HIPAA Notice of Privacy Practices for Knowble Health
Updated: July 25th, 2024
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides standards for how medical information should be used and disclosed by healthcare providers, health plans, and other covered entities. Knowble Health, is a health care provider that both directly delivers laboratory and medical services through its personnel as well as contracts with licensed providers to deliver health care services. We provide each of our users with this information and ask each of our users to acknowledge receipt of our HIPAA Notice of Privacy Practices for Knowble Health, which discloses our practices for personal information gathering and dissemination. Please note that by registering on the website (the “Site”) or by using the services provided by Knowble Health, together with any independently contracted affiliates, affiliated covered entities, or members of an organized health care arrangement (together “Knowble Health”, “we”, “our” or “us”), you accept the practices described in this Notice of Privacy Practices. If you do not agree to this Notice, please do not use the Site or Knowble Health’s services. IF YOU ARE UNDER 13 YEARS OF AGE OR RESIDE OUTSIDE OF THE UNITED STATES, PLEASE DO NOT USE OR ACCESS OUR SITE.
What information do we collect from users and how is it used?
Registration. Before using some of our services, we need you to register with the Site and provide your name, email address, your home address, and other personal details. We request this information for identification purposes, to communicate with you, and to improve the functioning of certain services. In some cases, we (through our service provider) may create biometric information or collect information from third party databases to verify your identity prior to your use of our services. We will ask for your consent prior to creating biometric information. By providing us with your email address, you consent to receiving information from us through the email you provide us, with may include some protected health information which is private to you and protected under HIPAA. For more information on the information we collect, you can also review our Terms of Use and Privacy Policy, which can be found on our website. You may also be asked to complete other forms (e.g. intake forms, medical record unification, informed consent, etc.) depending on the services you choose.
Enrollment Forms. To fully use our offerings, you may need to fill out forms and input information that ask for or contain personal information such as your name, contact information, health, health history, medical providers, and other personal information.
Medical Records. In order for us to get you the best care, we may ask you to provide us with a list of your providers, patient portal information which you may have access in the past or will access in the future, and the health systems you’ve visited. We may also ask you for a description of symptoms, a medical history, lifestyle descriptions and information regarding your interest and past experiences at prior health entities, participation in clinical trials and research. In addition, if you see a provider that orders labs through Knowble Health, we will maintain a medical record that contains the details of the care you receive through Knowble Health or it’s affiliated business associates involved in your care.
Correspondence. If you correspond with us via email, secure message, or text, we may gather in a file specific to you the information that you submit.
Health Recommendations. We will use your information to provide insights regarding your healthcare and recommend services that may assist in your care, such as provider referrals and access to labwork. It is always recommended that you also notify and consult your primary care provider or other relevant health practitioners for any test results, lab work questions or results, health related questions, or changes to your care plans.
Recordings. If you contact our care team by phone or by email, we may record and retain copies of the interaction for, among other things, quality assurance and training purposes. If you access any apps or other services we offer, we may record your interactions with our software or our providers.
We will store the above described categories of information for as long as needed to provide our services, and as required to comply with our legal obligations (including those under HIPAA), resolve potential or actual disputes, improve the quality of our services, or enforce our agreements. Biometric information will be kept no longer than three years.
How does Knowble Health use and disclose protected health information about you that we collect?
We are required to maintain the confidentiality of your protected health information (“PHI”), and we have implemented policies, procedures, and other safeguards to help protect your PHI from improper use and disclosure. We protect your PHI in accordance with HIPAA and all other applicable laws and regulations. Where an applicable state law or any other applicable law or regulation requires more protection for your PHI than HIPAA, we comply with that law or regulation as well.
Below, we describe different ways that we may use your PHI amongst ourselves and disclose your PHI to other persons and entities. We have not listed every possible use or disclosure in the list below, but all of the ways that may use and disclose PHI fall within one of the categories below. As we describe below, some uses and disclosures will require your specific authorization.
Treatment. We can use your PHI and share it with other professionals or programs that are treating you, such as when you visit a new health care provider or are offered services related to your health by other entities. By using our services, you hereby explicitly consent to the sharing of information like your name, age, gender, problems you are seeking help for, including alcohol and substance use, care preferences, health plan coverage, and progress of your treatment with current and potential providers to promote good outcomes.
Run our Organization. We can use and share your PHI to support our business operations, which include caring for you. This means your information may be shared to run our offerings, improve our offerings to clients, improve your care and the coordination of your care, and contact you when necessary, such as using your PHI to manage your treatment and services.
Billing and Payment. We may use and share your PHI to confirm eligibility for services and to receive and ensure proper payment. For example, we may request your information from your health plan or employer in order to confirm eligibility for laboratory services.
Disclosure at Your Request. If you ask us to send PHI about you to a third party, such as a friend, family member, health care provider, or health care company, we will do so if we believe that your request is authentic. We may ask you to prove your identity before we honor this request. We may need up to 60 days to honor a request like this, depending on the information that you would like us to disclose, but in most cases, we can honor this request in seven or fewer days.
Business Associates. We provide some aspects of our services through contracts with business associates for whom we are legally responsible. Examples of our business associates include companies involved in your care, for secure cloud hosting, management consultants, quality assurance reviewers, identity verification providers, accreditation agencies, and billing and collection services. We may disclose your PHI to our business associates so that they can perform the jobs that we have asked them to perform. To protect your PHI, we require our business associates to sign written agreements requiring that they appropriately safeguard your PHI and use it only as we permit.
Affiliated Covered Entity and Organized Health Care Arrangement. We may participate as part of an Affiliated Covered Entity (ACE) or organized health care arrangement (OHCA). An ACE is a collective designation under HIPAA for a group of legally separate health providers that may work together. These entities may choose to function together for compliance with HIPAA regulations. These entities and arrangements, collectively, are referred to in this policy as “care teams". This designation allows for the seamless sharing of your protected health information (PHI) for the purposes of treatment, payment, and healthcare operations. This allows us to provide coordinated care and comprehensive services to our patients across care teams. This may allow care teams to share protected health information (PHI) among themselves facilitating coordinated care and efficient healthcare operations. These arrangements are common among different healthcare groups and many health systems that operate nationally, sometimes to maintain compliance with state regulations.
ACE and OHCA purpose and benefits. These designations enable care teams to:
Information Sharing and Use. We may share your personal health information (PHI) for treatment, payment, and healthcare operations. This may assist care teams in providing health services and health-related services, such as, but not limited to access to laboratory testing, clinical services, and medication delivery. This sharing of information helps care teams to enhance the quality of care you receive and to operate more efficiently and comprehensively.
This relationship enables us to provide you with comprehensive and coordinated healthcare services while ensuring your information is handled in compliance with HIPAA privacy and security rules. We may share your PHI with clinical teams to provide you with coordinated and comprehensive healthcare services. This is done in compliance with HIPAA regulations to ensure your privacy and the security of your health information.
Other Uses. We are allowed or required to share your information in other ways – usually in ways that contribute to your benefit or public good, such as public health and research. We have to meet many conditions in the law before we can share your information for these purposes. For more information see: “Your Rights Under HIPAA”. The following are ways we may share your information:
You have both the right and the choice to tell us to share your PHI with your family, close friends, or others involved in your care; share your PHI in a disaster relief situation; and other health related functions. If you are not able to tell us your preference, we may go ahead and share your information if we believe it is in your best interest.
We will never share your PHI to outside parties, unless you give us written permission to. You may revoke or restrict the authorization to disclose your PHI at any time.
We reserve the right to release collected information to law enforcement or other government officials, as we, in our sole and absolute discretion, deem necessary or appropriate.
What are your rights regarding your protected health information?
You have certain rights regarding protected health information that we maintain about you, including rights to:
What are Knowble Health’s responsibilities with my information?
We are required by federal law (HIPAA) and state law to maintain the privacy and security of your protected health information. We will let you know promptly if a breach occurs that may have compromised the privacy or security of your protected health information. We must follow the duties and privacy practices described in this notice and give you a copy of it. We will not use or share your information other than as described here unless you tell us we can in writing. If you tell us we can, you may change your mind at any time. Let us know in writing if you change your mind.
How will I know about changes in the Notice of Privacy Practices?
We reserve the right to update this Notice of Privacy Practices from time to time, but we may not change this Notice in a way that would violate HIPAA. Please visit this page periodically so that you can be updated of any changes. The policies indicated in this Notice will remain effective, even if you are no longer using our Site or services.
At times, Knowble Health may work with its affiliates or a third party contracted provider to deliver services to you. To the extent that there is a conflict between Knowble Health’s Notice of Privacy Practices and that of a third party contracted provider regarding how your PHI will handled, the Notice of Privacy Practices for Knowble Health PC will take in effect if you signed up directly through Knowble Health or the Notice of Privacy Practices or Privacy policy of the health care entity you signed up for first will take in effect.
How to contact us? If you have questions, or need to reach us for any other reason, you may contact the team with our form on the website.