HIPAA Notice of Privacy Practices | Luma Health

This Notice of Privacy Practices describes how Luma Health may use and disclose your Protected Health Information (PHI) to carry out treatment, payment, or healthcare operations and for other purposes permitted or required by law. It also describes your rights regarding your PHI.

We are required by law to maintain the privacy of your PHI, provide you with this Notice of our legal duties and privacy practices, and abide by the terms of this Notice.

Uses and Disclosures of PHI

We may use and disclose your PHI for the following purposes:

a. Treatment

We may use and disclose your PHI to provide, coordinate, or manage your healthcare and related services. This may include communication with other healthcare providers regarding your treatment and coordinating your care with other providers.

b. Payment

We may use and disclose your PHI to obtain payment for healthcare services provided to you. This may include contacting your insurance company to verify coverage, billing and collection activities, and sharing PHI with healthcare providers, insurance companies, or collection agencies.

c. Healthcare Operations

We may use and disclose your PHI for healthcare operations, including quality assessment and improvement activities, case management, accreditation, licensing, credentialing, and conducting or arranging for medical reviews, audits, or legal services.

d. As Required by Law

We may use and disclose your PHI when required by federal, state, or local law.

e. Public Health and Safety

We may use and disclose your PHI to prevent or control disease, injury, or disability; report child abuse or neglect; report reactions to medications or product issues; and notify individuals who may have been exposed to communicable diseases.

f. Health Oversight Activities

We may disclose your PHI to health oversight agencies for activities authorized by law, including audits, investigations, inspections, and licensure.

g. Judicial and Administrative Proceedings

We may disclose your PHI in response to a court or administrative order, subpoena, discovery request, or other lawful process.

h. Law Enforcement

We may disclose your PHI for law enforcement purposes as authorized by law.

i. Research

We may use and disclose your PHI for research purposes when approved by an Institutional Review Board (IRB) and when appropriate privacy protections are in place.

j. Organ and Tissue Donation

If you are an organ donor, we may disclose your PHI to organizations involved in organ procurement, transplantation, or donation.

k. Workers' Compensation

We may disclose your PHI as necessary to comply with workers' compensation laws and similar programs.

l. Military and Veterans

If you are a member of the armed forces, we may disclose your PHI as required by military authorities.

m. Inmates

If you are an inmate, we may disclose your PHI to correctional institutions or law enforcement officials having lawful custody of you.

Your Rights Regarding PHI

You have the following rights regarding your Protected Health Information:

๐Ÿ“‹
Right to Inspect & Copy

You have the right to inspect and obtain copies of your PHI maintained by us, subject to certain exceptions.

โœ๏ธ
Right to Amend

You have the right to request corrections or amendments to your PHI if you believe it is inaccurate or incomplete.

๐Ÿ“Š
Right to Accounting

You may request an accounting of certain disclosures of your PHI made during the previous six years.

๐Ÿ”’
Right to Request Restrictions

You may request restrictions on our use or disclosure of your PHI. While we will consider all requests, we are not required to agree to them.

๐Ÿ’ฌ
Right to Confidential Communications

You may request that communications regarding your PHI be made through specific methods or at specific locations.

๐Ÿ“„
Right to Paper Copy

You may obtain a paper copy of this Notice at any time, even if you previously agreed to receive it electronically.

๐Ÿ””
Right to Be Notified of a Breach

You have the right to receive notification if a breach of your unsecured PHI occurs.

Transmission of PHI

We are committed to protecting the privacy and security of your PHI. Any electronic transmission of PHI will comply with the Health Insurance Portability and Accountability Act (HIPAA), including the use of Secure Socket Layer (SSL) encryption or equivalent technologies and adherence to applicable security standards.

Changes to This Notice

We reserve the right to revise this Notice at any time. Any revised Notice will apply to all PHI we maintain, including information collected before the revision date. Updated versions will be posted on our website and made available upon request.

Complaints

If you believe your privacy rights have been violated, you may file a complaint with our Privacy Officer or with the Secretary of the U.S. Department of Health and Human Services.

You will not be retaliated against for filing a complaint. All complaints are taken seriously and handled in accordance with applicable federal and state law.

Contact Information

To exercise your rights or obtain additional information about this Notice, please contact us:

Luma Health Privacy Office

Address 8 The Green, Dover, Delaware 19901, United States

State-Specific Privacy Rights

Certain states provide additional privacy protections beyond HIPAA. Luma Health complies with all applicable state privacy laws, including those related to mental health records, HIV/AIDS information, genetic testing data, substance use treatment records, and other sensitive health information where required.

  • California

    California residents may have additional rights under the Confidentiality of Medical Information Act (CMIA), including rights related to electronic access, marketing restrictions, sale of PHI, and protections for minors receiving sensitive healthcare services.

  • New York

    We comply with New York laws protecting HIV-related information, mental health records, and genetic testing information.

  • Texas

    We comply with the Texas Medical Privacy Act and applicable requirements concerning electronic PHI safeguards and consent-based disclosures.

  • Florida

    We comply with Florida laws regarding mental health records, HIV/AIDS-related information, and substance abuse treatment records.

  • Illinois

    We comply with Illinois privacy laws protecting mental health, HIV/AIDS, and genetic testing information and provide breach notifications as required by law.

  • Massachusetts

    We comply with Massachusetts laws governing the protection of mental health, HIV/AIDS, and genetic testing information and maintain appropriate security safeguards.

For additional information regarding state-specific privacy rights, please contact our Privacy Officer at [email protected].