HIPAA Notice of Privacy Practices
This notice describes how information you submit through this platform may be used and disclosed, and how you can access it. Please review it carefully.
Our responsibilities
We are required by law to maintain the privacy of your protected health information ("PHI"), provide this notice describing our practices, and follow the terms currently in effect.
How we may use and disclose your information
- Care coordination — routing your reported symptoms and contact details to the licensed chiropractor serving your area, so they can schedule an evaluation.
- Operations — internal audit logging, security monitoring, and spam prevention.
- As required by law — for example, in response to a valid court order or subpoena.
We do not use or disclose your information for marketing or sell it to third parties.
Your rights
- The right to request a copy of your record.
- The right to request a correction to your record.
- The right to request an accounting of disclosures.
- The right to request restrictions on certain uses.
- The right to file a complaint if you believe your privacy rights were violated, without retaliation.
To exercise any of these rights, email privacy@usa-digital.com. You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights.
Safeguards
PHI fields are encrypted at rest (AES-256-GCM) and in transit (TLS). Access is role-restricted — a chiropractor partner can only see records routed to their own territory — and every access to a patient record is written to an append-only audit log retained for a minimum of six years. See Security & Compliance for detail.
Breach notification
In the unlikely event of a breach of unsecured PHI, affected individuals and, where required, regulators will be notified without unreasonable delay and in accordance with the HIPAA Breach Notification Rule.
Effective date
This notice is effective as of the date at the top of this page and remains in effect until replaced.
