HIPAA Privacy Policy

Effective Date: 8/4/2025

1. Introduction

Welcome to RegenhHaus Medical Atlanta. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy outlines how we collect, use, disclose, and safeguard your data in compliance with applicable laws and regulations, including the Federal Trade Commission (FTC) guidelines, the Fair Credit Reporting Act (FCRA), the General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).

2. Information We Collect

We collect the following types of personal information:
  • Contact Information: Name, email address, phone number.
  • Financial Information: Soft credit data, wallet balance, and unsecured credit line approvals (collected in compliance with FCRA regulations).
  • Usage Data: Information about how you use our services, including interaction data and preferences.

3. How We Collect Information

We collect information through:

  • Direct Interactions: When you provide information by filling out forms or communicating with us.
  • Automated Technologies: Through cookies and similar tracking technologies as you interact with our website.
  • Third Parties: From partners and service providers who assist us in delivering our services.
  • Credit Pre-Screening: We may collect financial data through a soft credit pull authorized under the FCRA for the purpose of determining financial qualifications.

4. Purpose of Data Processing

We process your personal information for the following purposes:

  • Service Delivery: To provide and manage our services effectively.
  • Personalization: To tailor our services to your preferences.
  • Communication: To send updates, newsletters, and marketing materials, where permitted.
  • Compliance: To adhere to legal obligations, including FCRA compliance for credit pre-screening.

5. Legal Basis for Processing (GDPR Compliance)

Our legal grounds for processing personal data include:

  • Consent: When you have given explicit consent for specific purposes.
  • Contractual Necessity: To fulfill our contractual obligations to you.
  • Legal Obligation: To comply with legal and regulatory requirements, including FCRA mandates.
  • Legitimate Interests: For purposes such as improving our services, provided these interests are not overridden by your rights.

6. Consumer Rights

Under GDPR:

  • Access: You have the right to request access to your personal data.
  • Rectification: You can request correction of inaccurate data.
  • Erasure: You have the right to request deletion of your data.
  • Restriction: You can request the restriction of processing under certain conditions.
  • Data Portability: You have the right to receive your data in a structured, commonly used format.
  • Objection: You can object to processing based on legitimate interests.

Under CCPA:

  • Right to Know: You can request disclosure of the categories and specific pieces of personal information we have collected.
  • Right to Delete: You can request deletion of your personal information.
  • Right to Opt-Out: You can opt-out of the sale of your personal information.
  • Non-Discrimination: You have the right not to be discriminated against for exercising your CCPA rights.

Under FCRA:

  • Access to Credit Data: You can request information about your credit data collected during the pre-screening process.
  • Dispute Inaccuracies: You have the right to dispute any inaccuracies in your credit information and request corrections.
  • Purpose Disclosure: We conduct soft credit pulls strictly for the purpose of financial qualification, as permitted by FCRA regulations.

To exercise these rights, please contact us at:

RegenhHaus Medical Atlanta
3155 North Point Parkway, Suite F-200, Alpharetta, GA  30005
404-424-4068
https://regenhausmedical.com/

7. Data Sharing and Disclosure

We may share your personal information with:

  • Service Providers: Third parties who assist us in providing our services.
  • Legal Obligations: Authorities when required by law or to protect our rights.
  • Business Transfers: In connection with mergers, acquisitions, or asset sales.
Soft credit pull data is shared only with authorized entities in compliance with FCRA regulations.

8. Data Retention

We retain personal information only as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. FCRA data is retained securely for the duration required by law.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction, in compliance with FTC, GDPR, CCPA, and FCRA standards.

10. International Data Transfers (GDPR Compliance)

If we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.

11. Children's Privacy

Our services are not directed to individuals under 16. We do not knowingly collect personal information from children under 16.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on our website.

13. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:

RegenhHaus Medical Atlanta
3155 North Point Parkway, Suite F-200, Alpharetta, GA  30005
404-424-4068
https://regenhausmedical.com/

Effective Date: January 2025

Introduction

RegenHaus Medical is committed to protecting the privacy and security of your protected health information (PHI) in compliance with the Health Insurance Portability and Accountability Act (HIPAA) and applicable state laws. This HIPAA Privacy Policy outlines how we collect, use, and disclose your PHI, your rights regarding your health information, and how you can contact us with questions or concerns.

1. How We Use and Disclose Your Health Information

RegenHaus Medical may use and disclose your PHI for the following purposes:

A. Permitted Uses and Disclosures

We may use or share your PHI for the following reasons:

  • Treatment: We may use and share your PHI with doctors, nurses, or other healthcare providers involved in your care.
  • Payment: Your PHI may be used to process claims, obtain payment from insurance providers, or determine coverage.
  • Healthcare Operations: We may use your PHI for administrative, quality improvement, and operational purposes, including staff training and compliance monitoring.

B. Additional Uses and Disclosures

  • Required by Law: We may disclose your PHI when required by federal, state, or local laws.
  • Public Health and Safety: Your PHI may be shared with public health authorities for disease control, reporting abuse, or preventing serious threats to health or safety.
  • Law Enforcement and Legal Proceedings: We may provide PHI in response to court orders, subpoenas, or as required by law enforcement agencies.
  • Business Associates: We may disclose PHI to third-party service providers (e.g., billing companies or IT providers) who assist us in our healthcare operations, provided they agree to protect your PHI.

C. Uses and Disclosures Requiring Authorization

We will not use or disclose your PHI for the following purposes without your written authorization:

  • Marketing or selling your PHI
  • Most uses of psychotherapy notes
  • Any disclosures not described in this policy
You may revoke your authorization at any time by providing written notice to our office.

2. Your Rights Regarding Your Health Information

Under HIPAA, you have the following rights:

  • Right to Access: You have the right to inspect and obtain a copy of your PHI.
  • Right to Amend: You may request corrections to your PHI if you believe it is incorrect or incomplete.
  • Right to Request Restrictions: You can request restrictions on how your PHI is used or disclosed; however, we may not always be able to accommodate these requests.
  • Right to Confidential Communications: You can request that we communicate with you through specific methods or locations (e.g., email, phone, or mail).
  • Right to an Accounting of Disclosures: You may request a list of certain disclosures of your PHI made in the past six years.
  • Right to File a Complaint: If you believe your privacy rights have been violated, you have the right to file a complaint with our office or with the U.S. Department of Health and Human Services (HHS) without fear of retaliation.

3. How We Protect Your Information

RegenHaus Medical takes appropriate safeguards to protect your PHI, including:
  • Using secure electronic systems to store and transmit PHI
  • Training staff on HIPAA compliance
  • Implementing administrative, physical, and technical security measures

4. Changes to This Policy

We reserve the right to update this HIPAA Privacy Policy at any time. Any changes will be posted on our website with the updated effective date.

5. Contact Information

For questions about this policy, to exercise your rights, or to file a complaint, please contact:

RegenHaus Medical

Alpharetta Location
(404) 424-4068
3155 North Point Parkway, Suite F-200
Alpharetta, GA 30005

If you wish to file a complaint with the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services, you may do so online at https://www.hhs.gov/ocr/ or by calling 1-800-368-1019.

By using our website and services, you acknowledge that you have read and understand this HIPAA Privacy Policy.