Apex Radiology Group, PLLC ("Apex Radiology Group," "we," "us," or "our") is committed to safeguarding the privacy and security of Protected Health Information ("PHI") in accordance with the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and the regulations promulgated thereunder, including 45 C.F.R. Parts 160 and 164 (collectively, "HIPAA"), as well as applicable state privacy and security laws.
This HIPAA Compliance Statement provides a general overview of our compliance program. It is not a substitute for our Notice of Privacy Practices, Business Associate Agreements, or other contractual or legal documents that govern the specific handling of PHI in any given engagement.
1. Our Role Under HIPAA
Apex Radiology Group is a healthcare provider that furnishes professional radiology interpretation services to hospitals, imaging centers, and other healthcare clients. Depending on the nature of a particular engagement, Apex Radiology Group may operate as a HIPAA "covered entity," a "business associate," or both, with respect to PHI.
Our specific responsibilities for any particular engagement are governed by the applicable service agreement, Business Associate Agreement, or other written contract with the client.
2. Safeguards
Apex Radiology Group maintains administrative, physical, and technical safeguards reasonably and appropriately designed to protect the confidentiality, integrity, and availability of electronic PHI ("ePHI") in accordance with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C).
2.1 Administrative Safeguards
• Designation of a Privacy Officer and a Security Officer responsible for HIPAA compliance
• Documented policies and procedures addressing the HIPAA Privacy, Security, and Breach Notification Rules
• Workforce training on HIPAA, security awareness, and incident response, including upon hire and on a recurring basis
• Role-based access controls and the principle of minimum necessary use and disclosure
• Periodic risk analyses and risk management activities
• Sanction policy for workforce members who fail to comply with policies and procedures
• Contingency planning, including data backup, disaster recovery, and emergency mode operation plans
• Business Associate Agreements with all subcontractors and vendors that create, receive, maintain, or transmit PHI on our behalf
2.2 Physical Safeguards
• Facility access controls and workstation security policies
• Device and media controls, including policies for the secure disposal and reuse of electronic media
• Restrictions on physical access to systems and storage media containing ePHI
2.3 Technical Safeguards
• Unique user identification and authentication for systems that access ePHI
• Automatic logoff and session controls
• Encryption of ePHI at rest and in transit consistent with current National Institute of Standards and Technology (NIST) guidance
• Audit logging and regular review of system activity
• Integrity controls designed to prevent improper alteration or destruction of ePHI
• Transmission security for ePHI sent over electronic communications networks
3. Use and Disclosure of PHI
Apex Radiology Group uses and discloses PHI only as permitted or required by HIPAA and by the applicable service agreement or Business Associate Agreement. Permitted uses and disclosures generally include those for treatment, payment, and healthcare operations; uses and disclosures required by law; and uses and disclosures authorized in writing by the individual or the individual's personal representative.
We apply the HIPAA "minimum necessary" standard to all uses, disclosures, and requests for PHI, except where an exception applies (for example, disclosures to the individual or for treatment purposes).
4. Business Associate Relationships
When Apex Radiology Group acts as a business associate to a covered entity, we enter into a Business Associate Agreement that addresses, among other things, permitted and required uses and disclosures of PHI, safeguards, reporting of security incidents and breaches, subcontractor obligations, individuals' rights, and termination.
When Apex Radiology Group engages a subcontractor that will create, receive, maintain, or transmit PHI on our behalf, we require that subcontractor to enter into a written agreement containing substantially the same restrictions and conditions that apply to us with respect to such PHI.
5. Breach Notification
Apex Radiology Group maintains policies and procedures for identifying, investigating, mitigating, and reporting breaches of unsecured PHI in accordance with the HIPAA Breach Notification Rule (45 C.F.R. Part 164, Subpart D) and applicable state law. In the event of a breach, we will notify affected individuals, covered entities, the U.S. Department of Health and Human Services, and, where required, the media, within the timeframes required by law.
6. Individual Rights
HIPAA grants individuals certain rights with respect to their PHI, including:
• The right to receive a Notice of Privacy Practices from covered entities
• The right to request access to and copies of PHI in a designated record set
• The right to request an amendment to PHI
• The right to request an accounting of certain disclosures
• The right to request restrictions on certain uses and disclosures
• The right to request confidential communications by alternative means or at alternative locations
• The right to file a complaint with the covered entity or with the U.S. Department of Health and Human Services, Office for Civil Rights, without retaliation
Individuals seeking to exercise these rights should generally direct their request to the covered entity that maintains the relevant designated record set. When Apex Radiology Group acts as a covered entity, requests should be directed to our Privacy Officer using the contact information below.
7. Workforce Training and Sanctions
All Apex Radiology Group workforce members, including employees, contractors, and other personnel with access to PHI, receive HIPAA training upon engagement and on a recurring basis. Workforce members who violate our HIPAA policies and procedures are subject to sanctions up to and including termination of employment or engagement and referral to applicable licensing boards or law enforcement when appropriate.
8. Risk Analysis and Ongoing Compliance
Apex Radiology Group conducts and documents periodic risk analyses to identify potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. Identified risks are addressed through reasonable and appropriate risk management measures. We periodically review and update our policies, procedures, and safeguards in response to changes in our environment, operations, technology, and applicable law.
9. Reporting a HIPAA Concern
If you believe that your privacy rights have been violated or that Apex Radiology Group has not complied with HIPAA, you may file a complaint with our Privacy Officer using the contact information below. Apex Radiology Group will not retaliate against any person for filing a good-faith complaint.
You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights:
U.S. Department of Health and Human Services
Office for Civil Rights
200 Independence Avenue, S.W.
Washington, D.C. 20201
Toll-Free: 1-800-368-1019
TDD: 1-800-537-7697
Website: www.hhs.gov/ocr
10. Relationship to Notice of Privacy Practices and Business Associate Agreements
This HIPAA Compliance Statement provides a general overview of our compliance program. It does not replace, supersede, or modify our Notice of Privacy Practices, any Business Associate Agreement, or any other agreement between Apex Radiology Group and a client, individual, or other party. In the event of a conflict between this Statement and any such notice or agreement, the notice or agreement controls.
11. Important Notice Regarding Communications with Apex Radiology Group
Communications transmitted to Apex Radiology Group through our website, through unencrypted email, or through other unsecured channels may not be secure. Please do not transmit PHI or other sensitive information to us through these channels unless we have specifically directed you to do so through a designated secure channel.
12. Contact Information
For questions about our HIPAA compliance program, to request a copy of our Notice of Privacy Practices, to file a HIPAA complaint, or to exercise individual rights with respect to PHI we maintain as a covered entity, please contact our Privacy Officer:
Apex Radiology Group, PLLC
Attn: HIPAA Privacy Officer
4850 Tamiami Trail N, Suite 301
Naples, FL 34103
Phone: (239) 529-4069
Email: [email protected]