HIPAA Privacy Notice - University Diagnostic Medical Imaging

HIPAA Privacy Notice






We are committed to preserving the privacy and confidentiality of your health information. This Privacy Notice describes how the office of University Diagnostic Medical Imaging, P.C. (“the Practice”) may use and disclose your PHI according to applicable laws and regulations. It also describes your rights with respect to your “protected health information.” Your protected health information (“PHI”) includes most information about your physical and mental health, such as symptoms, treatment, test results, and demographic data, which contains details that can be used to identify you. We are required by law to maintain the privacy of your PHI, to provide you with this notice of our legal duties and privacy practices, and to notify you following a breach of your unsecured PHI.

We reserve the right to change this notice and to make the revised notice effective for all PHI that we maintain at that time and any information we may receive in the future. We will make any revised notice available at the facility for you to request a copy.

You will be asked to provide a signed acknowledgment of receipt of this Notice.  Our intent is to make you aware of the possible uses and disclosures of your PHI and your privacy rights.  The delivery of your health care services will in no way be conditioned upon your signed acknowledgment.  If you decline to provide a signed acknowledgment, we will continue to provide your treatment and will use and disclose your PHI in accordance with law.


We must obtain your written permission or “authorization” to use or disclose your PHI except in the limited situations listed below, which do not require your written authorization:

1.            Treatment: We will use and disclose your PHI to provide, coordinate and manage your health care and related services. We may disclose your PHI to health care providers, including providers not affiliated with the Practice, so that they may provide you with treatment. For example, we may disclose your PHI to a pharmacy to fill a prescription, to a laboratory to order a test, or to a specialist for a consultation. 45 C.F.R. § 164.512.

2.            Payment: We will use and disclose your PHI, as needed, for the Practice to obtain payment for our health care services. For example, we may disclose PHI to your health insurance company so we may obtain prior approval for a surgery, to determine whether you are eligible for benefits or to determine whether a particular service is covered under your plan. We may also disclose your PHI to other health care providers, health plans, or health care clearinghouses for their payment activities. For example, we may disclose PHI to anesthesia care providers so that they may obtain payment for their services. 45 C.F.R. § 164.512.

3.            Health Care Operations: We will use and disclose your PHI for our health care operations. For example, we may use your PHI to evaluate the performance of the Practice’s personnel and to perform licensing, training, and accreditation activities. In certain situations, we may also disclose your PHI to another health care provider, health plan, or health care clearinghouse that has or had a relationship with you, for the purpose of that entity’s health care operations, as long as the PHI is related to your relationship with that entity. For example, the Practice may disclose your PHI to allow another entity to conduct activities to determine whether it has provided quality services, to review the performance and qualifications of health care providers, to conduct training programs, and to perform accreditation, certification, licensing or credentialing activities. 45 C.F.R. § 164.512.

4.            Law Enforcement Purposes: We may disclose your PHI to law enforcement officials under certain circumstances when we are required or permitted by law to disclose such information. For example, we may disclose your PHI if we are required by law to report a certain type of wound or injury, such as a gunshot wound. We may also disclose your PHI pursuant to an order, warrant, subpoena or summons issued by a judicial officer. Under certain circumstances, we may disclose your PHI pursuant to administrative requests related to law enforcement purposes. We may disclose limited PHI to law enforcement officials upon their request to assist them in identifying or locating a suspect, fugitive, material witness or missing person. Additionally, under certain circumstances we may disclose your PHI to law enforcement officials if you are suspected to be the victim of a crime or in order to report evidence of criminal conduct that occurred on our premises. 45 C.F.R. § 164.512.

5.            Public Health Activities: The Practice may disclose your PHI to certain public health authorities and others according to specific rules that apply to public health activities. For example, the Practice may disclose your PHI to public health authorities or other government authorities authorized by law to receive such information for purposes of preventing or controlling disease, injury, disability, or child abuse or neglect or for the conduct of public health surveillance, investigations and interventions. We may also disclose your PHI to certain individuals subject to the jurisdiction of the Food and Drug Administration regarding FDA-regulated products or activities, to certain individuals who may be at risk of contracting or spreading a disease or condition, and under certain circumstances to your employer if we have provided health care to you at your employer’s request. 45 C.F.R. § 164.512.

6.            Health Oversight Activities: The Practice may disclose your PHI to a health oversight agency for oversight activities authorized by law, including audits; civil, administrative, or criminal investigations, proceedings and actions; inspections; licensure or disciplinary actions; and other activities necessary for appropriate oversight of the health care system and oversight of certain programs and entities as authorized by law. 45 C.F.R. § 164.512.

7.            Judicial and Administrative Proceedings: We may disclose your PHI in the course of any judicial or administrative proceeding in response to an order of a court or administrative tribunal as expressly authorized by such order. In certain circumstances, we may disclose your PHI in response to a subpoena, discovery request or other lawful process to the extent authorized by State law if we receive satisfactory assurances from the party requesting your information that you have been notified of the request or that they have made reasonable efforts to obtain a qualified protective order. A qualified protective order is an order of a court or tribunal that prohibits the use or disclosure of your PHI for any purpose other than the proceeding for which it was requested and which requires that your PHI will be returned to the Practice at the end of the proceeding. 45 C.F.R. § 164.512.

8.            Specialized Government Functions: In certain circumstances, Federal regulations authorize the Practice to use and/or disclose your PHI for specialized government functions. If you are a member of the armed forces, the Practice may use and disclose your PHI as directed by appropriate military authorities. We may disclose your PHI to authorized Federal officials for certain national security and intelligence activities and to protect the President of the United States and other dignitaries. The Practice may also disclose your PHI to law enforcement personnel or to a correctional institution if such information is required for the health and safety of inmates, law enforcement personnel, individuals at the correctional institution, or individuals responsible for transporting inmates or if such information is required to maintain safety, law and order at a correctional institution. 45 C.F.R. § 164.512.

9.            Suspected Abuse, Neglect or Domestic Violence: The Practice will disclose medical information that reveals that you may be a victim of abuse, neglect or domestic violence to a government authority if the Practice is required by law to make such disclosure. For example, State law requires health care professionals to report cases of suspected child abuse or maltreatment. If the Practice is authorized, but not required, by law to disclose evidence of suspected abuse, neglect or domestic violence, it will do so if it believes that the disclosure is necessary to prevent serious harm, or if you are incapacitated and government officials need such information for an immediate law enforcement activity. 45 C.F.R. § 164.512.

10.          Necessary To Avert a Serious Threat to Health or Safety: The Practice may, consistent with applicable law and standards of ethical conduct, use or disclose PHI if we believe, in good faith, that such use or disclosure is necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public and the disclosure is made to an individual who is reasonably able to prevent or lessen the threat. 45 C.F.R. § 164.512.

11.          Research: We may use and disclose your PHI for research as long as such research has been approved by an institutional review board or privacy board that has reviewed the research proposal and established protocols to preserve the privacy of your PHI. For example, a research project may involve comparing the health of patients who received one treatment to those who received another treatment for the same condition. Before we use or disclose PHI for research purposes, the research project will go through a special review and approval process. Even without special approval, however, we may permit researchers to review your PHI if it is necessary to help them prepare for a research project, as long as they do not remove or take a copy of any PHI. 45 C.F.R. § 164.512.

12.          Medical Examiners, Funeral Directors, and Organ Donation: The Practice may disclose your PHI to a medical examiner for identification purposes, to determine the cause of death or for other purposes authorized by law. We may also disclose your PHI to a funeral director, as authorized by law, to permit the funeral director to carry out his or her duties. Additionally, the Practice may use and disclose your PHI for the purpose of arranging for cadaveric organ, eye, or tissue donation and transplantation. 45 C.F.R. § 164.512.

13.          Workers’ Compensation: The facility may disclose your PHI, as authorized by and in compliance with workers’ compensation laws. 45 C.F.R. § 164.512.

14.          Appointment Reminders: The Practice may, from time to time, use or disclose your PHI to contact you to provide appointment reminders or information about treatment alternatives or other health-related benefits and services that we believe may be of interest to you. The Practice may remind you of appointments by mailing a postcard to you at the address provided by you or by telephoning your home and leaving a message on your answering machine or with the individual answering the phone. The Practice will not disclose any information with these appointment reminders except your name, your address and the time, date and location of your appointment. 45 C.F.R. § 164.520.

15.          De-identified Information: The Practice may de-identify your PHI according to specific Federal rules so that the information does not identify you and cannot be used to identify you. The Practice may use and disclose your de-identified information. The Practice may also partly de-identify your PHI by removing your name, address, telephone number and many other identifying factors to create a “limited data set,” which may be used and disclosed for research purposes. Your PHI will only be disclosed in the form of a “limited data set” to recipients who sign an agreement to use your PHI for specific purposes according to law and who agree not to identify you. 45 C.F.R. § 164.514.

16.          Business Associates: The Practice may disclose your PHI to a business associate of the Practice if we obtain satisfactory written assurance, in accordance with applicable law, that the business associate will appropriately safeguard your PHI. A “business associate” is an entity that creates, receives, maintains, or transmits PHI in the process of providing certain services for the Practice. Such services include legal, actuarial, accounting, consulting, date aggregation, management, administrative, accreditation, or financial services. A Health Information Organization, E-prescribing Gateway, or a person that offers personal health records to individuals on behalf of a cover entity, and subcontractors who perform work on behalf of business associates are also covered. Health care providers, plan sponsors and government agencies are not covered by the term “business associates.” 45 C.F.R. §§ 164.502(b), 160.103.

17.          Personal Representatives: The Practice may disclose your PHI to or according to the direction of a person who, under applicable law, has the authority to represent you in making decisions related to your health. For example, we may disclose your PHI to an agent who you authorize through a health care proxy form to make health care decisions for you in the event that you should become unable to make your own health care decisions. 45 C.F.R. § 164.502.

18.          Family and Friends: Under certain circumstances, the Practice may disclose to your family member, other relative, a close personal friend, or any other person identified by you, your PHI directly relevant to such person’s involvement with your care or the payment for your care. The Practice may also use or disclose your PHI to the previously named individuals as well as to a public or private entity authorized by law or by its charter to assist in disaster relief efforts to notify or assist in the notification (including identifying or locating) of a family member, a personal representative, or another person responsible for your care, of your location, general condition or death. However, the following conditions will apply: 45 C.F.R. § 164.510.

a.            If you are present at or available prior to the use or disclosure of your PHI, the Practice may use or disclose your PHI if you agree, or if the Practice can reasonably infer from the circumstances, based on the exercise of its professional judgment, that you do not object to the use or disclosure.

b.            If you are not present or are unable to agree or object to the use or disclosure because of incapacity or an emergency, the Practice will, in the exercise of professional judgment, determine whether the use or disclosure is in your best interests and, if so, disclose only the PHI that is directly relevant to the person’s involvement with your care.

19.           Required by Law: In addition to those uses and disclosures listed above, we may use and disclose your PHI if and to the extent we are required by law.

20.          Other Uses. Authorization is required before the Practice may disclose psychotherapy notes, uses and disclosures for marketing purposes, and disclosures that constitute a sale of your personal health information. The Practice may not use or disclose your PHI for any reason not described in this Privacy Notice. 45 C.F.R. § 164.520(b)(1)(ii)(E).

C.           YOUR RIGHTS

You have the following rights regarding your PHI:

1.            Right to Revoke an Authorization: You may revoke an Authorization in writing, at any time. To request a revocation, you must submit a written request to the Practice’s Privacy Contact, whose contact information is listed below in part D of this Privacy Notice. 45 C.F.R. § 164.522.

2.            Right to Request Restrictions on Uses and/or Disclosures: You may request restrictions on the use and/or disclosure of your PHI, or of certain parts of your PHI, for treatment, payment or health care operations. You may also request that we not disclose your PHI to family members or friends who may be involved in your care or for notification purposes as described in section (18) of part B of this Privacy Notice, titled “Friends and Family.” To request restrictions, you must submit a written request to the Practice’s Privacy Contact. In your written request, you must identify the specific restriction requested and identify who you want the restrictions to apply to. The Practice is not obligated to agree to any of your requested restrictions. If we deny your request to a restriction, we will notify you. If the Practice agrees to your requested restriction, we may not use or disclose your PHI in violation of that restriction unless it is needed to provide you with emergency treatment. Under certain circumstances, we may terminate our agreement to a restriction. 45 C.F.R. § 164.522.

3.            Right to Request Confidential Communications: You may request to receive confidential communications of PHI by alternative means or at alternative locations. You must make your request to the Practice’s Privacy Contact. The Practice will accommodate all reasonable requests. We may condition this accommodation on your providing us with information as to how payment will be handled or by specifying an alternative address or other method of contact. We will not require you to provide an explanation for your request. 45 C.F.R. § 164.522.

4.            Right to Inspect and Copy Information: According to Federal regulations, you may generally inspect and obtain a copy of your PHI that we maintain in a designated record set. A “designated record set” is a group of records that includes medical and billing records or other records that your surgeon and the Practice use for making decisions about you. Under Federal privacy regulations, however, you have no right to inspect or copy certain records, including psychotherapy notes, information compiled in reasonable anticipation of legal proceedings and certain clinical laboratory information. Please note that New York State’s Mental Hygiene Law and Public Health Law may provide you with independent rights to inspect and copy such information. If Federal law does not allow you to inspect or copy certain information, such as psychotherapy notes, but State law allows you to inspect and copy such information, the Practice will respond to your request to access such information in accordance with New York State law. We may deny your request to inspect or copy your PHI. Depending on the circumstances, you may or may not have a right to appeal our decision to deny your request. To inspect or copy your PHI, you must submit a written request to the Practice’s Privacy Contact. If you request a copy of your information, we may charge you a fee for the costs of copying and mailing your information and for other costs only as allowed by law. 45 C.F.R. § 164.522.

5.            Right to Amend your Information: You may request that we amend your PHI that we maintain in a designated record set. To request an amendment, you must submit a written request, along with a reason that supports your request to our Privacy Contact. In certain cases, we may deny your request for an amendment. If we deny your request for an amendment, you have the right to file a statement of disagreement with us. If you file such a statement, we may prepare a rebuttal to your statement and will provide you with a copy of any such rebuttal. 45 C.F.R. § 164.522.

6.            Right to Receive an Accounting: You may request an accounting of certain disclosures of your PHI made by the Practice after April 14, 2003. We are not required to provide you with an accounting of disclosures that you authorize or with an accounting of some disclosures that we are permitted to make without your authorization. Your request for an accounting of disclosures must be submitted in writing to our Privacy Contact and must specify a time period to be covered by the accounting. Your right to receive this information is subject to additional exceptions, restrictions and limitations. 45 C.F.R. § 164.522.

7.            Right to Receive a Copy of Notice: Upon your request, we will provide you with a paper copy of this Privacy Notice. 45 C.F.R. § 164.522.

8.            Right to Complain: You have the right to complain to the Practice or to the Secretary of the Department of Health and Human Services if you believe your privacy rights have been violated. You may complain to the Practice by contacting the Practice’s Privacy Contact, using the contact information below. You will not be retaliated against in any way for filing a complaint. 45 C.F.R. § 164.522.

9.            Right to Opt-Out of Fundraising Communications: You have the right to opt-out of receiving fundraising communications from the Practice. (This paragraph optional if Practice does not intend to contact individuals about fundraising.) 45 C.F.R. § 164.520(b)(1)(iii)(A).

10.          Limited Right to Restrict Disclosure to a Health Plan: You have the right to restrict the Practice’s disclosure for the purpose of payment or health care operations – and not for other reasons required by law – to your health plan of PHI pertaining solely to a health care item or service you or a person other than the health plan on your behalf, has paid the Practice in full. 45 C.F.R. § 164.520(b)(1)(iv)(A).

11.          Right to Breach Notification: You have the right to be notified following any breach of your unsecured PHI.


The Practice’s contact person for all issues regarding patient privacy and your rights under the Federal privacy standards is the Privacy Contact. Questions regarding matters covered by this Notice shall be directed to the Privacy Contact. You may contact the Privacy Contact at:

Dr. Daniel Gurell, M.D.
Associate Medical Director/Chief Compliance Officer
University Diagnostic Medical Imaging, P.C.
1200 Waters Place, Suite M108
Bronx, NY 10461
(718) 931-5620