M - TH: 9:00 - 6:00, F: 9:00 - 5:00, Saturdays: 9:00 - 3:00
info@divinitymedspa.co

HIPAA & Privacy Policy

PRIVACY POLICY

Divinity Med Spa is committed to protecting your privacy. It is important for you to understand that it is not mandatory for you to provide your personally identifiable information or personal healthcare information and other possible information about you to use or visit www.divinitymedspa.co.

During your visit to our website, remember that the medical and health information presented here is intended to be general in nature, and should not be viewed as a substitute for professional advice. Please consult with a health care professional for all matters relating to personal medical and health care issues.

To protect your privacy, you should not submit any information that contains personal healthcare information or personally identifiable information (like name, phone number, email address) regarding your personal situation, as Divinity Med Spa cannot protect the confidentiality of your personal healthcare information or personally identifiable information in such circumstances. Any personal healthcare information or personally identifiable information submitted is done so at your own risk.

Certain health and medical information about you is protected under the Health Insurance Portability and Accountability Act (“HIPAA”) and applicable state law. This information may be provided by you online or offline, or may be collected by us from other methods such as through a health care provider. We protect covered health and medical information as we may be required by HIPAA and applicable state law. Similarly, we may use covered health and medical information as permitted by HIPAA and applicable state law.

To read more about our privacy practices regarding health and medical information under HIPAA, please read below. In the event of any conflict between our HIPAA Notice of Privacy Practices and this Website Privacy Statement, the terms of our HIPAA Notice of Privacy Practices shall control.

We will not collect your personally identifiable information unless it has been clearly provided by you. If you decide to sign up to any tools (newsletters, alerts, participate in games, polls, sweepstakes or other activities, participate in forums or blogs, etc), you will need to provide your personally identifiable information to us along with your clear consent for us to use it.

As we do not control third party websites to which we provide links, the collection and use of your personally identifiable information by such websites shall be subject to the policies and procedures of those third party websites

Divinity Med Spa does not sell, rent, release or trade personal customer information to outside parties. Divinity Med Spa reserves the right to disclose information if necessary to comply with any legal proceedings.

Divinity Med Spa does not sell or distribute healthcare information, but may utilize anonymously submitted health data you give voluntarily for surveys, research projects or data collection.

Divinity Med Spa’s web site may use “cookies” to store information about a visit to its web site. Cookies are text files stored on your computer which can retain small pieces of information between visits to the web site. This way, your personal preferences may be retained between visits. Most web browser software can be configured to refuse cookies or to notify you when a web site attempts to send you a cookie.

Divinity Med Spa reserves the right to make changes to its privacy policy without prior notice. Announcements of such changes will be displayed on this web site.

HIPAA Compliance

Notice of HIPAA Privacy Practices THIS NOTICE DESCRIBES HOW CERTAIN MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION.   To the extent we request and obtain any personal healthcare information (“PHI”) about your medical history and current health that may be protected under the Health Insurance Portability and Accountability Act (“HIPAA”) and applicable state law, this Notice of Privacy Practices explains how that information may be used and shared with others. It also explains your privacy rights regarding this information.

Under HIPAA, certain parties that obtain PHI entities are required by law to abide by the terms of this Notice, to make sure that information that identifies you is kept private, and to provide this Notice of our legal duties and practices with respect to PHI about you. We are also required to notify you in the event there is a breach of your health information.

Uses and Disclosures of your Health Information We may use PHI to carry out treatment, payment and health care operations.

•Treatment is the provision, coordination or management of health care. For example, we may use and disclose your information to consult with a third party or to refer you to other health care providers.

•Payment includes the activities necessary to obtain reimbursement for the provision of health care. For example, we may need to give your health plan information about treatment you received so your health plan will pay us or reimburse you for the treatment.

•Health care operations include the activities necessary for Divinity Med Spa to run its business operations. For example, we may use your information to review treatment and services and to evaluate the performance of our staff.

We may use or disclose your health information:

•When required by federal, state, or local law.

•To support public health activities by reporting as required or authorized by state or federal law. These reports may include the reporting of exposure to a communicable disease or risk of spreading a disease or condition.

•To cooperate with law enforcement officials for certain law enforcement purposes as directed by a court order, warrant, criminal subpoena, or other lawful process.

•To report abuse or neglect.

•To support health oversight activities that are authorized by law, such as administrative or criminal investigations, inspections, licensure or disciplinary actions and other similar activities necessary for appropriate oversight of government benefit programs or functions.

•When required by a coroner or medical examiner for the purpose of identifying a deceased person, determining a cause of death or other duties as required by law.

•When necessary to prevent or lessen a serious and imminent threat to the health and safety of a person or the public and the disclosure is to a person reasonably able to prevent or lessen the threat, as consistent with applicable law and standards.

•For judicial or administrative proceedings, in response to a valid court order, administrative order, a grand jury subpoena, or with your written consent.

•For research purposes, with your written authorization or as permitted by law.

•To business associates to perform functions on Divinity Med Spa’s behalf, if the business associate has signed an agreement to protect the confidentiality of the information.

We may disclose your health information to a family member, other relatives, or a close friend or any other person you identify if the information relates to that person’s involvement in your health care if you consent to such a disclosure. If you are unable to agree or object to the use or disclosure, we may disclose such information as necessary if we determine that it is in your best interest.

We May Use or Disclose Your Health Information for Other Purposes

Only With Your Authorization Your written authorization to use and disclose your health information is required in order for us to:

•Use and disclose psychotherapy notes containing your health information (to the extent we hold any).

•Send marketing communications to you. If we will receive payment for making a marketing communication, we will state this in the authorization.

•Receive payment in exchange for your health information.

In addition to the above situations, any other uses and disclosures of your health information not described elsewhere in this Notice will be made only with your prior written authorization.

Patient Rights Inspect and obtain a copy of your health information. You have a right to inspect and obtain a copy of your health information that is used to make decisions about your care for as long as Divinity Med Spa maintains the information. You may request an electronic copy of this health information that we maintain electronically. This right does not apply to certain health information, including information compiled in reasonable anticipation of or for litigation. Requests for access to health information should be made in writing to the Divinity Med Spa Privacy Office. You may also ask us to provide a copy of this health information to another person. In that case, your written request must be signed by you, must clearly identify the person to whom you want us to send the copy of your health information, and must state where the copy is to be sent. If access is denied, you will be provided with a written explanation that sets forth the basis for the denial, a description of how you may review those rights and a description of how you may complain.

Request an amendment. You have the right to request that Divinity Med Spa amend your health information if it is incorrect or incomplete. Requests for amendment of information should be made in writing to Divinity Med Spa, Privacy Office, and you must provide a reason that supports your request to have the information changed. Divinity Med Spa may deny your request for an amendment if the request is not in writing and submitted to the Privacy Office. In addition, we may deny your request if you ask us to amend information that: (a) was not created by Divinity Med Spa (unless the person or entity that created the information is no longer available to make the amendment); (b) is not part of the medical information kept by Divinity Med Spa; (c) is not part of the information you would be permitted to inspect and copy; or (d) is accurate and complete.

Receive an accounting of disclosures. At your request, Divinity Med Spa will provide you with an accounting of disclosures by Divinity Med Spa of your health information during the six years prior to the date of your request. However, such accounting will not include certain disclosures, such as those made: 1) to carry out treatment, payment or health care operations; 2) directly to you or your personal representatives; or 3) based on your written authorization. If you request more than one accounting within a 12-month period, Divinity Med Spa will charge a reasonable, cost-based fee for each subsequent accounting. Requests for a request of an accounting of disclosures should be made in writing to Divinity Med Spa, Privacy Office.

Request a general restriction. A general restriction is one that restricts or limits our use or disclosure of your health information. To request a general restriction, you must identify in this request: (i) what particular information you would like to limit, (ii) whether you want to limit use, disclosure, or both, and (iii) to whom you want the limits to apply. We will consider your request but are not required to agree. We have the right to terminate the restriction if: (i) you agree orally or in writing to terminate the restriction, or (ii) if we inform you of the termination, which becomes effective only for your health information created or received after we inform you of the termination.

Request a plan restriction. A plan restriction is one that meets the following three conditions: (a) it is to restrict disclosure of your health information to a health plan for purposes of payment or health care operations; (b) the health information relates solely to a health care item or service for which you, or someone on your behalf, has paid us in full; and (c) the disclosure is not otherwise required by law. If you wish to request a plan restriction, you must do so separately for each service visit, and must make your request at the Divinity Med Spa before your visit. Otherwise Divinity Med Spa will automatically submit the claim to your health plan on record, if any, for payment. We will not agree to a plan restriction unless we have first received payment in full for the item or service. We will also not agree to a plan restriction if by law we are required to submit your health information to the plan. If we do agree to a restriction, we will not apply the restriction in the event of an emergency.

Obtain a copy of this Notice. To obtain a paper copy of this notice, contact Divinity Med Spa.

Exercise right through a personal representative. You may exercise your rights through a personal representative as permitted or required by applicable law. Your personal representative may be required to produce evidence of authority to act on your behalf before that person will be given access to your information or allowed to take any action for you.

Complaints. If you desire further information about your privacy rights, are concerned that we have violated your privacy rights, or disagree with a decision that we made about access to PHI, you may contact our Privacy Officer. You may reach our Privacy Officer at the contact information provided below. You may also file written complaints with the relevant local, state, national, or international privacy agency. We will not retaliate against you if you file a complaint with us or any governmental agency.

Divinity Med Spa Duties

This Notice is effective beginning Dec 20, 2015. However, Divinity Med Spa reserves the right to change its privacy practices and this Notice, and to apply the changes to any health information received or maintained by Divinity Med Spa prior to the date of the changes. If the terms of this Notice are changed, a revised version will be available upon request and will be posted in a clear and prominent location. You may access the notice by visiting our website at: www.divinitymedspa.co