HIPAA Notice of Privacy Practices
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED, AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
Our Duties
The law requires us to:
- Keep your PHI private.
- Give you this Notice describing our legal duties and privacy practices.
- Follow the terms of the Notice that is currently in effect.
- Notify you promptly if a breach of your unsecured PHI occurs.
How We May Use and Share Your PHI
Without your written authorization, we may use your PHI to:
- Treat you — coordinate care with your case manager, medical providers, and mental-health clinicians.
- Get paid — bill funders, grants, and health-plan payers for services provided under the program.
- Operate our program — quality assurance, training, licensing audits, milestone tracking.
- Follow the law — comply with court orders, subpoenas, and mandatory reporting statutes (child welfare, elder protection, communicable disease).
- Respond to emergencies — protect your life or the safety of others.
- Support research — only with de-identified data or IRB-approved authorization.
With your written authorization, we will:
- Share PHI with people or organizations you name.
- Use your PHI in marketing materials or public testimony.
- Sell your PHI (we do not currently do this and have no plans to).
- Share psychotherapy notes.
You may revoke your authorization in writing at any time. We cannot take back disclosures already made.
Your Rights
You have the right to:
- Inspect and copy your PHI. We may charge a reasonable fee for copies.
- Request corrections to your record. We must respond within 60 days.
- Request an accounting of disclosures we have made in the last six years (some exceptions apply).
- Request restrictions on certain uses and disclosures. We must agree if you paid out-of-pocket for a service and ask us not to share the information with your health plan.
- Request confidential communications — for example, that we contact you at a specific phone number or by mail only.
- Get a paper copy of this Notice at any time by asking your case manager.
- File a complaint if you believe your privacy rights have been violated — see below.
How to Exercise Your Rights
Send all requests to our HIPAA Privacy Officer:
- Email: privacy@theexchangealliance.org
- Mail:
[Registered mailing address — Horry County, SC — to be finalized before live deployment], ATTN: HIPAA Privacy Officer
We will respond within 30 days.
How to File a Complaint
You may file a complaint with us, and separately with the U.S. Department of Health & Human Services. We will not retaliate against you for filing a complaint.
- With us: privacy@theexchangealliance.org
- With HHS: Office for Civil Rights, 200 Independence Avenue SW, Washington, DC 20201 · 1-877-696-6775 · hhs.gov/hipaa/filing-a-complaint
Breach Notification
If a breach of your unsecured PHI occurs, we will notify you in writing within 60 days of discovery, as required by 45 CFR § 164.404. If the breach affects more than 500 individuals, we will also notify HHS and prominent media in your state.
Business Associate Agreements
When we work with contractors who need to access PHI to perform work for us — hosting providers, email vendors, analytics processors — we require them to sign a Business Associate Agreement (BAA) that binds them to the same HIPAA obligations we follow. You may request or execute a BAA with us directly at /legal/baa.
Technical Safeguards Summary
The Platform implements the technical safeguards required by the HIPAA Security Rule (45 CFR § 164.312), including:
- Unique user identification, automatic logoff, and encryption/decryption of PHI at rest and in transit.
- Audit controls that record every access to PHI, retained 7 years.
- Integrity controls to prevent unauthorized alteration or destruction.
- Person-or-entity authentication (MFA required for all staff).
- Transmission security via TLS 1.3.
Full detail is on our Security & Compliance page.
Changes to This Notice
We reserve the right to change this Notice and to make the new terms effective for all PHI we maintain. We will post the current Notice on this page and provide a copy to enrolled participants on request.
Contact
- HIPAA Privacy Officer: privacy@theexchangealliance.org
- Compliance Officer: compliance@theexchangealliance.org
- Executive Director: William Smith · william@theexchangealliance.org
