HIPAA Notice of Privacy Practices
1. About This Notice
HOOTL MedicalAssist ("the Platform") is required by law to maintain the privacy of protected health information (PHI), to provide individuals with notice of our legal duties and privacy practices with respect to PHI, and to follow the terms of the notice that is currently in effect. This Notice of Privacy Practices ("Notice") describes how we may use and disclose PHI and your rights regarding that information.
This Notice applies to all PHI created, received, maintained, or transmitted by the Platform in connection with the medical denial appeal management services we provide.
2. Uses and Disclosures of PHI
2.1 Treatment
We may use and disclose PHI to assist in the coordination of healthcare services related to denial appeals. This includes sharing case information with authorized healthcare providers within your practice who are involved in the patient's care or appeal process.
2.2 Payment
We may use and disclose PHI as necessary for payment-related activities, including generating appeal letters to insurers, documenting medical necessity for denied claims, and supporting reimbursement efforts for healthcare services.
2.3 Healthcare Operations
We may use and disclose PHI for healthcare operations, including quality assessment and improvement, case management, auditing, compliance activities, and business planning related to the denial appeal management process.
2.4 Business Associates
We may disclose PHI to our business associates who perform services on our behalf that involve the use or disclosure of PHI. All business associates are required to enter into Business Associate Agreements (BAAs) that obligate them to protect PHI in accordance with HIPAA. Our current business associates include:
- Anthropic — Provides AI services (Claude API) used for denial analysis and appeal letter generation. PHI is processed under a BAA and is not retained after processing or used for model training.
- Cloudflare — Provides hosting, database, and infrastructure services. PHI is stored and processed under a BAA with appropriate security controls.
2.5 Required by Law
We may use or disclose PHI when required to do so by federal, state, or local law, including for public health activities, health oversight activities, judicial and administrative proceedings, law enforcement purposes, and to avert a serious threat to health or safety.
2.6 Authorization-Based Disclosures
Other uses and disclosures of PHI not described in this Notice will be made only with your written authorization. You may revoke any authorization at any time by submitting a written request to our Privacy Officer, except to the extent that we have already taken action in reliance on the authorization.
3. Your Rights Regarding PHI
3.1 Right to Access
You have the right to inspect and obtain a copy of PHI maintained about you in our records. To request access, submit a written request to our Privacy Officer. We will respond within 30 days. We may charge a reasonable, cost-based fee for copies.
3.2 Right to Request Amendment
You have the right to request an amendment to PHI maintained in our records if you believe the information is inaccurate or incomplete. Submit amendment requests in writing to our Privacy Officer. We may deny the request under certain circumstances as permitted by HIPAA, and will provide a written explanation if denied.
3.3 Right to an Accounting of Disclosures
You have the right to request an accounting of certain disclosures of your PHI that we have made. This accounting will not include disclosures made for treatment, payment, or healthcare operations, or disclosures made with your authorization. Submit requests in writing to our Privacy Officer.
3.4 Right to Request Restrictions
You have the right to request restrictions on how we use or disclose your PHI for treatment, payment, or healthcare operations. While we are not required to agree to all restriction requests, we will accommodate reasonable requests where possible. We are required to agree to a restriction if the disclosure is to a health plan for payment or healthcare operations and the PHI pertains to a service that has been paid for in full out of pocket.
3.5 Right to Confidential Communications
You have the right to request that we communicate with you about your PHI in a specific way or at a specific location. We will accommodate reasonable requests.
3.6 Right to a Copy of This Notice
You have the right to obtain a paper or electronic copy of this Notice at any time. To request a copy, contact our Privacy Officer or download it from this page.
3.7 Right to File a Complaint
If you believe your privacy rights have been violated, you may file a complaint with us or with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights. You will not be retaliated against for filing a complaint.
- File with us: Contact our Privacy Officer at privacy@hootl.com
- File with HHS: www.hhs.gov/hipaa/filing-a-complaint
4. Our Duties
We are required by law to:
- Maintain the privacy of PHI and provide you with notice of our legal duties and privacy practices.
- Abide by the terms of this Notice currently in effect.
- Notify you if a breach of unsecured PHI occurs that affects your information, in accordance with the HIPAA Breach Notification Rule (45 CFR 164.400-414).
- Not use or disclose PHI for marketing purposes without your written authorization.
- Not sell PHI without your written authorization.
- Obtain your authorization before using or disclosing psychotherapy notes, if applicable.
5. Security Measures
We implement comprehensive administrative, physical, and technical safeguards to protect PHI, including:
- Encryption: All PHI is encrypted at rest using AES-GCM-256 encryption and in transit using TLS 1.3.
- Access Controls: Role-based access controls (RBAC), multi-practice isolation, and session management.
- Audit Logging: All access to PHI is logged with user identification, timestamps, and action details. Audit logs are retained for a minimum of 6 years.
- Workforce Training: Personnel with access to PHI receive HIPAA privacy and security training.
- Incident Response: Documented breach detection, investigation, and notification procedures.
6. Business Associate Agreements
If you are a Covered Entity under HIPAA and wish to use the Platform for managing PHI, a Business Associate Agreement (BAA) must be executed between your organization and HOOTL MedicalAssist prior to the submission of any PHI. To request a BAA, contact us at legal@hootl.com.
We maintain BAAs with all of our subcontractors and service providers who may access or process PHI on our behalf. These agreements require that our business associates implement appropriate safeguards, report security incidents, and comply with applicable HIPAA requirements.
7. Changes to This Notice
We reserve the right to change the terms of this Notice and to make the new provisions effective for all PHI that we maintain. If we make material changes, we will post the revised Notice on this page with an updated effective date. We will also make the revised Notice available upon request.
8. Contact Information
For questions about this Notice, to exercise your rights, or to file a complaint, contact our Privacy Officer:
- HIPAA Privacy Officer
- Email: privacy@hootl.com
- Subject Line: HIPAA Privacy Inquiry
For general support inquiries, contact support@hootl.com.
← Back to home