Notice of Privacy Practices — Draft

This draft is awaiting review and approval by qualified healthcare counsel and Ibnsina’s Privacy Official. It is not final legal advice. Effective date: to be inserted after approval.

About this notice

This Notice of Privacy Practices explains how Ibnsina may use and disclose protected health information (PHI), how patients may exercise their privacy rights, and how to raise a complaint. The approved notice, effective date, covered entity or business associate designation, and contact details must be completed before publication.

How we may use and disclose PHI

  • Treatment: to support consultation, care coordination, and communications with healthcare providers involved in your care.
  • Payment: to process charges, obtain payment, and coordinate billing for services.
  • Healthcare operations: to improve services, support quality and safety, train authorized workforce members, and administer the platform.
  • As required by law: when a law, court order, public-health requirement, oversight activity, or other legally permitted basis applies.
  • With your authorization: for uses or disclosures not otherwise described here, including most marketing or sale of PHI. You may revoke an authorization in writing where permitted.

Your patient rights

  • Request access to inspect or receive a copy of your PHI, subject to applicable limits and identity verification.
  • Request an amendment to PHI you believe is inaccurate or incomplete.
  • Request restrictions on certain uses or disclosures, including a request that PHI not be disclosed to a health plan for a service paid in full where applicable.
  • Request confidential communications by a different method or at a different location.
  • Receive an accounting of certain disclosures, subject to legal exceptions.
  • Receive a paper or electronic copy of this notice and ask questions about privacy practices.

Our privacy and security duties

Ibnsina will use reasonable administrative, physical, and technical safeguards for PHI, limit workforce access to the minimum necessary for assigned duties, require appropriate workforce training and confidentiality, and notify affected individuals as required by law if a breach of unsecured PHI occurs. These duties are subject to the final legal and operational review.

Complaints and non-retaliation

You may submit a privacy complaint to Ibnsina’s Privacy Official or to the U.S. Department of Health and Human Services Office for Civil Rights. The approved notice must list the current submission channels before publication. Ibnsina will not retaliate against you for filing a privacy complaint or exercising a privacy right.

Contact the Privacy Official

Contact details are intentionally left for the Privacy Official and counsel to approve and insert; no postal address or phone number is asserted by this draft. Patients may use the privacy contact channel published by Ibnsina once this notice is approved.

Changes to this notice

Ibnsina may revise this notice and make the revised notice effective for PHI it already maintains, as permitted by law. The effective date and an approved change-notification process must be added before publication.

This page does not capture a patient acknowledgment. A compliant acknowledgment workflow, retention policy, and any required notice-delivery record remain to be implemented after legal and Privacy Official approval.