Version 2026.05.1

HIPAA Notice of Privacy Practices

This notice describes how protected health information may be used or disclosed through ScoliBase, ScoliBase Connect, and related healthcare workflows, and what rights may apply where HIPAA governs the handling of health information.

Our Legal Duties

Where HIPAA applies, ScoliBase and the applicable healthcare organization are required to protect protected health information (PHI), provide notice of applicable privacy practices, follow the notice currently in effect, and provide breach notification when required by law.

ScoliBase and ScoliBase Connect

ScoliBase provides technology used to support healthcare-related workflows, including patient and guardian access, care coordination, secure communications, scheduling, clinical documentation, imaging workflows, and brace wear tracking.

ScoliBase Connect is a mobile application within the ScoliBase ecosystem that may process PHI when authorized users sign in, record brace wear activity, review brace wear history or progress, add notes, or otherwise interact with health-related information associated with a ScoliBase account.

Uses and Disclosures for Treatment

PHI may be used or disclosed for treatment-related activities such as care coordination, referral handling, clinical review, brace-related care workflows, and secure communication among authorized care participants.

Information recorded through ScoliBase Connect may be made available to authorized healthcare personnel or other authorized users when necessary to support care coordination and related treatment activities.

Payment and Healthcare Operations

PHI may be used or disclosed for billing, payment operations, scheduling, internal quality improvement, workforce operations, audit, compliance, security review, system administration, and other healthcare operations as permitted by law.

Other Permitted Disclosures

PHI may also be used or disclosed when permitted or required by law, including for legal requirements, public health activities, abuse or neglect reporting, health oversight, certain law enforcement requests, judicial or administrative proceedings, or situations involving a serious threat to health or safety.

Business Associates and Service Providers

ScoliBase and applicable healthcare organizations may use vendors or service providers to support hosting, security, communications, technical operations, and other services. Where required by HIPAA, appropriate Business Associate Agreements or other safeguards may be used to govern access to PHI.

Your Rights

Where applicable, you may have the right to inspect or obtain copies of certain health records, request amendments, request restrictions, request confidential communications, receive an accounting of certain disclosures, obtain a copy of the applicable Notice of Privacy Practices, and file a privacy complaint.

Some rights may be exercised through the healthcare organization responsible for the applicable medical record or treatment relationship rather than directly through ScoliBase.

Guardian and Minor Access

ScoliBase and ScoliBase Connect may support access by parents, guardians, or other authorized representatives. Access to a minor's PHI is subject to applicable law, authorization requirements, organizational policies, and the circumstances of the applicable healthcare relationship.

Organization Responsibilities

ScoliBase and the applicable healthcare organization are responsible for safeguarding PHI within their respective roles, following applicable privacy and security requirements, and updating privacy practices when legal requirements or operational practices change.

Privacy Complaints

Users may raise privacy concerns or submit complaints through the designated Privacy Officer or published complaint channel for the applicable organization. Retaliation for filing a good-faith privacy complaint is prohibited where required by law.

Contact

Questions, requests, or complaints regarding PHI handled through ScoliBase or ScoliBase Connect should be directed to the designated Privacy Officer or published privacy contact channel for the applicable organization.