Notice of Privacy Practices
Last modified: June 12, 2022
This HIPAA Notice of Privacy Practices (“Notice”) will explain the ways in which Avero Diagnostics, a laboratory operations and pathology practice of Northwest Pathology, P.S., (“we” or “us”) protects, uses and discloses your Protected Health Information (“PHI”). This Notice also describes your rights and certain obligations we have regarding the use and disclosure of PHI.
PHI is individually identifiable health information, including identifiable demographic and other information relating to an individual’s past, present, or future physical or mental health, or condition and related health care services.
We are required by law to:
- Maintain the privacy and security of your PHI;
- Give you this Notice of our legal duties and privacy practices with respect to your PHI;
- Comply with the currently effective terms of this Notice.
We will not use or share your PHI other than as described herein unless you tell us we can in writing. If you tell us we can, you may change your mind at any time. Let us know in writing if you change your mind.
See the section below titled “Your Rights with Respect to Your PHI and How to Exercise Them.” The following paragraphs describe examples of the ways we may use and disclose PHI.
For more information see: www.hhs.gov/ocr/privacy/hipaa/understanding/consumers/noticepp.html.
Use for Treatment, Payment or Health Care Operations
For Treatment: We may use or disclose PHI for treatment purposes, including disclosure to physicians, nurses, medical students, pharmacies, and other health care professionals who provide you with health care services and/or are involved in the coordination of your care, such as providing your physician with your laboratory test results.
For Payment: We may use and disclose your PHI so that the services and items you receive from us may be billed to and payment may be collected from you, an insurance company or other third-party payor. For example, we may need to give your insurance company information about the services or items that you received from us so that your insurance company will pay us or reimburse you for the services or items.
For Health Care Operations: We may use or disclose your PHI to carry out health care operations. These are activities that are needed to operate our facilities and for administrative and quality assurance purposes. They include, for example: conducting quality assessment and improvement activities; reviewing the qualifications and performance of health care providers; training and performing accreditation, certification, or licensing activities; and managing our business and performing general administrative activities.
Other Uses and Disclosures of PHI
Listed below are several other examples of ways PHI can be used or disclosed.
Business Associates; Affiliates: We obtain some services provided through contracts with Business Associates in which PHI is disclosed. For example, we may use a third-party for laboratory services and to process, analyze, and deliver your testing results, analysis billing and collections, document destruction, software support and quality assurance. At times, we may disclose your PHI to our business associates so that the Business Associates can provide services to, or on behalf of, us. Any Business Associate who receives your PHI is required to appropriately safeguard your PHI through a written Business Associate Agreement. If our Business Associate discloses the PHI to its own subcontractor, it must enter into a similar agreement with the subcontractor regarding your PHI.
Personal Communication: We may use PHI in our personal communications with you under certain circumstances, such as to provide appointment reminders.
Individuals Involved in Your Care or Payment for Your Care: We may release PHI about you to a friend or family member who is involved in your medical care or who helps to pay for your care. You have the right to object to such disclosure unless you are unable to function or there is an emergency.
Public Health Risks: We may disclose PHI about you for public health activities, including to prevent or control disease, or, when required by law, to notify public authorities concerning cases of abuse or neglect. We may disclose necessary information about you to law enforcement, to family members, or to others if we believe that you may present a serious danger to yourself or others. We may warn others in order to prevent or lessen serious threat to you or to others.
Research: Under certain circumstances, we may use or disclose PHI about you for research purposes. For example, we might disclose PHI for use in a research project involving the effectiveness of certain medical procedures. In some cases, we might disclose PHI for research purposes without your knowledge or approval. However, such disclosures will only be made after evaluating the proposed research project and its use of PHI and balancing the research needs with your need for privacy of your PHI.
Military: If you are a member of the armed forces, we may release PHI about you as required by military command authorities.
About a Decedent: In the event of your death, disclosures about you (the decedent) can be made to family members or others involved in your care or payment for your care prior to your death unless inconsistent with your prior expressed preferences that are known to us. Disclosures may also be made to your personal representative.
As Required by Law: We may use and disclose PHI about you when required to do so by federal, state or local law. Law Enforcement/Legal Proceedings: We may disclose PHI about you for law enforcement purposes as required by law or in response to a court or administrative order. We may disclose PHI about you in response to a subpoena, discovery request or other lawful process by someone else involved in a dispute, but only if efforts have been made to tell you about the request or to obtain an order protecting the information requested.
Additional State and Federal Requirements: Some state and federal laws provide additional privacy protection of your health information. These include:
Sensitive Information. Some types of health information are particularly sensitive, and the law, with limited exceptions, may require that we obtain your written permission or in some instances, a court order, to use or disclose that information. Sensitive health information includes information dealing with genetics, HIV/AIDS, mental health, sexual assault and alcohol and substance abuse.
Information Used in Certain Disciplinary Proceedings. State law may require your written permission if certain health information is to be used in various review and disciplinary proceedings by state health oversight boards.
Information Used in Certain Litigation Proceedings. State law may require your written permission for us to disclose information in certain legal proceedings.
Disclosures to Certain Registries. Some laws require your written permission if we disclose your health information to certain state-sponsored registries.
Uses and Disclosures of PHI that Require Your Written Permission (Authorization): Uses and disclosures of your PHI for purposes other than those referred to in this Notice will be made only with your written authorization. You also have the right to revoke such authorization in writing for any future uses and disclosures. However, it will not stop any uses or disclosures that we have already made before you revoked your authorization.
The disclosure of your records is subject to your authorization if we receive financial remuneration from a third-party whose product or service is the subject of the communication of PHI. Financial remuneration consists of direct or indirect payment to us from, or on behalf of, the third-party whose product is the subject of the communication. We may obtain conditional or unconditional authorizations for research activities provided the authorization differentiates between those that are conditional and those that are unconditional.
If we receive direct or indirect remuneration in exchange for the disclosure of PHI (a so-called “sale” of PHI), an authorization must be obtained from you. A sale of PHI is a disclosure of PHI by us where we or a business associate directly or indirectly receive remuneration from or on behalf of the recipient of the PHI in exchange for the PHI.
We may combine conditional and unconditional authorization for research if we differentiate between the two activities and allow for unconditional research activities. Future research studies may be part of a properly executed authorization which includes all the required core elements of an authorization.
We must obtain an authorization for any use or disclosure of PHI for marketing, except if the communication is in the form of:
- Face-to-face communication made by us to you; or
- A promotional gift of nominal value provided by us.
If the marketing involves financial remuneration to us from a third-party, the authorization must state that such remuneration is involved.
Your Rights with Respect to Your PHI and How to Exercise Them
You have the following rights with respect to your PHI:
Inspect and Copy: You have the right to inspect and copy your PHI maintained by us. Generally, this information includes health care and billing records. You have the right to obtain electronic copies of your PHI. You do not have a right of access to information prepared in anticipation of or for use in, a civil, criminal, or administrative action. Under certain circumstances, you also do not have a right of access to information created or obtained in the course of research involving treatment or received from someone other than a health care provider under a promise of confidentiality.
We may deny your request to inspect and copy your PHI for the reasons set forth above or under certain other limited circumstances. If you are denied access to PHI other than for a reason stated above, you will receive a written denial. You may request that the denial be reviewed. Thereafter, a licensed health care provider chosen by us will review your request and the denial. The person conducting the review will not be the person who originally denied your request. We will comply with the outcome of the review.To inspect and/or obtain copies of your PHI maintained by us you must submit a request online via email at [email protected]; by phone at (360) 527-4580; or in writing to our Privacy Officer at:
Attn: Elaine Luckey, Privacy Officer
3560 Meridian Street, Suite 101
Bellingham, WA 98225
We may charge a fee for the costs of copying, mailing or other expenses associated with complying with your request consistent with federal and state law. You may request that we transmit a copy of your PHI to another person. To do so you must request this in writing, you must sign the request, and it must clearly identify the designated person and where to send the copy of the PHI.
Right to Amend PHI: You may ask us to amend the PHI we have about you. You have the right to request an amendment for so long as the information is kept by or for us. To request an amendment to your PHI, your request must be made in writing and submitted to our Privacy Officer. In addition, you must provide a reason that supports your request. We will generally make a decision regarding your request for amendment no later than sixty (60) days after receipt of your request. However, if we are unable to act on the request within this time, we may extend the time for thirty (30) more days, but we will provide you with a written notice of the reason for the delay and the approximate time for completion. If we deny your requested amendment, we will provide you with a written denial.
We have the right to deny your request for an amendment if it is not in writing or does not include a reason to support the request. We are not required to agree to your request if you ask us to amend PHI that: was not created by us, unless you provide a reasonable basis to believe the originator of the PHI is no longer available to act on the requested amendment; is not part of the PHI kept by or for us; is not part of the PHI which you would be permitted to inspect and copy; or is already accurate and complete.
Right to an Accounting of Disclosures: You have the right to receive an accounting of disclosures of PHI made by us in the six years prior to the date on which the accounting is requested, except for disclosures made under certain circumstances, such as disclosures made to carry out treatment, payment, and health care operations; disclosures made pursuant to a prior authorization by you; or for certain law enforcement purposes.To request this list or accounting of such disclosures, your request must be submitted in writing to our Privacy Officer. Your request must also state a time period, which may not be longer than a period of six (6) years prior to the request. Your request should also specify the format of the list you prefer (i.e., on paper or electronically). The first list you request within any twelve (12) month period will be free. For each subsequent request within the twelve (12) month period, we may charge you for the costs of providing the list. We will notify you of the costs involved and you may choose to withdraw or modify your request at that time before any costs are incurred.
Right to Request Restrictions on Use or Disclosure: You have the right to request that we restrict:
- uses and/or disclosures of PHI about you to carry out treatment, payment or health care operations;
- disclosures to a family member, other relative or a close personal friend of yours or any person identified by you, the PHI directly relevant to that person’s involvement with your health care or payment related to your health care; and
- use or disclosure involving PHI to notify or assist in notification of a family member, a personal representative, or another person responsible for the care of your location, general condition or death.
Except as provided herein, we are not required to agree to a restriction. However, if we do agree, we will comply with your request unless the information is needed to provide you emergency health care treatment.
We must agree to your request to restrict disclosure of PHI about you to a health plan if: (1) the disclosure is for the purpose of carrying out payment or health care operations and is not otherwise required by law; and (2) the PHI pertains solely to a health care item or service for which you, or a person other than the health plan on your behalf, has paid us in full.
We cannot restrict disclosures required by law or requested by the federal government to determine if we are meeting our privacy protection obligations.
To request restrictions, you must make your request in writing to our Privacy Officer. Your request must specify (1) what PHI you want to limit; (2) whether you want to limit our use, disclosure or both; and (3) to whom you want the limits to apply (e.g., disclosures to your spouse).
We may terminate a restriction if you agree to or request a termination in writing, if you orally agree to the termination and the oral agreement is documented, or if we inform you that we are terminating the agreement to a restriction, except that such termination is not effective for PHI restricted as provided in the above paragraph, and is only effective with respect to PHI created or received after we have so informed you.
We will document the restriction and maintain it in written or electronic form for a period of at least six (6) years from the date of its creation of the day when it was last in effect, whichever is later.
Right to Request Confidential Communications: You have the right to request that we communicate with you about your PHI at an alternative address or by alternative means. We will accommodate reasonable requests. Please write to our Privacy Officer to make such a request.
Right to a Paper Copy of this Notice: You can ask for a paper copy of this notice at any time, even if you have agreed to receive it electronically. To obtain a paper copy of this Notice, please write to our Privacy Officer.
Breach of Your Unsecured PHI: We will notify you as required by law in the event we become aware of a reportable breach of your unsecured PHI.
Changes to this Notice: We reserve the right to change our privacy practices that are described in this Notice. We reserve the right to make the revised or changed privacy practices applicable to PHI we already have about you as well as any information we receive in the future. Prior to a material change to the uses or disclosures, your rights, our legal duties or other privacy practices stated in this Notice, we will promptly revise the Notice. The Notice will contain the effective date on the first page. The new notice will be available upon request to our Privacy Officer and on our website.
Complaints: If you believe your privacy rights have been violated, you may file a complaint with us or with the Secretary of the Department of Health and Human Services.
To file a complaint with us, write to our Privacy Officer using the contact information listed under “Contact Us” below. All complaints must be in writing.
Complaints to the Secretary may be filed either in paper or electronically. Complaints may be submitted electronically using the OCR Complaint Portal or mailed to the following address:
Centralized Case Management Operations
U.S. Department of Health and Human Services
200 Independence Avenue, S.W.
Room 509F HHH Bldg.
Washington, D.C. 20201
You will not be penalized or retaliated against for filing a complaint.
For privacy related matters, please contact:
Attn: Elaine Luckey, Privacy Officer
3560 Meridian Street, Suite 101
Bellingham, WA 98225