Your health information is protected.
This is the federally required Notice of Privacy Practices. We are also listing our AI practices explicitly — which isn't required, but should be.
What this notice does
This Notice of Privacy Practices describes how we may use and disclose your Protected Health Information (PHI) and how you can access that information. We are required by law to maintain the privacy of PHI and to provide you with this notice.
How we use your PHI
We use your PHI to provide treatment, obtain payment, and operate the clinic. Specifically:
- Treatment — ordering labs, sending prescriptions, coordinating with specialists you choose
- Payment — charging you for services and generating superbills on your request
- Operations — improving our clinical quality, training our clinicians, running audits required by HIPAA and state law
Disclosures without your authorization
In limited cases we may disclose PHI without your authorization, including: public-health reporting (e.g., certain communicable diseases), investigations of suspected abuse/neglect, court orders, workers' compensation claims where you've made a claim, and responses to lawful subpoenas after giving you notice where the law allows.
Disclosures that require your authorization
We will ask for your written authorization before sharing PHI for marketing, for sale, for psychotherapy notes (if applicable), or to anyone not listed above. You can revoke an authorization in writing at any time; it does not affect disclosures we already made in reliance on it.
Your rights under HIPAA
- Access your records — full export in the portal, always free
- Request amendment of something you believe is inaccurate — we respond within 60 days
- Request restrictions on how we use or share your PHI — we must agree to restrictions on self-pay disclosures to health plans
- Request confidential communications (e.g., only contact you at a specific number)
- Receive an accounting of certain disclosures we made outside of treatment/payment/operations
- Receive a paper copy of this notice on request
Breach notification
If there is a breach of your unsecured PHI, we will notify you by the fastest means available (email first, then mail if needed) no later than 60 days after discovery, and sooner when state law requires. We will describe what happened, what was involved, steps we are taking, and what you can do.
AI and automation
We use AI tools to draft routine messages, summarize intake data, and flag abnormal labs for clinician review. All AI use is covered under a Business Associate Agreement with the provider. AI does not make clinical decisions; a licensed clinician reviews and approves every clinical message and every prescription.
We do not permit our AI vendors to train their general-purpose models on your PHI.
Complaints
If you believe your privacy rights have been violated, you can file a complaint with us or with the U.S. Department of Health and Human Services Office for Civil Rights. We will not retaliate against you for filing a complaint.
Designated Privacy Officer
Kevin Watson, FNP-C · privacy@everydayhealthco.com · 207 Third Ave E, Twin Falls, ID 83301
