HIPAA Notice of Privacy Practices
Effective: May 12, 2026
1. Our Legal Duty
Immaculate.Care is committed to protecting the privacy and security of your Protected Health Information (PHI). This notice describes how medical information about you may be used and disclosed, and how you can get access to this information.
2. How We Use and Disclose Your PHI
We use and disclose your PHI for the following permitted purposes:
- Treatment: To provide care and healthcare services to you
- Payment: To obtain payment for services provided and process insurance claims
- Operations: To conduct facility and business operations, including:
- Quality improvement and care optimization
- Predictive health analytics to prevent complications
- Staff scheduling and caregiver wellness monitoring
- Cost tracking and financial management
- Volunteer advocate matching for resident engagement
- Incident prevention and trend analysis
- Legal Compliance: When required by federal, state, or local law
- Public Health: To report public health or safety issues as required by law
- Law Enforcement: When required by legal process (subpoena, warrant)
- Family Notification: To notify family members or emergency contacts of your condition
- Care Coordination: To share with other healthcare providers involved in your care
- Research: Aggregated, de-identified data only (with proper authorization if identifiable)
3. Uses and Disclosures We May NOT Make Without Your Permission
- Marketing communications
- Sale of your information
- Fundraising activities
- Psychotherapy notes (except as required by law)
4. Your Rights
You have the following rights regarding your PHI:
- Right to Access: You can request to see or get copies of your PHI
- Right to Amend: You can ask us to correct inaccurate information
- Right to an Accounting: You can request a list of disclosures of your PHI
- Right to Confidential Communication: You can request we communicate with you in a certain way
- Right to Restrict Use: You can request restrictions on uses or disclosures
5. Our Responsibilities
Immaculate.Care is required to:
- Maintain the privacy and security of your PHI
- Provide you with this notice
- Notify you if there is a breach of your PHI
- Follow the terms of our current privacy practices
6. Security Safeguards
Immaculate.Care implements comprehensive safeguards to protect your PHI:
- Administrative Safeguards:
- Access controls (role-based permissions)
- User authentication (passwords, multi-factor)
- Comprehensive audit logging (all actions tracked)
- Security training for all staff (annual requirement)
- Background checks for staff with PHI access
- Physical Safeguards:
- Secure data centers with restricted access
- Video surveillance and alarm systems
- Workstation security policies
- Device encryption for mobile access
- Technical Safeguards:
- AES-256 encryption at rest
- TLS 1.3 encryption in transit
- Firewalls and intrusion detection
- Regular security patches and updates
- Intrusion prevention systems
- Data integrity verification
- Ongoing Assessments:
- Annual HIPAA compliance audits
- SOC 2 Type II certification (annual)
- Quarterly vulnerability assessments
- Monthly penetration testing
- Continuous security monitoring
7. Complaints
If you believe your privacy has been violated, you may file a complaint with:
Immaculate.Care Privacy Officer
Email: richy@immaculate.care
Phone: 1-800-CARE-NOW
U.S. Department of Health and Human Services
Office for Civil Rights
200 Independence Avenue, S.W.
Washington, D.C. 20201
8. Business Associate Agreements
Immaculate.Care is compliant with HIPAA requirements and maintains Business Associate Agreements with all vendors and contractors who handle PHI, including:
- AWS (cloud hosting and storage)
- SendGrid (email services)
- Stripe (payment processing)
- All other subcontractors
All BAAs require vendors to maintain the same level of security and privacy as Immaculate.Care.
9. Data Breach Notification
In the event of a breach of your unsecured PHI, we are required to notify you within 60 days. We will also:
- Conduct a forensic investigation
- Implement remedial measures
- Notify the U.S. Department of Health and Human Services
- Notify major news outlets if > 500 individuals affected
- Provide guidance on identity protection if needed
Breaches are taken very seriously. We have never experienced a breach of your PHI.
10. Effective Date & Changes
This Notice of Privacy Practices is effective immediately. We may change this notice at any time. Changes will be posted on our website and you will be notified of significant changes. Your continued use of Immaculate.Care indicates acceptance of updated practices.
11. Contact Information
For questions about this notice, your privacy rights, or to report a privacy violation, contact:
Privacy Officer
Immaculate.Care
Email: richy@immaculate.care
Phone: 1-800-CARE-NOW
Hours: Monday-Friday, 9 AM - 5 PM Central Time
You also have the right to file a complaint with:
U.S. Department of Health and Human Services
Office for Civil Rights
200 Independence Avenue, S.W.
Washington, D.C. 20201
Phone: 1-800-HHS-TIPS
Website: www.hhs.gov/ocr/privacy/hipaa/complaints