Version 2026.05.1

HIPAA Notice of Privacy Practices

This notice describes how protected health information may be used or disclosed and what rights may apply where HIPAA governs the handling of health information.

Our Legal Duties

Where HIPAA applies, we are required to protect PHI, provide notice of privacy practices, follow the notice currently in effect, and provide breach notification when required by law.

Uses and Disclosures for Treatment

PHI may be used or disclosed for treatment-related activities such as care coordination, referral handling, clinical review, and secure communication among authorized care participants.

Payment and Healthcare Operations

PHI may be used or disclosed for billing, payment operations, scheduling, internal quality improvement, workforce operations, audit, and security review as permitted by law.

Other Permitted Disclosures

PHI may also be disclosed for legal requirements, public health activities, abuse or neglect reporting, law enforcement requests, health oversight, or serious threat and safety situations when authorized by law.

Your Rights

Depending on applicable law, you may have the right to inspect or obtain copies of certain records, request amendments, request restrictions, request confidential communications, receive an accounting of certain disclosures, and file a complaint.

Organization Responsibilities

ScoliBase and the applicable healthcare organization are responsible for safeguarding PHI, following the terms of the notice in effect, and updating the notice when practices or legal requirements change.

Contact

Questions, requests, or complaints about privacy practices should be directed to the designated Privacy Officer or published complaint channel for the applicable organization.