HIPAA Compliance Policy
Effective Date: February 2, 2020
Last Updated: October 13, 2025
Commitment to Privacy and Security
At Casa Privée, we are committed to protecting the privacy and security of your health information. We comply fully with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), its implementing regulations, and all applicable federal and state privacy laws. Our mission is to ensure that every patient’s medical and personal information is handled with the highest level of confidentiality and integrity.
Protected Health Information (PHI)
“Protected Health Information” (PHI) includes any information that identifies you and relates to your past, present, or future physical or mental health, healthcare services, or payment for healthcare services.
This includes, but is not limited to:
- Name, address, date of birth, or phone number
- Medical records, treatment plans, and lab results
- Insurance and payment information
- Digital health records and telehealth communications
How We Use and Disclose PHI
We use and disclose your PHI only as permitted or required by law. Common uses and disclosures include:
- Treatment:
To coordinate and provide your healthcare services among our clinicians and authorized partners. - Payment:
To obtain payment for your healthcare services from you, your insurer, or other third-party payers. - Healthcare Operations:
To evaluate and improve the quality of our services, train staff, or conduct administrative activities. - Legal and Regulatory Requirements:
When required by law (e.g., reporting infectious diseases, responding to subpoenas, or audits). - With Your Authorization:
Any other use or disclosure not described above requires your explicit written consent, which you may revoke at any time.
Your Rights Under HIPAA
You have important rights regarding your health information, including:
- Right to Access: You may request copies of your medical records in paper or electronic form.
- Right to Amend: You may request corrections to your health information if you believe it is incomplete or inaccurate.
- Right to an Accounting: You may request a list of certain disclosures of your PHI made by our practice.
- Right to Restrict: You may request restrictions on how we use or disclose your information, where legally permissible.
- Right to Confidential Communications: You may request that we communicate with you through specific means or at specific locations.
- Right to File a Complaint: You may file a complaint with our Privacy Officer or with the U.S. Department of Health and Human Services (HHS) if you believe your privacy rights have been violated.
Safeguards to Protect Your Information
We employ administrative, physical, and technical safeguards to ensure your PHI is protected:
- Secure electronic medical records and encrypted communications
- Role-based access controls and authentication protocols
- Regular staff training on HIPAA compliance and confidentiality
- Routine risk assessments and system audits
- Encrypted email and telehealth platforms compliant with HIPAA standards
Telemedicine and Digital Privacy
All virtual consultations and digital communications are conducted via HIPAA-compliant platforms. Video, audio, and chat sessions are encrypted, not stored without authorization, and accessible only to authorized personnel.
Third-Party Partners and Business Associates
We may engage third-party partners (e.g., laboratories, billing services, or IT vendors) who assist in your care or operations. Each partner is contractually bound by a Business Associate Agreement (BAA) to maintain HIPAA-compliant safeguards and confidentiality standards.
Data Breach Notification
In the unlikely event of a data breach involving your PHI, we will notify you promptly in accordance with federal and state laws, outlining the nature of the breach, the affected information, and the corrective actions taken.
Policy Updates
We may revise this HIPAA Compliance Policy periodically. Updates will be posted on this website with the revised effective date. We encourage you to review this page regularly to stay informed of how we protect your information.
Contact Information
For questions, requests, or complaints regarding this policy, please contact:
HIPAA Privacy Officer
Dr. Bankole Johnson
1395 Brickell Ave, Suite 200, Miami, FL, 33131
Email: kole@casaprivee.com
Phone: 305-434-2647
If you are not satisfied with our response, you may contact:
U.S. Department of Health and Human Services, Office for Civil Rights (OCR)
Website: https://www.hhs.gov/ocr/privacy/hipaa/complaints/
✅ Note: This policy is suitable for public website display. For internal compliance, you should also maintain a more detailed HIPAA Procedures Manual (covering staff training, incident response, and technical security standards).
