Effective Date: October 29, 2024
Table of Contents
- Introduction
- Definitions
- Notice of Privacy Practices
- Information We Collect
- How We Use Your Information
- Legal Bases for Processing Information
- How We Share Your Information
- Your Rights and Choices
- Data Retention
- Cookies and Similar Technologies
- Data Security
- Breach Notification Procedures
- Children’s Privacy
- International Data Transfers
- Changes to This Privacy Policy
- Consent for Electronic Communications
- Contact Us
- Limitation of Liability
- Terms of Service
- Governing Law and Dispute Resolution
- Acknowledgment
Introduction
Levanti Health LLC (“Levanti Health“, “we“, “us“, or “our“) is committed to protecting the privacy and security of your personal and health information. This Privacy Policy outlines how we collect, use, disclose, and safeguard your information when you visit our website www.levantihealth.com (“Website“) and use our telehealth services (“Services“).
By accessing or using our Website and Services, you agree to the terms of this Privacy Policy and our Terms of Service.
Definitions
- “Personal Information”: Information that identifies, relates to, describes, or can be associated with an individual, including but not limited to name, address, email address, phone number, date of birth, and payment information.
- “Protected Health Information (PHI)”: Individually identifiable health information that is transmitted or maintained in any form or medium, as defined under the Health Insurance Portability and Accountability Act (HIPAA).
- “Cookies”: Small data files stored on your device by a website to enhance user experience.
Notice of Privacy Practices
This Notice of Privacy Practices describes how Levanti Health may use and disclose your PHI to carry out treatment, payment, or healthcare operations and for other purposes permitted or required by law. It also describes your rights to access and control your PHI.
Our Responsibilities
- Legal Obligations: We are required by law to maintain the privacy and security of your PHI and to provide you with this Notice of our legal duties and privacy practices.
- Compliance: We comply with all applicable federal and Michigan state laws, including HIPAA and the Michigan Medical Records Access Act.
Information We Collect
We may collect the following types of information:
4.1 Personal Information
- Name
- Mailing address
- Email address
- Phone number
- Date of birth
- Payment information (e.g., credit card details)
4.2 Protected Health Information (PHI)
- Medical history
- Medications
- Treatment plans
- Diagnostic information
- Health insurance information
- Any other health-related information necessary to provide our Services
4.3 Communication Data
- Information provided through communications with us via Updox, emails, phone calls, or other channels
4.4 Technical Data
- IP address
- Browser type and version
- Operating system
- Device identifiers
- Browsing behavior on our Website
- Cookies and similar tracking technologies
How We Use Your Information
We use your information for the following purposes:
5.1 Treatment
- Providing Medical Services: To facilitate telehealth consultations, diagnose health conditions, prescribe medications, and deliver healthcare Services in compliance with applicable laws and regulations.
5.2 Payment
- Billing and Payments: To process payments for our Services and manage your account.
5.3 Healthcare Operations
- Service Improvement: To analyze data for improving our Website, Services, and user experience.
- Quality Assurance: To monitor the quality of care provided by our healthcare professionals.
- Training and Education: For training purposes within Levanti Health.
5.4 Communication
- Appointments and Follow-ups: To contact you regarding appointments, treatment plans, and follow-up care.
- Customer Service: To respond to your inquiries and provide support.
5.5 Legal Compliance
- Regulatory Requirements: To comply with federal and state laws, including HIPAA and Michigan state privacy laws.
- Law Enforcement: To respond to legal requests and prevent harm.
5.6 Marketing and Promotions
- With Your Consent: To send you promotional materials and updates about our Services. You may opt-out at any time.
5.7 Security and Fraud Prevention
- Protecting Our Interests: To detect, prevent, and respond to fraud, unauthorized activities, or other harmful activities.
Legal Bases for Processing Information
We process your Personal Information and PHI based on the following legal grounds:
- Consent: You have given explicit consent for processing your information for specific purposes.
- Contractual Necessity: Processing is necessary to perform our contract with you or to take steps at your request before entering into a contract.
- Legal Obligations: Processing is necessary to comply with legal obligations.
- Vital Interests: Processing is necessary to protect your vital interests or those of another person.
- Legitimate Interests: Processing is necessary for our legitimate interests, such as improving our Services, provided that your rights do not override these interests.
How We Share Your Information
We may share your information in the following situations:
7.1 Healthcare Providers
Your PHI may be shared with our contracted medical professionals to provide you with care:
- Dr. Sarah Kaminsky, DO
- Located at: 315 E Eisenhower Pkwy, STE 9B, Ann Arbor, Michigan 48108
- Amanda Compton, FNP
- Located at: 315 E Eisenhower Pkwy, STE 9B, Ann Arbor, Michigan 48108
7.2 Business Associates
We share information with third-party service providers (“Business Associates”) under strict confidentiality and data protection agreements, as required by HIPAA:
- Practice Fusion: Secure electronic health record (EHR) platform
- Updox: Secure messaging and telehealth communication tool
7.3 Legal Compliance and Public Safety
- We may share information to comply with applicable laws and to protect the safety of patients and others.
Your Rights and Choices
As a user of our Services, you have rights related to your Personal Information and PHI:
- Right to Access: You have the right to access your Personal Information and PHI maintained by us.
- Right to Rectification: You may request corrections to any inaccurate or incomplete information we hold about you.
- Right to Erasure: You may request deletion of your information, subject to legal requirements.
- Right to Restrict Processing: You may request limitations on how we use your information.
- Right to Data Portability: You may request a copy of your data in a portable format.
- Right to Object: You may object to the processing of your data under certain circumstances.
Data Retention
We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy or as required by law. We may retain and use your data as needed to comply with legal obligations, resolve disputes, enforce agreements, or protect our interests.
Cookies and Similar Technologies
We use cookies and similar tracking technologies to enhance your browsing experience on our Website. You may choose to accept or decline cookies through your browser settings. Declining cookies may limit some functionality of the Website.
Data Security
We employ various security measures to protect your information:
11.1 Technical Safeguards
- Encryption: Data is encrypted at rest and in transit using industry-standard protocols.
- Access Controls: Restricted access to PHI and Personal Information based on job responsibilities.
- Firewalls and Intrusion Detection: Protect our systems from unauthorized access.
11.2 Administrative Safeguards
- Policies and Procedures: Implemented comprehensive policies to protect data.
- Employee Training: Regular training on privacy and security practices.
- Confidentiality Agreements: All employees and contractors sign agreements to protect your information.
11.3 Physical Safeguards
- Secure Facilities: Physical security measures at our offices and data centers.
- Data Disposal: Secure methods for disposing of PHI and Personal Information.
Breach Notification Procedures
In the event of a breach of unsecured PHI:
- Notification to Affected Individuals: We will notify you without unreasonable delay and no later than 60 days after discovery.
- Content of Notification: The notice will include a description of the breach, types of information involved, steps you should take, our response actions, and contact information.
- Regulatory Notification: We will notify the U.S. Department of Health and Human Services and, if required, media outlets.
Children’s Privacy
Our Services are not intended for individuals under 18 years of age. We do not knowingly collect information from minors without parental consent.
- If Collected Accidentally: If we become aware that we have inadvertently collected Personal Information from a minor without parental consent, we will delete such information promptly.
International Data Transfers
Our Services are intended for residents of the State of Michigan, USA. All data processing activities are conducted within the United States.
- No International Transfers: We do not transfer your Personal Information or PHI outside the United States.
- Future Transfers: If international data transfers become necessary, we will notify you and ensure compliance with applicable data protection laws.
Changes to This Privacy Policy
We may update this Privacy Policy periodically. Changes will be:
- Posted on This Page: With the updated effective date.
- Advance Notice: For significant changes, we will provide at least 30 days’ notice via email or prominent notice on our Website.
- Your Continued Use: Your continued use of our Services after changes take effect constitutes acceptance of the updated Privacy Policy.
Consent for Electronic Communications
By providing your contact information, you consent to receive communications electronically, including:
- Email: Appointment reminders, treatment information, and marketing communications.
- Text Messages: Notifications and alerts.
- Electronic Documents: Access to electronic records and agreements.
E-Sign Act Compliance
- Your Rights: You have the right to receive paper copies and withdraw consent for electronic communications.
- How to Exercise: Contact our Privacy Officer to request paper copies or withdraw consent.
Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact:
Privacy Officer
Levanti Health LLC
315 E Eisenhower Pkwy, STE 9B
Ann Arbor, Michigan 48108
Phone: +1 (877) 522-0888
Email: [email protected]
Limitation of Liability
To the fullest extent permitted by law:
- No Liability: Levanti Health LLC shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising out of your use of our Website or Services.
- Maximum Liability: Our total liability to you shall not exceed the amounts paid by you for the Services.
Terms of Service
This Privacy Policy is part of our Terms of Service (“Terms“), which governs your use of our Website and Services. Please review the Terms carefully.
Governing Law and Dispute Resolution
20.1 Governing Law
- Jurisdiction: This Privacy Policy and any disputes arising out of or related to it are governed by the laws of Washtenaw County in the State of Michigan, without regard to its conflict of law provisions.
20.2 Dispute Resolution
- Good Faith Efforts: Parties agree to attempt to resolve disputes informally before initiating arbitration or litigation.
- Arbitration: Any unresolved disputes shall be settled by binding arbitration in Washtenaw County, Michigan, in accordance with the rules of the American Arbitration Association.
- Exceptions: Either party may seek injunctive relief in a court of competent jurisdiction for intellectual property infringement or confidentiality breaches.
Acknowledgment
By using our Website and Services, you acknowledge that you have read, understood, and agree to this Privacy Policy.
Last Updated: October 29, 2024
Note: This Privacy Policy is designed to comply with federal laws, including HIPAA, and Michigan state laws. For specific legal advice or concerns, please consult with a legal professional.
Accessibility
We are committed to ensuring that our Privacy Policy is accessible to individuals with disabilities. If you require this Privacy Policy in an alternative format, please contact us.
Version History
- Version 1.0: Effective October 29, 2024
Additional Information
- Employee Confidentiality: All employees and contractors with access to PHI are required to sign confidentiality agreements and undergo regular training on privacy practices.
- Data Minimization: We collect only the minimum necessary information required to provide our Services, in compliance with HIPAA’s Minimum Necessary Rule.
- Third-Party Advertising: We do not use third-party advertising services on our Website.
- Users Outside of Michigan: Our Services are intended for Michigan residents. If you access our Website from outside Michigan, your information will be handled in accordance with this Privacy Policy, but please note that we may not be subject to the data protection laws of your jurisdiction.
Effective Date
This Privacy Policy is effective as of October 29, 2024.
Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at [email protected].