law enforcement on the premises of the correctional institution; and 11.   The administration and maintenance of the safety, security, and good order of the correctional institution.


      Disclosures for workers’ compensation

      1. To the extent necessary, PHI may be disclosed to comply with laws relating to workers’ compensation or other similar programs, that provide benefits for work-related injuries or illnesses, without regard to fault.

USES AND DISCLOSURES OF PROTECTED HEALTH INFORMATION FOR WHICH AN AUTHORIZATION IS NOT REQUIRED

Protected health information (PHI) may be used or disclosed without the written authorization from the individual, and without providing notice to an individual only in very specific situations.

PROCEDURE

Water Wellness Group may use and disclose PHI without a patient authorization in all of the situations listed below. If you receive a request to release PHI outside of the organization and you are not typically involved in releasing such information you must contact the Privacy Officer before any PHI can be released.


  1. 1.      In accordance with the Policy on Uses and Disclosures for Treatment, Payment and Health Care Operations.    

  2. When the use or disclosure is required by law and is limited to the relevant requirements of such law.    

  3. Disclosures for public health activities to:   

  4. A public health authority that is authorized by law to collect, receive, or report such information for the purpose of preventing or controlling disease, injury or disability as well as to conduct public health surveillance, investigations, and interventions;    

  5. A public health authority authorized by law to receive reports of child abuse or neglect;    

  6. A person subject to the authority of the FDA because that person is responsible for the quality, safety or effectiveness of a FDA-regulated product or activity. The purposes of these disclosures include:    

  7. To collect or report adverse events, product defects, or biological product deviations;  

  8. To track FDA-regulated products;    

  9. To allow and notify individuals about product recalls, repairs, replacements, or lookbacks; or                  

  10. To conduct post-market   

  11. A person who may have been exposed to or may be at risk of contracting or spreading a communicable disease or condition; or .

  12. An employer about an individual who is a member of the employer’s workforce if:

  13. Water Wellness Group provides health care to the workforce member at the request of the employer to conduct an evaluation relating to medical surveillance of the workplace or to evaluate whether the individual has a work-related illness or injury;                  

  14. The PHI that is disclosed contains findings that indicate a work-related illness or injury or workplace-related medical surveillance;

  15. The employer needs such findings in order to comply with federal and state labor regulations which require the recording of work-related illnesses or injuries or the carrying out of responsibilities for workplace medical surveillance; and

  16. Written notice of the disclosure is given to the individual at the time that health care is provided or by posting the notice prominently where the health care is provided, if the care is provided at the work site.

  17. A school, about an individual who is a student or prospective student of the school, if:

  18. The PHI that is disclosed is limited to proof of immunization;

  19. The school is required by state or other law to have such proof of immunization prior to admitting the individual; and                

    1. Water Wellness Group obtains and documents the agreement to the disclosure from either: a parent, guardian or other person acting in loco parentis of the individual, if the individual is an unemancipated minor; or the individual, if the individual is an adult or emancipated minor.

      Disclosures about victims of abuse, neglect or domestic

      1. PHI about an individual who is believed to be a victim of abuse, neglect, or domestic violence may be disclosed to a governmental authority, including a social or protective services agency:

      2. The disclosure must be limited to the extent required by law;  

      3. The individual must agree to the disclosure;   

      4. The disclosure must only be to the extent that is expressly authorized by statute or regulation; and    

      5. There is a belief that the disclosure is necessary to prevent serious harm to the individual or others; or    

      6. If the individual does not have the capacity to agree, a law enforcement, or other public official authorized to receive the report, represents that the PHI to be disclosed is not intended to be used against the individual and that an immediate enforcement activity that depends on disclosure would be significantly adversely affected by waiting until the individual is able to agree to the.   

      7. The individual must be promptly informed that the report concerning the suspected abuse, neglect, or domestic violence has been or will be made, except if:   

      8. There is a reasonable belief that informing the individual would place the individual at risk of serious harm; or   

      9. The disclosure would be made to a personal representative and there is a reasonable belief that the personal representative is responsible for the abuse, neglect, or other injury.


      Uses and disclosures for health oversight activities

      1. PHI may be disclosed to a health oversight agency for oversight activities authorized by law including audits, inspections, licensure, or disciplinary actions, or other activities necessary for the appropriate oversight of:    

      2. The health care system;   

      3. Government benefit programs for which health information is relevant to beneficiary eligibility; or  

      4. Entities subject to government regulatory programs and civil rights laws for which health information is required to determine compliance.    

      5. Health oversight activities do not include:    

      6. An investigation or other activity in which the individual is the subject of the investigation;    

      7. An investigation or activity that is not related to:  

      8. The receipt of health care;   

      9. A claim for public health benefits; or                    

      10. Qualification for, or receipt of, public benefits or services when a patient’s health is integral to the claim for those benefits or services.


      Uses and disclosures about decedents

      1. PHI may be disclosed to coroners, medical examiners, and funeral directors to carry out their duties.   

      2. Disclosures made to funeral directors include those made in reasonable anticipation of the individual’s death.   

      3. PHI may be disclosed to a family member, other relative, or close personal friend if such person was involved in the deceased’s care or payment for health care prior to decedent’s death, if the PHI is relevant to such person’s involvement, unless doing so is inconsistent with any prior expressed preference of the decedent that is known to Water Wellness Group.


      Uses and disclosures for cadaveric organ, eye or tissue donation purposes

      1. PHI may be disclosed to an organ procurement organization to facilitate organ, eye or tissue donation and transplantation.


      Uses and disclosures for research purposes

      1. PHI may be disclosed for research purposes only in accordance with 45 C.F.R. 164.512(i).


      Uses and disclosures to avert a serious threat to health or safety

      1. PHI may be used or disclosed if there:    

      2. Is a good faith belief that the use or disclosure is necessary, and is to a person who is reasonably able, to prevent or lessen a serious and imminent threat to the health or safety of a person or the public; or    

      3. Is necessary for law enforcement authorities to identify or apprehend an individual who made a statement admitting participation in a violent crime that may have caused serious physical harm to the victim.  

      4. Disclosure may not be made if:   

      5. The information to be disclosed was discovered during treatment to mitigate the propensity to commit the criminal conduct that is the base

      6. s for the disclosure, such as counseling or therapy; or     Through the request by the individual to initiate or to be referred for the treatment.    

      7. The information to be disclosed is limited to:   

      8. The statement of the individual who is believed to have participated in a violent crime that may have caused serious harm to the victim;   

      9. Name and address;                   

      10. Date and place of birth;   

      11. Social security number;

      12. ABO blood type and Rh factor;

      13. Type of injury;                    

      14. Date and time of treatment;

      15. Date and time of death, if applicable; and

      16. A description of distinguishing physical

      17. If PHI is used or disclosed in accordance with section “I” then there is a presumption that the use or disclosure was done in good faith and based on actual knowledge or in reliance on a credible representation by a person with apparent knowledge or


      Uses and disclosures for specialized government functions

      1. PHI may be used or disclosed for military and veterans.   

      2. PHI may be used by or disclosed to Armed Services personnel or foreign military personnel for activities deemed necessary by military command authorities to assure the proper execution of the military mission.  

      3. PHI may be disclosed to federal officials for lawful intelligence, counter-intelligence, and other national security activities.

      4. PHI may be disclose to federal officials for the protective services of the President or foreign heads of state.    

      5. PHI may be disclosed to a correctional institution or a law enforcement official who has lawful custody of an inmate if such PHI is necessary for:    

      6. Providing health care to such individual;    

      7. The health and safety of such individual or other inmates;

      8. The health and safety of the officers or employees of or others at the correctional institution;  

      9. The health and safety of those responsible for transporting inmates;                  

      10. Law enforcement on the premises of the correctional institution; and 11.   The administration and maintenance of the safety, security, and good order of the correctional institution.


      Disclosures for workers’ compensation

      1. To the extent necessary, PHI may be disclosed to comply with laws relating to workers’ compensation or other similar programs, that provide benefits for work-related injuries or illnesses, without regard to fault.

RIGHT TO REQUEST CONFIDENTIAL COMMUNICATIONS AND TO RESTRICT ACCESS OR DISCLOSURE OF PROTECTED HEALTH INFORMATION

Any reasonable request for confidential communications of protected health information (PHI) must be accommodated. Individuals need not explain the reason for their request. However, the request must be reasonable, be made in writing, and specify an alternative address or method of contact. All requests for restrictions on uses and disclosures will be considered by Water Wellness Group.

PROCEDURE

Confidential Communications Individuals have the right to request confidential communications of their PHI. All reasonable requests must be accommodated. Examples of types of communications to which this policy may apply include: Mailing or telephoning regarding appointment reminders; Mailing bills or statements of payments due; Sending test results; or Prescription refill reminders .A reasonable accommodation may be conditioned on: Specification of an alternative address or method of contact; or How payment will be handled, if the individual must not be required to explain the basis for the request as a condition of providing the communications, unless Water Wellness Group is a health plan, see subsection f, below. Requests for confidential communication must be made in. The patient’s request for confidential communication must be documented in the patient’s medical and billing records, and the original copy of the request form must be placed in the patient’s medical record. If Water Wellness Group is a health plan, a request may be required to contain a statement that disclosure of all or part of the information to which the request pertains could endanger the individual. Restrictions to Access and Disclosures. An individual must be permitted to request the restriction of uses and disclosures of their PHI. The following are the rights and obligations when reviewing these types of requests: Water Wellness Group is not required to agree to a restriction except for a request of an individual to restrict disclosure of PHI about the individual to a health plan if: The disclosure is for the purpose of carrying out payment or health care operations and is not otherwise required by law; and the PHI pertains solely to a health care item or service for which the individual, or person other than the health plan on behalf of the individual, has paid Water Wellness
Group in full. If Water Wellness Group agrees to the restriction, then the PHI may not be used or disclosed in violation of the restriction agreement, except in situations where the information is needed to treat the patient in an emergency. If restricted PHI is disclosed for emergency treatment, Water Wellness Group must request that the provider to whom the PHI was disclosed not make any further disclosures. An agreed upon restriction must be documented. Water Wellness Group may terminate an agreed upon restriction if: The individual agrees to or requests the termination in writing; The individual orally agrees to the termination and the oral agreement is documented; or the individual is informed that the agreement to the restriction is terminated except that such termination is only effective with respect to PHI created or received after the individual has been informed. Some examples of possible requests for restriction of uses and disclosures include Individual requests that PHI not be shared with an outside transcription service, since the individual knows that Individual requests that a certain diagnosis be left off a claim form. Individual requests that certain PHI not be shared with other providers the Privacy Officer will review each restriction request and consider the following criteria: Would Water Wellness Group be able to provide or continue treatment if Water Wellness Group honor the request? Would Water Wellness Group be able to submit a valid claim if Water Wellness Group were to honor the request?

How would our agreement impact operations?

Would Water Wellness Group be able to enforce the restriction internally now and in the future?

ACCOUNTING OF DISCLOSURES

Disclosures for purposes other than treatment, payment and healthcare operations that are not specifically authorized by the patient shall be tracked. Water Wellness
Group must act on the individual’s request for accounting, no later than 60 days after receipt of the request.

PROCEDURE

  1. An individual has the right to receive an accounting of disclosures of protected health information (PHI) in the six years prior to the date on which the accounting is requested unless the disclosure was:   

  2. To carry out treatment, payment and health care operations;   

  3. To individuals of PHI about them;  

  4. Incident to use or disclosure otherwise permitted by this policy;   

  5. The type of PHI for which authorization is required according to Policy Number

  6. Uses and Disclosures of Protected Health Information For Which An Authorization Is Required.   

  7. For persons involved in the individual’s care or other notification purposes   

  8. For national security or intelligence purposes;   

  9. To correctional institutions or law enforcement officials;   

  10. Part of a Limited Data Set; or                   

  11. Made prior to the compliance  

  12. A Limited Data Set is PHI that excludes direct identifiers of the individual or of relatives, employers, or household members of the individual. A Limited Data Set excludes all of the following:

  13. Names;

  14. Address information, other than town or city, state, and zip code;                   

  15. Telephone numbers;

  16. Fax numbers;

  17. E-mail addresses;

  18. Social security numbers;

  19. Medical record numbers;

  20. Health plan beneficiary numbers;                 

  21. Account numbers;

  22. Certificate/license numbers;                  

  23. Vehicle identifiers and serial numbers, including license plate numbers;                   

  24. Device identifiers and serial numbers;                  

  25. Web Universal Resource Locators (URLs);                   

  26. Internet Protocol (IP) address numbers;                  

  27. Biometric identifiers, including finger and voice prints; and                  

  28. Full face photographic                   

  29. Suspension of right to receive an accounting of disclosures                  

  30. An individual’s right to receive an accounting of disclosures to a health oversight agency or law enforcement official must be temporarily suspended for the time specified by such agency or official, if such agency or official                  

  31. Specifies the time for which such a suspension is required

  32. Provides Water Wellness
    Group with a written statement that such an accounting to the individual would be reasonably likely to impede the agency’s activities                  

  33. If the statement is made orally then Water Wellness
    Group must:                  

  34. Document the statement, including the identity of the agency or official making the statement;                  

  35. Temporarily suspend the individual’s right to an accounting of disclosures subject to the statement; and                 

  36. Limit the temporary suspension to no longer than 30 days from the date of the oral statement, unless a written statement is submitted during that time.                  

  37. Content of the Accounting                  

  38. The accounting of disclosures of PHI must include:                   

  39. Date of the disclosure;                   

  40. Description of information disclosed;              

  41. Name of party who received the PHI and, if known, the address of such party; and                   

  42. A brief statement of the purpose of the disclosure that reasonably informs the individual of the basis for the disclosure;                 

  43. If during the period covered by the accounting, disclosures were made for a particular research purpose to fifty (50) or more individuals, the accounting may provide:                  

  44. The name of the protocol or other research activity;                

  45. A description in plain language of the research protocol or other research activity, including the purpose of the research and the criteria for selecting particular records;                 

  46. A brief description of the type of PHI that was disclosed;              

  47. The date or period of time during which such disclosures occurred or may have occurred including the date of the last disclosure during the accounting period;                

  48. The name, address, and telephone number of the entity that sponsored the research and of the researcher to whom the information was disclosed; and                 

  49. A statement that the PHI of the individual may or may not have been disclosed for a particular protocol or other research activity. 49.                 

  50. Responding to a Request for Disclosure:                 

  51. The requesting party will receive the accounting in writing from the Privacy Officer within 60 days. If additional time is required in order to comply with the request, an additional 30 days may be taken so long as the requesting party is notified in writing of the

  52. The first accounting to an individual in any twelve (12) month period must be provided without charge. A [reasonable] fee will be imposed for each subsequent request for an accounting by the same individual within that twelve (12) month period.                  

  53. An individual may request an accounting of disclosures for a period of time less than six (6) years from the date of the request. All requests by individuals for an accounting of disclosures of PHI must be directed to the Privacy Officer at: Kush Patel Privacy Officer 903-885-2639 310 Bluff City Hwy., Bristol, TN 37620 trey@waterwellness.

AMENDMENT OF PROTECTED HEALTH INFORMATION

An individual’s protected health information (PHI) in a Designated Record Set will be amended at the request of the individual, in accordance with HIPAA requirements.

PROCEDURE

  1. This policy applies to PHI that is part of a Designated Record Set. A Designated Record Set includes:   

  2. Medical records and billing records;   

  3. Enrollment, payment, claims and case or medical management records; and

  4. Any records used to make decisions about the individual. 5.   

  5. Requests for amendments must be submitted in writing to the Privacy Officer.    

  6. Water Wellness Group will respond to an individual’s request for an amendment within 60 days after receipt of the request. If this is not possible, the individual will be given a written notice explaining the reasons for the delay and the date when the amendment will be completed. This extension will not go beyond thirty (30) days.   

  7. If Water Wellness Group accepts the individual’s request for an amendment to PHI, Water Wellness Group will:  

  8. Make the requested amendments;   

  9. Inform the individual of the acceptance in a timely manner;                 

  10. Notify the people authorized by the individual that the amendments have been made and provide copies of the amendments as requested; and   

  11. Notify business associates that the amendments have been made and provide copies upon request.

  12. Denials

  13. An individual’s request for amendment to PHI may be denied if it is determined that the PHI or record requested:                    

  14. Was not created by Water Wellness
    Group, unless the individual provides a reasonable basis to believe that the originator of the PHI is no longer available to act on the requested amendment;

  15. Is not part of a Designated Record Set;

  16. Is not available for inspection under HIPAA; or

  17. Is accurate and complete

  18. Following a denial to the individual’s request for an amendment to PHI Water Wellness Group will notify the individual in plain writing of the denial which will include:

  19. The reason for denial;                 

  20. Information about how the individual may submit a written statement concerning their disagreement with the denial;

  21. A statement that, if the individual does not submit a statement of disagreement, the individual may request that Water Wellness
    Group provide the individual’s request for amendment and the denial with all future disclosures of the PHI that is the subject of the amendment; and                  

  22. A description of how the individual may file a complaint with Water Wellness
    Group or to the Secretary of Health and Human Services. The description must include the name, or title, and telephone number of the Privacy Officer.                  

  23. An individual is permitted to submit a written statement disagreeing with the denial of all or part of a requested amendment and the basis of such disagreement. The length of this statement may be limited.                 

  24. The individual’s record or PHI that is the subject of the disputed amendment must be identified and linked to the individual’s request for an amendment, the denial of the request, the individual’s statement of disagreement, and any rebuttal in response to the statement of disagreement.                  

  25. If a statement of disagreement has been submitted by the individual, then all future disclosures of PHI which concern the disagreement must include the individual’s request for an amendment, the denial of the request, the individual’s statement of disagreement, and any rebuttal in response to the statement of disagreement in full or a summary of such information.                

  26. If the individual has not submitted a written statement of disagreement, then the individual’s request for amendment and the denial to that request, or an accurate summary of such information, will be included with any subsequent disclosure of PHI only if the individual has requested such action.                  

  27. If informed by another health plan, health care clearinghouse, or health care provider of an amendment to an individual’s PHI, Water Wellness Group will also amend the PHI of the individual within its system.                 

  28. The titles of the persons or offices responsible for receiving and processing requests for amendments by individuals will be recorded.

AMENDMENT OF PROTECTED HEALTH INFORMATION

An individual has the right to request access to his or her own protected health information (PHI) in a designated record set.

PROCEDURE

     

  1. A designated record set includes:   

  2. Medical records and billing records;   

  3. Enrollment, payment, claims and case or medical management records; and  

  4. Any records used to make decisions about the   

  5. This right of access does not apply to:   

  6. Psychotherapy notes; and   

  7. Information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding.  

  8. Requesting Access   

  9. Water Wellness Group shall provide the attached form for all individuals who request access to PHI.                   

  10. The request shall be submitted and processed by the Privacy Officer.  

  11. Denying an individual’s request to access their PHI:

  12. If an individual’s request for access to PHI is denied then Water Wellness
    Group will comply with the following requirements:

  13. Access will be given to any other PHI requested after excluding the denied PHI; and                   

  14. A timely written denial will be given to the individual that is in plain language and includes:

  15. The reason for the denial of access;

  16. Any right of review (if applicable);

  17. How to file a complaint;

  18. The name and number of the person to whom the complaint may be filed; and

  19. The address of the United States Secretary of Health and Human Services.                 

  20. An individual’s request for access to PHI may be denied without providing the individual an opportunity for review of that denial in the following circumstances:

  21. The right of access to the PHI does not apply as explained by section “B”;                   

  22. The care was provided by or under the guidance of a correctional institution, the individual requesting PHI is an inmate, and obtaining such a copy may jeopardize the health, safety, or rehabilitation of the individual, other inmates, or other people at the correctional institution;                 

  23. The PHI was collected during the course of research for treatment of the individual and the individual agreed to suspend his or her right of access during this period; and                  

  24. The PHI was obtained from someone other than a health care provider under a promise of confidentiality and the access requested is reasonably likely to reveal the source of the information.                  

  25. An individual’s request for access to PHI may be denied with a right to have the denial reviewed. This review must be done by a health care professional who did not participate in the original denial. The right to have a denial reviewed is allowed in the following circumstances:                   

  26. A licensed health care professional determined that the access requested is reasonably likely to endanger the life or physical safety of the individual or another person;                   

  27. The PHI makes reference to another person and a licensed health care professional determined that the access requested is reasonably likely to cause substantial harm to such other person; or                  

  28. The request for access is made by the individual’s personal representative and a licensed healthcare professional determined that allowing access to the personal representative is reasonably likely to cause substantial harm to the individual or another person.                  

  29. Allowing access to                 

  30. If an individual’s request for access to PHI is accepted then:

  31. The individual must be provided with the access requested, including inspection or obtaining a copy, or both, of the PHI about the individual;                  

  32. The PHI requested must be in the form and format requested by the individual;                   

  33. A summary of the PHI may be provided in lieu of access to the PHI if the individual agrees in advance to such a summary and to any fees imposed; and                 

  34. If the PHI that is the subject of a request for access is maintained in one or more designated record sets electronically and if the individual requests an electronic copy of such information, Water Wellness
    Group must provide the individual with access to the PHI in the electronic form and format requested, if it is readily producible in such form and format; or, if not, in a readable electronic form and format as agreed to by Water Wellness
    Group and the individual.                   

  35. If an individual requests a copy of the PHI or agrees to a summary or explanation, a reasonable fee may be imposed provided that the fee includes only the cost of:                  

  36. Copying;                   

  37. Supplies for creating the paper copy or electronic media if the individual requests that the electronic copy be provided in portable media;                  

  38. Postage; or Preparing an explanation or summary of the PHI if agreed                 

  39. Water Wellness
    Group must respond to an individual’s request for access to PHI no later than thirty (30) days after receipt of the request. If action cannot be taken in response to the request to access PHI within the thirty (30) day limit then a thirty (30) day extension is Under these circumstances, the individual must be given a written statement (within thirty (30) days of receipt of the request) of the reasons for the delay and the date by which action on the request will be completed. This extension may only be used once.                  

  40. If an individual’s request directs Water Wellness
    Group to transmit the copy of PHI directly to another person designated by the individual, Water Wellness
    Group must provide the copy to the person designated by the individual. The individual’s request must be in writing, signed by the individual, and clearly identify the designated person and where to send the copy of                

  41. The following must be documented:                  

  42. The designated record sets that are subject to access by individuals; and The titles of the person or offices responsible for receiving and processing requests.

USES AND DISCLOSURES OF PROTECTED HEALTH INFORMATION TO PERSONAL REPRESENTATIVES

An individual’s personal representative will be treated as the individual with respect to the individual’s rights under HIPAA, for example, accounting of disclosures, amendment of PHI, and right to request access to PHI.

PROCEDURE

    

  1. If under applicable state law a person has authority to act on behalf of an individual who is an adult or an emancipated minor in making health care decisions, that person will be treated as the individual’s personal representative and shall have all rights under HIPAA that the individual would have.   

  2. If the individual is an unemancipated minor, his or her personal representative is a parent or guardian with legal authority to make health care decisions on behalf of the minor. There are three circumstances in which the parent is not the personal representative with respect to the minor’s PHI:   

  3. When state or other law does not require the consent of another to perform the health care service given to the minor, the minor consents to the health care service, and the minor has not requested that such other person be treated as the personal representative;  

  4. When a court determines that the minor may obtain the health care service without the consent of a parent or guardian; and  

  5. When a parent agrees to a confidential relationship between the minor and the physician.

  6. State or other law supersedes the access or lack thereof that a parent or guardian has to an unemancipated minor’s PHI.   

  7. If the individual is deceased, the personal representative is the person with the legal authority to act on behalf of the decedent or the estate of the decedent. Water Wellness
    Group shall request reasonable documentation to verify that the personal representative has such legal authority – for example, a court order.

  8. Water Wellness Group may not treat a person as the personal representative if there is a reasonable belief that the individual is being subjected to domestic violence, abuse or neglect by the personal representative or that treating such person as the individual’s personal representative would endanger the individual and Water Wellness

  9. Group concludes that it is not in the best interest of the individual to treat the person as the individual’s personal representative.

USES AND DISCLOSURES OF PROTECTED HEALTH INFORMATION REGARDING DECEASED INDIVIDUALS

The protected health information (PHI) of deceased individuals is subject to the same standards of use and disclosure as applies to the PHI of living individuals for fifty (50) years following the death of the individual.

PROCEDURE   

  1. A person who has the authority under the law to act on behalf of the deceased individual or for their estate will be treated as the decedent’s personal representative for the purpose of using or disclosing the decedent’s PHI.   

  2. Disclosures of PHI to medical examiners, coroners, and funeral directors to carry out their official duties are allowed.   

  3. Disclosure requests from a health provider for the purpose of treating a surviving relative of the deceased are allowed.  

  4. Disclosure requests from a public health authority that is legally authorized to receive such a report is allowed.   

  5. Disclosure requests from a researcher must include an oral or written certification that the use or disclosure is for research purposes using the PHI of the deceased, that the disclosure is necessary for the research, and documentation of the death of the individual whose PHI is sought must be provided.  

  6. Disclosure of PHI may be made regarding an individual after the period of fifty (50) years following the death of the individual.   

  7. PHI of a deceased may be disclosed to a family member, other relative, or close personal friend who does not qualify as a personal representative in Section A above, if such person was involved in the deceased’s care or payment for health care prior to decedent’s death, if the PHI is relevant to such person’s involvement, unless doing so is inconsistent with any prior expressed preference of the decedent that is known to Water Wellness Group.

USES AND DISCLOSURES FOR TREATMENT, PAYMENT, AND HEALTH CARE OPERATIONS

The protected health information (PHI) of deceased individuals is subject to the same standards of use and disclosure as applies to the PHI of living individuals for fifty (50) years following the death of the individual.

PROCEDURE  

   

  1. Definitions:   

  2. Health care operations   

  3. means any of the following activities of Water Wellness Group:

  4. Conducting quality assessment and improvement activities, including outcomes evaluation and development of clinical guidelines, provided that the obtaining of generalizable knowledge is not the primary purpose of any studies resulting from such activities; patient safety activities (as defined in 42 CFR 3.20); population-based activities relating to improving health or reducing health care costs, protocol development, case management and care coordination, contacting of health care providers and patients with information about treatment alternatives; and related functions that do not include treatment;

  5. (2) Reviewing the competence or qualifications of health care professionals, evaluating practitioner and provider performance, health plan performance, conducting training programs in which students, trainees, or practitioners in areas of health care learn under supervision to practice or improve their skills as health care providers, training of non-health care professionals, accreditation, certification, licensing, or credentialing activities;    

  6. (3) Except as prohibited under Section 164.502(a)(5)(i), underwriting, enrollment, premium rating, and other activities related to the creation, renewal or replacement of a contract of health insurance or health benefits, and ceding, securing, or placing a contract for reinsurance of risk relating to claims for health care (including stop-loss insurance and excess of loss insurance), provided that the requirements of 45 CFR 164.514(g) are met, if applicable;   

  7. (4) Conducting or arranging for medical review, legal services, and auditing functions, including fraud and abuse detection and compliance programs;

  8. (5) Business planning and development, such as conducting cost-management and planning-related analyses related to managing and operating the entity, including formulary development and administration, development or improvement of methods of payment or coverage policies; and   

  9. (6) Business management and general administrative activities of Water Wellness Group, including, but not limited to:                   

  10. (i) Management activities relating to implementation of and compliance with the requirements of HIPAA;

  11. (ii) Customer service, including the provision of data analyses for policy holders, plan sponsors, or other customers, provided that PHI is not disclosed to such policy holder, plan sponsor, or customer;

  12. (iii) Resolution of internal grievances;

  13. (iv) The sale, transfer, merger, or consolidation of all or part of Water Wellness
    Group with another covered entity, or an entity that following such activity will become a covered entity and due diligence related to such activity; and                  

  14. (v) Consistent with the applicable requirements of 45 CFR 164.514, creating de-identified health information or a limited data set, and fundraising for the benefit of the covered entity.

  15. Payment means:

  16. The activities undertaken by:

  17. A health plan to obtain premiums or to determine or fulfill its responsibility for coverage and provision of benefits under the health plan (except as prohibited under Section 164.502(a)(5)(i); or

  18. A health care provider or health plan to obtain or provide reimbursement for the provision of health care; and

  19. The activities in paragraph (1) of this definition relate to the individual to whom health care is provided and include, but are not limited to:                 

  20. Determinations of eligibility or coverage (including coordination of benefits or the determination of cost sharing amounts), and adjudication or subrogation of health benefit claims;

  21. Risk adjusting amounts due based on enrollee health status and demographic characteristics;                  

  22. Billing, claims management, collection activities, obtaining payment under a contract for reinsurance (including stop-loss insurance and excess of loss insurance), and related health care data processing;                  

  23. Review of health care services with respect to medical necessity, coverage under a health plan, appropriateness of care, or justification of charges;                  

  24. Utilization review activities, including precertification and preauthorization of services, concurrent and retrospective review of services; and                  

  25. Disclosure to consumer reporting agencies of any of the following PHI relating to collection of premiums or reimbursement:                  

  26. Date of birth;                   

  27. Social security number                  

  28. Payment history;                   

  29. Account number; and                 

  30. Name and address of the health care provider and/or health plan.

  31. Name and address;                 

  32. Treatment means the provision, coordination, or management of health care and related services by one or more health care providers, including the coordination or management of health care by a health care provider with a third party; consultation between health care providers relating to a patient; or the referral of a patient for health care from one health care provider to                   

  33. Except with respect to uses or disclosures that require an authorization under 45 CFR 164.508(a)(2) through (4) or that are prohibited under 45 CFR 164.502(a)(5)(i), Water Wellness
    Group may use or disclose PHI for treatment, payment, or health care operations, as follows (provided such use or disclosure is consistent with other applicable requirements of the Privacy Rule):                

  34. Water Wellness Group may use or disclose PHI for its own treatment, payment, or health care operations.                   

  35. PHI may be disclosed for the treatment activities of another health care provider.                   

  36. PHI may be disclosed to another health care provider, clearinghouse, or health plan for the payment activities of the entity that receives the PHI.                   

  37. PHI may be disclosed to another health care provider, clearinghouse, or health plan for health care operations activities of the entity that receives the PHI, if both Water Wellness
    Group and receiving entity have or had a relationship with the individual who is the subject of the PHI being requested, the PHI pertains to such relationship, and the disclosure is:                   

  38. For a purpose listed in paragraph (1) or (2) of the definition of Health Care Operations under this policy; or                 

  39. For the purpose of health care fraud and abuse detection or                

  40. PHI about an individual may be disclosed to another health care provider, clearinghouse, or health plan that participates in an organized health care arrangement if Water Wellness
    Group also participates in an organized health care arrangement and the disclosure is for any health care operations activities of the organized health care

USES AND DISCLOSURES REQUIRING AGREEMENT OR OBJECTION

The Privacy Regulations allow use and disclose of protected health information (“PHI”) for certain purposes, provided that, except in emergency situations, such use or disclosure is consistent with the individual’s agreement or the individual’s failure to object after being given an opportunity to do so

PROCEDURE   

 

  1. Water Wellness Group may disclose to a family member, other relative, or any other person identified by the individual, the PHI directly relevant to such person’s involvement with the individual’s care or payment related to the individual’s health care.   

  2. Water Wellness Group may use or disclose PHI to notify, or assist in the notification of (including identifying or locating), a family member, a personal representative of the individual, or another person responsible for the care of the individual, of the individual’s location, general condition, or death. Any such use or disclosure of PHI for such notification purposes must be in accordance with Paragraphs 3, 4 and 5 below, as applicable.  

  3. If the individual is present for, or otherwise available prior to, a use or disclosure permitted by Paragraphs 1 or 2 above and has the capacity to make health-care decisions, Water Wellness
    Group may use or disclose the PHI if Water Wellness Group:  

  4. Obtains the individual’s agreement;   

  5. Provides the individual with the opportunity to object to the disclosure, and the individual does not express an objection; or   

  6. reasonably infers from the circumstances, based on the exercise of professional judgment, that the individual does not object to the disclosure.   

  7. If the individual is not present, or the opportunity to agree or object to the use or disclosure permitted by Paragraphs 1 or 2 cannot practicably be provided because of the individual’s incapacity or an emergency circumstance, Water Wellness
    Group may, in the exercise of professional judgment, determine whether the disclosure is in the best interest of the individual and, if so, disclose only the PHI that is directly relevant to the person’s involvement with the individual’s health care, including payment. Water Wellness Group may use professional judgment and its experience with common practice to make reasonable inferences of the individual’s best interest in allowing a person to act on behalf of the individual to pick up filled prescriptions, medical supplies, X-rays, or other similar forms of PHI.  

  8. Water Wellness Group may use or disclose PHI to a public or private entity authorized by law or by its charter to assist in disaster relief efforts, for the purpose of coordinating with such entities the uses or disclosures permitted by Paragraph 2 of this Policy. The requirements in Paragraphs 3 and 4 above apply to such uses and disclosure to the extent that Water Wellness
    Group, in the exercise of professional judgment, determines that the requirements do not interfere with the ability to respond to the emergency circumstances.   

  9. If an individual is deceased, Water Wellness Group may disclose PHI of the individual to a family member, other relative, or close personal friend of the individual, if such person(s) was involved in the individual’s care or payment for health care prior to the individual’s death, if the PHI is relevant to such person(s) involvement, unless doing so is inconsistent with any prior expressed preference of the individual that is known to Water Wellness
    Group.

DISPOSAL OF PROTECTED HEALTH INFORMATION

Appropriate steps must be taken to dispose of any documents, film or hard copy materials that contain protected health information (PHI).

PROCEDURE     

  1. PHI in paper records, film or hard copy materials must be shredded, burned, pulped, or pulverized so that the PHI is rendered unreadable and otherwise cannot be reconstructed. Redaction is specifically prohibited as means of data destruction. In addition, documents cannot be disposed of in a public manner. For example, documents with PHI may not be placed in the regular trash or in a dumpster. If documents are stored pending destruction, for example in a shred bin, the storage device must be locked and otherwise secured.   

  2. Electronic media (discs, phones, thumb drives, hard drives, and copy machines) and all other ePHI must be disposed of in accordance with Water Wellness Group Security Policy on Disposal of ePHI.    

  3. All workforce members must follow this disposal policy at all times

COOPERATION WITH HHS INVESTIGATIONS

Water Wellness Group will cooperate with the Secretary of the United States Department of Health and Human Services (“Secretary”) if the Secretary investigates whether Water Wellness Group has complied with the HIPAA requirements.

PROCEDURE

  1. If any member of the workforce of Water Wellness
    Group receives notice in any form that the Secretary is requesting information or documents from Water Wellness
    Group, the member shall immediately notify Water Wellness
    Group Privacy Official and Security Official.   

  2. The Water Wellness Group Privacy Official and Security Officials shall be in charge of ensuring that Water Wellness
    Group and all employees comply with the requests of the Secretary.   

  3. Water Wellness Group and all members of Water Wellness
    Group workforce shall cooperate fully and in a timely manner with the Secretary during the 

  4. Water Wellness Group will permit access by the Secretary during normal business hours to Water Wellness
    Group facilities, books, records, accounts, and other sources of information, including protected health information (PHI), that are pertinent to ascertaining compliance with the applicable administrative simplification If the Secretary determines that exigent circumstances exist, such as when documents may be hidden or destroyed, Water Wellness
    Group must permit access by the Secretary at any time and without notice.   

  5. If any information required of Water Wellness
    Group during an investigation is in the exclusive possession of any other agency, institution, or person and the other agency, institution, or person fails or refuses to furnish the information, Water Wellness Group must so certify and set forth what efforts Water Wellness Group has made to obtain the information.

DE-IDENTIFICATION OF PROTECTED HEALTH INFORMATION

The Privacy Regulations allow Water Wellness Group to de-identify protected health information (“PHI”). Water Wellness Group will comply with the HIPAA standard for de-identification.

PROCEDURE     

  1. Water Wellness Group may de-identify PHI as follows:    

  2. a person with appropriate knowledge of, and experience with, generally accepted statistical and scientific principles and methods for rendering information not individually identifiable:   

  3. applying such principles and methods, determines that the risk is very small that the information could be used, alone or in combination with other reasonably available information, by an anticipated recipient to identify an individual who is a subject of the information; and  

  4. documents the methods and results of the analysis that justify such determination.   

  5. In the alternative, de-identified information may be created by removing the following identifiers of the individual, or of relatives, employers, or household members of the individual:    

  6. names    

  7. all geographic subdivisions smaller than a State, including street address, city, county, precinct, zip code, and their equivalent geocodes, except for the initial three digits of a zip code if, according to the current publicly available data from the Bureau of the Census:  

  8. the geographic unit formed by combining all zip codes with the same three initial digits contains more than 20,000 people; and   

  9. the initial three digits of a zip code for all such geographic units containing 20,000 or fewer people is changed to 000;                    

  10. all elements of dates (except year) for dates directly related to an individual, including birth date, admission date, discharge date, date of death, and all ages over 89 and all elements of dates (including year) indicative of such age, except that such ages and elements may be aggregated into a single category of age 90 or older;  

  11. telephone numbers;

  12. fax numbers;

  13. electronic mail addresses;                    

  14. social security numbers;

  15. Medical record numbers;

  16. health plan beneficiary numbers;

  17. account numbers;

  18. certificate/license numbers;

  19. vehicle identifiers and serial numbers, including license plate numbers;                 

  20. device identifiers and serial numbers; 2

  21. web Universal Resource Locators (URLs);                   

  22. internet Protocol (IP) address numbers;                   

  23. biometric identifiers, including finger and voice prints;                 

  24. full face photographic images and any comparable images; and                  

  25. any other unique identifying number, characteristic, or code, except as permitted for purposes of re-identification.                  

  26. Water Wellness Group may assign a code or other means of record identification to allow information that has been de-identified to be re-identified by Water Wellness
    Group, provided that:                   

  27. the code or other means of record identification is not derived from or related to information about the individual and is not otherwise capable of being translated so as to identify the individual; and Water Wellness Group does not use or disclose the code or other means of record identification for any other purpose, and does not disclose the mechanism for re-identification.

FUNDRAISING

Water Wellness Group may use limited sets of PHI for the purpose of raising funds.

PROCEDURE   

  1. Water Wellness Group may use, or disclose to a business associate or to an institutionally related foundation, the following PHI for the purpose of raising funds for its own benefit, without an authorization:  

  2. demographic information relating to an individual (name, address, other contact information, age, gender and date of birth);   

  3. dates of health care provided to an individual;  

  4. department of service information;   

  5. treating physician;   

  6. outcome information; and   

  7. health insurance

  8. Water Wellness Group may not use or disclose PHI for fundraising purposes as permitted by Section A. unless a statement that Water Wellness Group may contact an individual to raise funds for Water Wellness Group and that an individual has a right to opt out of receiving such communications is included in Water Wellness
    Group Notice of Privacy Practices;   

  9. Water Wellness Group will include with each fundraising communication it sends to an individual a clear and conspicuous description of how the individual may opt out of receiving any further fundraising communications. The method to opt out may not cause the individual to incur an undue burden or more than a nominal cost. For example, providing a toll free phone number or email address is acceptable.                    

  10. Water Wellness Group must ensure that individuals who decide to opt out of receiving future fundraising communications are not sent such   

  11. Water Wellness Group will not use PHI for any fundraising purposes other than those permitted in Section A unless Water Wellness Group obtains an authorization from the individual.

  12. Water Wellness Group may not condition treatment or payment on the individual’s choice whether or not to opt out of receiving fundraising communications.

  13. Water Wellness Group may provide an individual who has elected not to receive further fundraising communications with a method to opt back in to receive such communications

NOTICE OF PRIVACY PRACTICES

  1. Water Wellness Group will provide notice to all individuals, through a Notice of Privacy Practices (“Notice”), as to the permitted uses and disclosures of their PHI.   

  2. The Notice will be provided to individuals and will comply with the provisions set forth below.   

  3. Water Wellness Group will provide a Notice:  

  4. No later than the date of the first service delivery, including service delivered electronically, to individuals.   

  5. In an emergency situation, as soon as reasonably practicable after the emergency situation.  

  6. Water Wellness Group will provide a Notice upon   

  7. Except in an emergency situation, Water Wellness
    Group will make a good faith effort to obtain a written acknowledgement of the receipt of the Notice, and if not obtained, Water Wellness Group should document its good faith efforts to obtain such acknowledgement and the reasons why the acknowledgement was not obtained.  

  8. Water Wellness Group will have the Notice available at all service delivery sites for individuals to request to take with them and will post the Notice in a clear and prominent location where it is reasonable to expect individuals seeking service to be able to read the Notice.   

  9. If Water Wellness Group maintains a web site, it will prominently post its Notice on the web site and make the Notice available electronically through the web site.                    

  10. Water Wellness Group may provide the Notice to an individual by e-mail, if the individual agrees to electronic Notice and such agreement has not been withdrawn. If Water Wellness
    Group knows that the e-mail transmission has failed, a paper copy of the Notice will be provided to the individual. Provision of electronic Notice by Water Wellness
    Group will satisfy the provisions of this Policy when timely made.

  11. The individual who is the recipient of an electronic Notice retains the right to obtain a paper copy of the Notice from Water Wellness
    Group upon request. The procedure for requesting the paper copy shall be set forth in the Notice.

  12. Water Wellness Group will provide the Notice to individuals in accordance with the implementation specifications set forth in this Policy.

  13. Water Wellness Group will document compliance with the notice requirements, by retaining copies of the Notices issued by Water Wellness
    Group for six years from the date of the Notices’ creation or the date when they last were in effect, whichever is later.                  

  14. The contents of the Notice will comply with the requirements of

ADMINISTRATIVE, PHYSICAL AND TECHNICAL SAFEGUARDS TO PROTECT PHI

Water Wellness Group has in place the appropriate administrative, technical, and physical safeguards to protect the privacy of Protected Health Information (“PHI”).

PROCEDURE    

  1. Before any member of Water Wellness
    Group workforce shall be granted access to PHI, Water Wellness
    Group Privacy Official shall review the member’s job responsibilities and determine whether such member needs access to PHI to perform the member’s job functions. Only members who require access to PHI to perform their job functions will be granted access to PHI. Furthermore, the member shall only have access to the minimum PHI that is necessary for the member to complete his or her job tasks. The Privacy Official shall document for each member the assessment and whether and to what extent access to PHI shall be granted. The Privacy Official shall review each member’s assessment no less than twice each year and each time a member’s job responsibilities   

  2. Each member of the workforce who has access to PHI is responsible for taking appropriate measures to protect the privacy of PHI, including but not limited to, those measures specified in this Policy.   

  3. Individuals shall comply at all times with Water Wellness
    Group Minimum Necessary Policy.  

  4. An Individual should never access PHI unless he or she is authorized to do so.   

  5. Each individual should only use and disclose PHI as directed by the individual’s supervisor and/or Water Wellness
    Group Privacy Official to perform the individual’s job responsibilities. If an individual receives a request to use or disclose PHI other than as directed by the individual’s supervisor or Water Wellness Group Privacy Official, the individual should contact the Privacy Official before such use or disclosure.   

  6. Paper documents containing PHI must be secured in a locked cabinet after business hours. Paper documents containing PHI must be secured in a locked cabinet during business hours if the documents are not in use. Keys to the cabinets will only be provided to the employees who are granted access to the documents and the Privacy Official.   

  7. Each individual is responsible for securing his or her physical space when using paper documents that contain PHI. This means, for example, that individuals who are not authorized to view the documents should not physically be able to view the documents.  

  8. If PHI will be faxed to Water Wellness
    Group, (a) the fax machine will be placed in a location where only authorized recipients of PHI will have access to the fax machine, or (b) the fax recipient will periodically check the fax machine to remove all faxes containing PHI.   

  9. If Water Wellness Group must fax documents containing PHI, such faxes can never be delivered to public places such as to a Kinkos. Faxes can only be sent directly to the business address of the specific authorized                   

  10. Prior to faxing documents containing PHI, the individual must double check the correct fax number of the When routinely faxing to the same fax number; the fax number shall be programmed into the fax machine if possible.  

  11. All faxes containing PHI must contain the following statement: This facsimile, including any attachment(s), is for the sole use of the intended recipient(s) and contains confidential information. Any unauthorized review, use, disclosure or distribution is strictly If you are not the intended recipient, please immediately contact the sender by phone.

  12. If PHI is mailed, it must be mailed using a service which allows tracking such as Fed In addition, the PHI must be sealed within the envelope or outside packaging which instructs the recipient to only open the package if the recipient is the correct intended recipient. The package should include contact information for the recipient to report the receipt of unintended packages.

  13. If PHI must be discussed over the phone each individual should take appropriate precautions such as using a land line and having the discussion in a private area.                    

  14. All offices which contain PHI must be locked and secured after

  15. If paper containing PHI is on the office premise, visitors must be required to check in before entering the office and shall be escorted by a member of Water Wellness
    Group workforce at all times to ensure that the visitor does not have access to PHI. Visitor check-in logs must be

  16. All members of Water Wellness
    Group workforce are prohibited from removing from the office paper materials that contain PHI. For example, an employee may not take papers containing PHI home to work on a

  17. Paper documents containing PHI must be disposed of in compliance with Water Wellness
    Group Disposal Policy. Under no circumstance shall paper containing PHI be disposed of in the trash.

  18. All members of Water Wellness
    Group workforce must comply with the safeguards found in Water Wellness Group Security policies regarding electronic PHI, for example, the proper use of passwords, logging off computers, and disposal of electronic media.

EXCEPTIONS

Requests for an exception to this Policy must be submitted for approval.

VIOLATION AND ENFORCEMENT

Any known violations of this policy should be reported. Violations of this policy can result in immediate withdrawal or suspension of system and network privileges and/or disciplinary action in accordance with company procedures up to and including termination of employment.

Copyright 2025. Waters Wellness. All Rights Reserved.