HIPAA Compliance
1. Introduction
Seven Reveries ("we," "our," or "us"), operating under the medical oversight of MTEP Medical PC, a licensed California professional medical corporation, working with Reveris Inc. for scheduling and administrative support, is dedicated to protecting the privacy, security, and confidentiality of all client Protected Health Information (PHI) in compliance with the Health Insurance Portability and Accountability Act (HIPAA) of 1996 and applicable federal and state regulations.
This HIPAA Compliance Statement explains how we collect, use, store, and protect your health-related information, as well as your rights regarding your PHI. By using our website, scheduling an appointment, or receiving our services, you acknowledge and agree to the terms outlined in this policy.
2. What is Protected Health Information (PHI)?
PHI refers to any individually identifiable health information that is created, received, stored, or transmitted by Seven Reveries in relation to your healthcare services. This includes:
- Your full name, address, phone number, and date of birth
- Your medical history, treatment plans, and healthcare services received
- Your insurance and billing details
- Any other information that can be used to identify you in a medical or healthcare context
We are required by law to maintain the privacy of your PHI and to provide you with this statement outlining our legal duties and privacy practices.
3. How We Use and Disclose Your PHI
3.1 Permitted Uses of PHI
- For Treatment: We use PHI to provide our services, assess medical history, coordinate care, and ensure safe administration of treatments.
- For Payment: We use PHI to process payments, verify insurance coverage, and manage billing for our services.
- For Healthcare Operations: We use PHI to conduct quality assurance, staff training, compliance monitoring, and administrative record-keeping.
3.2 Limited Disclosures Without Client Consent
We may disclose PHI without your written consent in certain legally required situations, including:
- Public Health Reporting: Reporting infectious diseases, adverse reactions, or product recalls to government authorities.
- Legal and Regulatory Compliance: When required by law, court order, or subpoena.
- Medical Emergencies: To prevent serious threats to health and safety.
- Law Enforcement Requests: For criminal investigations, fraud prevention, or legal inquiries.
3.3 Disclosures Requiring Written Authorization
We will obtain your written authorization for any PHI disclosures not covered under permitted uses. Examples include:
- Marketing or promotional communications involving PHI
- Disclosure of PHI to third-party researchers
- Sharing PHI with non-treatment/payment/operations entities
You may revoke your authorization at any time by submitting a written request to Seven Reveries.
4. Your HIPAA Privacy Rights
4.1 Right to Access Your PHI
You may request a copy of your medical records or treatment history. A reasonable fee may apply.
4.2 Right to Request Amendments
You may request corrections to inaccurate or incomplete PHI.
4.3 Right to Restrict Disclosures
You may request limitations on how we use or share your PHI, subject to legal constraints.
4.4 Right to Confidential Communications
You may request specific methods of communication (e.g., phone, email, mail) for receiving PHI.
4.5 Right to an Accounting of Disclosures
You may request a list of non-routine PHI disclosures.
4.6 Right to File a Complaint
If you believe your HIPAA rights were violated, you may file a complaint with:
- Seven Reveries' Privacy Officer
- The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR)
We do not retaliate against individuals who file complaints.
5. How We Protect Your PHI
5.1 Administrative Safeguards
- HIPAA training for employees
- Access controls for authorized personnel only
- Documented policies for PHI handling and disposal
5.2 Physical Safeguards
- Locked file cabinets for paper records
- Restricted areas for staff only
5.3 Technical Safeguards
- Encrypted digital PHI
- Secure electronic health record (EHR) systems
- Firewalls and access protocols
In case of a data breach, affected individuals will be notified per HIPAA's Breach Notification Rule.
6. Third-Party Business Associates
Seven Reveries may partner with business associates (e.g., payment processors, scheduling platforms) who handle PHI. All associates:
- Must sign a Business Associate Agreement (BAA)
- Are required to follow HIPAA-compliant protocols
7. HIPAA Breach Notification Policy
7.1 What Constitutes a HIPAA Breach?
Any unauthorized access, use, or disclosure of PHI that compromises privacy.
7.2 Breach Response Protocol
In the event of a breach, we will:
- Investigate and assess the scope
- Notify affected individuals within 60 days
- Report to HHS as necessary
- Take corrective actions
Notifications may be delivered by phone, email, or written notice.
8. Retention of Health Records
We retain PHI and medical records for the legally mandated period, after which they are securely disposed of in accordance with HIPAA.
9. Changes to This HIPAA Compliance Statement
We may update this statement as laws or practices evolve. Changes will be posted on our website. Continued use of services implies acceptance of updates.
10. Contact Information
If you have questions, wish to exercise your rights, or need to file a complaint, contact:
Seven Reveries · info@reveriesglobal.com