Last revised April 2020
Your Information. Your Rights. Our Responsibilities.
2. HIPAA. In addition, the healthcare providers from the CARECLIX Network group that you interact with when using the Services are required by the Health Insurance Portability and Accountability Act (“HIPAA”) to describe their privacy practices in document called a Notice of Privacy Practices. You can access a copy of this notice on the patient portal. Identifiable health information (also called protected health information, or PHI). In conducting our business, we will create records regarding you and the treatment and services we provide to you.
We are required by law to maintain the confidentiality of health information that identifies you. We also are required by law to provide you with this notice of our legal duties and the privacy practices that we maintain in our telemedicine practice concerning your PHI. By federal and state law, we must follow the terms of the Notice of Privacy Practices that we have in effect at the time. We realize that these laws are complicated, but we must provide you with the following important information:
How we may use and disclose your PHI
Your privacy rights in your PHI
Our obligations concerning the use and disclosure of your PHI. The terms of this notice apply to all records containing your PHI that are created or retained by CareClix. We reserve the right to revise or amend this Notice of Privacy Practices. Any revision or amendment to this notice will be effective for all of your records that CareClix has created or maintained in the past, and for any of your records that we may create or maintain in the future. CareClix will post a copy of our current Notice in your Personal health record at www.careclixemr.com/patientlogin, and you may request a copy of CareClix’s most current Notice at any time.
If you have questions about this Notice, please contact: [email protected], RN at 1-855-CARECLX
CareClix may use and disclose your PHI in the following ways: The following categories describe the different ways in which we may use and disclose your PHI. Treatment: CareClix may use your PHI to treat you. For example, we may ask you to have laboratory tests (such as blood or urine tests), and we may use the results to help us reach a diagnosis. CareClix might use your PHI in order to write a prescription for you, or we might disclose your PHI to a pharmacy when ordering a prescription for you. Many of the people who work for CareClix– including, but not limited to, our doctors and nurses – may use or disclose your PHI in order to treat you or to assist others in your treatment. Additionally, CareClix may disclose your PHI to others who may assist in your care, such as your spouse, children or parents. Finally, CareClix may also disclose your PHI to other health care providers for purposes related to your treatment.
Payment: CareClix may use and disclose your PHI in order to bill and collect payment for the services and items you may receive from us. For example, we may contact your health insurer to certify that you are eligible for benefits (and for what range of benefits), and we may provide your insurer with details regarding your treatment to determine if your insurer will cover, or pay for, your treatment.
CareClix may also use and disclose your PHI to obtain payment from third parties that may be responsible for such costs, such as family members.
Also, CareClix may use your PHI to bill you directly for services and items. We may disclose your PHI to other healthcare providers and entities to assist in their billing and collection efforts.
Health care operations CareClix may use and disclose your PHI to operate our business. As examples of the ways in which we may use and disclose your information for our operations, our practice may use your PHI to evaluate the quality of care you received from us or to conduct cost-management and business planning activities for our practice. We may disclose your PHI to other health care providers and entities to assist in their health care operations.
Optional Appointment Reminders: CareClix may use and disclose your PHI to contact you and remind you of an appointment.
Optional Treatment Options: CareClix may use and disclose your PHI to inform you of potential treatment options or alternatives.
Optional Health-Related Benefits and Services: CareClix may use and disclose your PHI to inform you of health-related benefits or services that may be of interest to you.
Optional Release Of Information To Family/Friends: CareClix may release your PHI to a friend or family member that is involved in your care, or who assists in taking care of you. For example, a parent or guardian may ask that a baby sitter take their child to the pediatrician’s office for treatment of a cold. In this example, the baby sitter may have access to this child’s medical information.
Disclosures Required By Law: CareClix will use and disclose your PHI when we are required to do so by federal, state or local law.
Use and disclosure of your PHI in certain special circumstances: The following categories describe unique scenarios in which we may use or disclose your identifiable health information:
Public health risks CareClix may disclose your PHI to public health authorities that are authorized by law to collect information for the purpose of:
Maintaining vital records, such as births and deaths
Reporting child abuse or neglect
Preventing or controlling disease, injury or disability
Notifying a person regarding potential exposure to a communicable disease
Notifying a person regarding a potential risk for spreading or contracting a disease or condition
Reporting reactions to drugs or problems with products or devices
Notifying individuals if a product or device they may be using has been recalled
Notifying appropriate government agency(ies) and authority(ies) regarding the potential abuse or neglect of an adult patient (including domestic violence); however, we will only disclose this
information if the patient agrees or we are required or authorized by law to disclose this information,
Notifying your employer under limited circumstances related primarily to workplace injury or illness or medical surveillance.
Health oversight activities: CareClix may disclose your PHI to a health oversight agency for activities authorized by law. Oversight activities can include, for example, investigations, inspections, audits, surveys, licensure, and disciplinary actions; civil, administrative and criminal procedures or actions; or other activities necessary for the government to monitor government programs, compliance with civil rights laws and the health care system in general.
CareClix may use and disclose your PHI in response to a court or administrative order if you are involved in a lawsuit or similar proceeding. We also may disclose your PHI in response to a discovery request, subpoena or other lawful processes by another party involved in the dispute, but only if we have made an effort to inform you of the request or to obtain an order protecting the information the party has requested.
Law Enforcement: CareClix may release PHI if asked to do so by a law enforcement official:
Regarding a crime victim in certain situations, if we are unable to obtain the person’s agreement.
Concerning a death we believe has resulted from criminal conduct.
Regarding criminal conduct at our offices.
In response to a warrant, summons, court order, subpoena or similar legal process
To identify/locate a suspect, material witness, fugitive or missing person.
In an emergency, to report a crime (including the location or victim(s) of the crime, or the description, identity or location of the perpetrator).
Optional: Deceased patients. CareClix may release PHI to a medical examiner or coroner to identify a deceased individual or to identify the cause of death. If necessary, we also may release information in order for funeral directors to perform their jobs.
Organ and tissue donation: CareClix may release your PHI to organizations that handle organ, eye or tissue procurement or transplantation, including organ donation banks, as necessary to facilitate organ or tissue donation and transplantation if you are an organ donor.
Optional Research: Our CareClix may use and disclose your PHI for research purposes in certain limited circumstances. CareClix will obtain your written authorization to use your PHI for research purposes except when an Internal Review Board or Privacy Board has determined that the waiver of your authorization satisfies all of the following conditions:
The use or disclosure involves no more than a minimal risk to your privacy based on the following:
An adequate plan to protect the identifiers from improper use and disclosure;
An adequate plan to destroy the identifiers at the earliest opportunity consistent with the research (unless there is a health or research justification for retaining the identifiers or such retention is otherwise required by law); and adequate written assurances that the PHI will not be re-used or disclosed to any other person or entity (except as required by law) for authorized oversight of the research study, or for other research for which the use or disclosure would otherwise be permitted.
The research could not practicably be conducted without the waiver.
The research could not practicably be conducted without access to and use of the PHI.
Serious threats to health or safety: CareClix may use and disclose your PHI when necessary to reduce or prevent a serious threat to your health and safety or the health and safety of another individual or the public. Under these circumstances, we will only make disclosures to a person or organization able to help prevent the threat.
Military: CareClix may disclose your PHI if you are a member of U.S. or foreign military forces (including veterans) and if required by the appropriate authorities.
National security: CareClix may disclose your PHI to federal officials for intelligence and national security activities authorized by law. We also may disclose your PHI to federal and national security activities authorized by law. We also may disclose your PHI to federal officials in order to protect the president, other officials or foreign heads of state, or to conduct investigations.
Inmates: CareClix may disclose your PHI to correctional institutions or law enforcement officials if you are an inmate or under the custody of a law enforcement official. Disclosure for these purposes would be necessary: for the institution to provide health care services to you, for the safety and security of the institution, and/or to protect your health and safety or the health and safety of other individuals.
Workers’ compensation: CareClix may release your PHI for workers’ compensation and similar programs.
Your rights regarding your PHI: You have the following rights regarding the PHI that CareClix maintains about you:
Confidential Communications: You have the right to request that CareClix communicate with you about your health and related issues in a particular manner or at a certain location. For instance, you may ask that we contact you at home, rather than work. In order to request a type of confidential communication, you must make a written request to insert name or title and telephone number of a person or office to contact for further information specifying the requested method of contact, or the location where you wish to be contacted. CareClix will accommodate reasonable requests. You do not need to give a reason for your request.
Requesting Restrictions: You have the right to request a restriction in our use or disclosure of your PHI for treatment, payment or health care operations. Additionally, you have the right to request that we restrict our disclosure of your PHI to only certain individuals involved in your care or the payment for your care, such as family members and friends. CareClix is not required to agree to your request to restriction; however, if we do agree, we are bound by our agreement except when otherwise required by law, in emergencies or when the information is necessary to treat you. In order to request a restriction in our use or disclosure of your PHI, you must make your request in writing to [email protected], RN at 1-855-CARECLX. Your request must describe in a clear and concise fashion:
The information you wish restricted.
Whether you are requesting to limit our practice’s use, disclosure or both,
To whom you want the limits to apply.
Inspection and Copies: You have the right to inspect and obtain a copy of the PHI that may be used to make decisions about you, including patient medical records and billing records, but not including psychotherapy notes. You must submit your request in writing to [email protected], RN at 1-855-CARECLXin order to inspect and/or obtain a copy of your PHI. CareClix may charge a fee for the costs of copying, mailing, labor and supplies associated with your request. CareClix may deny your request to inspect and/or copy in certain limited circumstances; however, you may request a review of our denial. Another licensed health care professional chosen by us will conduct reviews.
Amendment: You may ask CareClix to amend your health information if you believe it is incorrect or incomplete, and you may request an amendment for as long as the information is kept by or for CareClix. To request an amendment, your request must be made in writing and submitted to [email protected], RN at 1-855-CARECLX. You must provide us with a reason that supports your request for amendment. CareClix will deny your request if you fail to submit your request (and the reason supporting your request) in writing.
Also, we may deny your request if you ask us to amend information that is in our opinion:
Accurate and complete;
Not part of the PHI kept by or for CareClix;
Not part of the PHI which you would be permitted to inspect and copy; or
Not created by CareClix, unless the individual or entity that created the information is not available to amend the information.
Accounting of Disclosures: All of our patients have the right to request an “Accounting of disclosure.” An “accounting of disclosures” is a list of certain non-routine disclosures our practice has made of your PHI for purposes not related to treatment, payment or operations. Use of your PHI as part of the routine patient care in our practice is not required to be documented – for example, the doctor sharing information with the nurse, or the billing department using your information to file your insurance claim. In order to obtain an accounting of disclosures, you must submit your request in writing to [email protected], RN at 1-855-CARECLX. All requests for an “accounting of disclosures” must state a time period, which may not be longer than seven (7) years from the date of disclosure and may not include dates before April 14, 2003. The first list you request within a 12-month period is free of charge, but CareClix may charge you for additional lists within the same 12-month period. CareClix will notify you of the costs involved with additional requests, and you may withdraw your request before you incur any costs.
Right To a Paper Copy of This Notice: You are entitled to receive a paper copy of our notice of privacy practices. You may ask us to give you a copy of this notice at any time.
To obtain a paper copy of this notice, contact [email protected], RN at 1-855-CARECLX.
Right to file a complaint: If you believe your privacy rights have been violated, you may file a complaint with CareClix or with the Secretary of the Department of Health and Human Services. To file a complaint with CareClix, contact [email protected] or 1-855-CARECLX. All complaints must be submitted in writing. You will not be penalized for filing a complaint. Right to provide authorization for other uses and disclosures: CareClix will obtain your written authorization for uses and disclosures that are not identified by this notice or permitted by applicable law. Any authorization you provide to us regarding the use and disclosure of your PHI may be revoked at any time in writing. After you revoke your authorization, we will no longer use or disclose your PHI for the reasons described in the authorization.
Please note: CareClix is required to retain records of your care.
5. The Personal Information We Collect or Maintain: The personal information we collect or maintain may include:
Your name, age, email address, username, password, and other registration information.
Health Information that you provide us, which may include information or records relating to your medical or health history, health status and laboratory testing results, diagnostic images, and other health-related information.
Health information about you prepared by the health care provider(s) who provide the Services through the Site such as medical records, treatment, and examination notes, and other health-related information.
Billing information that you provide us.
Information about the computer or mobile device you are using, such as what Internet browser you use, the kind of computer or mobile device you use, and other information about how you use the Site.
Other information you input into the Site or related services.
6. Use of Personal Information: We may use your Personal Information for the following purposes (subject to applicable legal restrictions):
To provide you with the Services
To improve the services offered – by performing quality reviews and similar activities
To create De-identified Information such as aggregate statistics relating to the use of the Service
To notify you when Site updates are available,
To market and promote our Site and the Services offered to you through the Site
To fulfill any other purpose for which you provide us Personal Information
For any other purpose for which you give us authorization
You can “opt-out” of receiving direct marketing or market research information by emailing us at [email protected]
7. Disclosure of Personal Information: We may also disclose Personal Information that we collect or you provide as permitted or allowed by law, as follows:
To our wholly-owned subsidiary, breakthrough, and affiliated medical groups.
To contractors, service providers and other third parties we use to support our business and who are bound by contractual obligations to keep personal information confidential and use it only for the purposes for which we disclose it to them.
As required by law, which can include providing information as required by law, regulation, subpoena, court order, legal process or government request.
When we believe in good faith that disclosure is necessary to protect your safety or the safety of others, to protect our rights, to investigate fraud, or to respond to a government request.
To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution or other sale or transfer of some or all of CARECLIX’s assets, whether as a going concern or as part of bankruptcy, liquidation or similar proceeding, in which Personal Information maintained by the Site is among the assets transferred.
8. Information We Collect Via Technology: As you use the Site or the Service, certain information may be passively collected by Cookies, navigational data like Uniform Resource Locators (URLs) and third-party tracking services, including:
Site Activity Information. We may keep track of some of the actions you take on the Site, such as the content of searches you perform on the Site.
Access Device and Browser Information. When you access the Site from a computer or other device, we may collect anonymous information from that device, such as your Internet protocol address, browser type, connection speed and access times.
Real-Time Location. Certain features of the Site use GPS technology to collect real-time information about the location of your device so that the Site can connect you to a health care provider who is licensed or authorized to provide services in the state where you are located.
9. De-Identified Information: We may use De-Identified Information created by us without restriction.
10. Security of Information Collected: We use industry-standard physical, technical and administrative security measures and safeguards to protect the confidentiality and security of your Personal Information. Specifically, the Site is protected by SSL 3.0 technology, the leading security protocol for data transfer on the Internet. However, since the Internet is not a 100% secure environment, we cannot guarantee, ensure, or warrant the security of any information you transmit to us. There is no guarantee that information may not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards. Even though there are many benefits to using this Site, as with all electronic communications there are some risks such as (i) failure of hardware, software and/or Internet connections; we are not responsible for failures, distortions, delays, or other problems resulting from equipment configuration, connection, signal power, hardware, software or any equipment used to access the internet; and (ii) no guarantee that the confidentiality or security of electronic transmissions via the Internet can be assured due to potentially unsecure computers and links. This could result in your data becoming lost or intercepted during transmission. It is your responsibility to protect the security of your login information and to use good judgment before deciding to send information via the Internet. Please note that e-mails and other communications you send to us through our Site are not encrypted, and we strongly advise you not to communicate any confidential information through these means.
11. Modification of Information: You can update some of your personal information through our Site. Requests to modify any information may also be submitted directly to [email protected]
12. Deletion of Information: You can close your online account by emailing us at [email protected] If you close your account, we will no longer use your online account information or share it with third parties. We may, however, retain a copy of the information for archival purposes, and to avoid identity theft or fraud.
13. Report Violations: You should report any security violations to us by sending an email to [email protected]
14. A Special Note about Children and Minors: CARECLIX does not knowingly allow individuals under the age of 18 to create accounts that allow access to our Site or use the Services. If you are below the age of 18 you are not permitted to use this Site or the Services.
15. Other Applicable Law: California Residents have special protections under state law regarding the access and use of personal information. CA Civil Code Sec. 1798.80-1978.84.
206 N Washington Street Suite 100
Alexandria VA, 22314
CareClix has further committed to refer unresolved privacy complaints under the US-EU Safe Harbor Principles to an independent dispute resolution mechanism, the BBB EU SAFE HARBOR, operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed by CareClix, please visit the BBB EU SAFE HARBOR web site at www.bbb.org/us/safe-harbor-complaints for more information and to file a complaint.