HIPPA Notice
HIPAA Compliance Policy
Effective Date: January 1, 2025
At Kennestone Dentist, we are committed to safeguarding the privacy and security of our patients’ health information in compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA). This policy outlines how we protect and manage Protected Health Information (PHI) to ensure confidentiality, integrity, and compliance with applicable laws.
1. What is Protected Health Information (PHI)?
Protected Health Information (PHI) includes any individually identifiable health information that relates to a patient’s:
- Past, present, or future physical or mental health condition
- Healthcare services provided
- Payment for healthcare services
PHI can include names, addresses, phone numbers, Social Security numbers, medical records, insurance information, and any other data that could identify a patient.
2. How We Protect Your PHI
Kennestone Dentist implements strict policies and safeguards to ensure your PHI remains private and secure:
- Physical Safeguards: Access to patient records is restricted to authorized personnel only. Paper records are stored in secure, locked areas.
- Technical Safeguards: Electronic records are protected with encryption, secure passwords, and firewalls. Only authorized staff have access to patient data, and access is monitored.
- Administrative Safeguards: All employees are trained on HIPAA compliance policies, including the proper handling, sharing, and protection of PHI.
3. How We Use and Disclose PHI
We use and disclose PHI only as permitted under HIPAA. Your information may be used or shared for the following purposes:
- Treatment: To provide and coordinate your healthcare, including consultations with specialists or labs.
- Payment: To bill and collect payment for services provided to you, including sharing information with your insurance provider.
- Healthcare Operations: To improve the quality of our services, conduct staff training, or perform administrative tasks.
- As Required by Law: We may disclose PHI if required by law or in response to legal proceedings.
Other uses and disclosures of your PHI will only be made with your written authorization. You have the right to revoke such authorization at any time.
4. Your Rights Regarding PHI
Under HIPAA, you have several important rights related to your PHI, including the following:
- Access to Records: You have the right to request and review your health records. Copies may be provided upon request.
- Amendments: If you believe your PHI contains errors, you have the right to request corrections.
- Accounting of Disclosures: You can request a list of disclosures we’ve made of your PHI, excluding those made for treatment, payment, or healthcare operations.
- Restrictions: You may request restrictions on how your PHI is used or disclosed. While we will consider your request, we are not always required to agree to it.
- Confidential Communications: You can request that we communicate with you in a specific way (e.g., only calling your mobile phone or sending mail to a different address).
- File a Complaint: If you believe your privacy rights have been violated, you have the right to file a complaint with us or with the U.S. Department of Health and Human Services (HHS). Complaints can be filed without fear of retaliation.
5. HIPAA Training and Awareness
All Kennestone Dentist employees and contractors receive regular training on HIPAA compliance and are required to:
- Maintain the confidentiality of PHI at all times.
- Follow all security procedures to safeguard patient information.
- Report any potential privacy breaches immediately.
Failure to comply with HIPAA policies may result in disciplinary action, up to and including termination.
6. Breach Notification Policy
Kennestone Dentist takes any potential or actual breach of PHI seriously. In the event of a breach:
- Affected patients will be notified promptly, as required by law.
- We will investigate the breach, take corrective actions, and implement measures to prevent future occurrences.
- Reports will be filed with the appropriate authorities, including the U.S. Department of Health and Human Services (HHS), if necessary.
7. Third-Party Business Associates
We work with trusted third-party vendors, known as Business Associates, who may have access to PHI to perform certain services (e.g., billing, software support, or lab services). All Business Associates are required to:
- Sign a Business Associate Agreement (BAA) ensuring they will protect your PHI.
- Adhere to all HIPAA requirements when handling patient information.
8. Retention of Records
Patient health records are retained in accordance with federal and state laws. Records will only be retained for as long as necessary to provide care, meet legal requirements, or support healthcare operations.
9. Updates to This Policy
This HIPAA Compliance Policy is effective as of January 1, 2025. We may update or revise this policy as needed to reflect changes in regulations or our practices. Updated versions of the policy will be posted on our website.
10. Contact Us
If you have any questions about this HIPAA Compliance Policy or need to exercise your rights regarding your PHI, please contact us:
- Address: 598 Nancy Street NW, #200, Marietta, GA 30060
- Phone: 404-220-7732
- Email: [email protected]