NOTICE OF PRIVACY PRACTICES

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Effective Date: 11/01/2024

Shields Health Care Group (“Shields”) is required by law to maintain the privacy of your health information in accordance with federal and state law. This Notice of Privacy Practices (“Notice”) outlines our legal duties and privacy practices with respect to health information. We are required by law to provide you with a copy of this Notice and to notify you following a breach of your unsecured health information. Shields may provide health care through health care providers who are contracted with Shields. All such Shields health care providers have agreed to be bound by this Notice.

We will abide by the terms of the Notice. We reserve the right to make changes to this Notice as permitted by law. We reserve the right to make the new Notice provisions effective for all health information we currently maintain, as well as any health information we receive in the future. If we make material or important changes to our privacy practices, we will promptly revise our Notice. Each version of the Notice will have an effective date listed on the first page. If we change this Notice, you can access the revised Notice on our website (www.shields.com) or from the receptionist at any of our facilities.

You have the right to file a complaint if you believe your privacy rights have been violated. If you would like to file a complaint about our privacy practices, you can do so by sending a letter outlining your concerns to: Shields Health Care Group, Attn: Privacy Officer, 700 Congress Street, Quincy, MA 02169 or by contacting our Privacy Officer at 1-800-258-4674. You also have the right to complain to the Secretary of the United States Department of Health and Human Services. You will not be penalized or otherwise retaliated against for filing a complaint.

USES AND DISCLOSURES OF YOUR HEALTH INFORMATION:

The following categories describe the ways that we may use and disclose your health information without your written authorization.

Treatment. We may use and disclose your health information to provide you with medical treatment and services. For example, your images from an MRI scan may be disclosed to radiologists or other health care providers who are involved in your care for interpretation of your scan for purposes of treatment and to coordinate or manage your health care services.

Payment. We may use and disclose your health information to obtain payment for the services we provide to you. For example, we may disclose your health information to seek payment from your insurance company or from another third party. We may also inform your insurance company about a treatment you are going to receive so that we obtain prior approval for the treatment or in order to determine whether your insurance company will cover the cost of the treatment.

Health Care Operations. We may use and disclose your health information to conduct certain of our business activities, which are called health care operations. These uses and disclosures are necessary to run our business and make sure our patients receive quality care. For example, we may use your health information for quality assessment activities, necessary credentialing, and for other essential activities. We may also disclose your health information to third party “business associates” that perform various services on our behalf, such as transcription, billing, and collection services. In these cases, we will enter into a written agreement with the business associates to ensure they protect the privacy of your health information.

Family Members and Friends for Care and Payment and Notification. If you verbally agree to the use or disclosure and in certain other situations, we may make the following uses and disclosures of your health information. We may disclose certain health information to your family, friends, and anyone else whom you identify as involved in your health care or who helps pay for your care; the health information we disclose would be limited to the health information that is relevant to that person’s involvement in your care or payment for your care. We may also make these disclosures after your death as authorized by applicable law unless doing so is inconsistent with any prior expressed preference. We may use or disclose your information to notify or assist in notifying a family member, personal representative, or any other person responsible for your care regarding your location, general condition, or death. We may also use or disclose your health information to disaster-relief organizations so that your family or other persons responsible for your care can be notified about your condition, status, and location.

Required by Law. We may disclose your health information when required by law to do so.

Public Health Reporting. We may disclose your health information to public health agencies as authorized by law. For example, we may report information to cancer registries.

Reporting Victims of Abuse or Neglect. We may disclose health information to the appropriate government authority if we believe you have been the victim of abuse, neglect, or domestic violence. We only make this disclosure if you agree or when we are required or authorized by law to make the disclosure.

Health Care Oversight. We may disclose your health information to authorities and agencies for oversight activities allowed by law, including audits, investigations, inspections, licensure and disciplinary actions, or civil, administrative, and criminal proceedings, as necessary for oversight of the health care system, government programs, and civil rights laws.

Legal Proceedings. We may disclose your health information in the course of certain administrative or judicial proceedings. For example, we may disclose your health information in response to a court order.

Law Enforcement. We may disclose your health information to a law enforcement official for certain specific purposes, such as reporting certain types of injuries.

Deceased Persons. We may disclose your health information to coroners, medical examiners, or funeral directors so that they can carry out their duties.

Organ and Tissue Donation. We may use and disclose your health information to organizations that handle procurement, transplantation, or banking of organs, eyes, or tissues.

Research. Under certain circumstances, we may disclose your health information to researchers who are conducting a specific research project. For certain research activities, an Institutional Review Board (IRB) or Privacy Board may approve uses and disclosures of your health information without your authorization.

To Avert a Serious Threat to Health or Safety. If there is a serious threat to your health and safety or the health and safety of the public or another person, we may use and disclose your health information in a very limited manner to someone able to help lessen the threat.

Specialized Government Functions. In certain circumstances, HIPAA authorizes us to use or disclose your health information to authorized federal officials for the conduct of national security activities and other specialized government functions.

Inmates. If you are an inmate of a correctional institution or under the custody of a law enforcement official, we may disclose your health information to the correctional institution or law enforcement official to assist them in providing you health care, protecting your health and safety or the health and safety of others, or providing for the safety of the correctional institution.

Workers’ Compensation. We may disclose your health information as necessary to comply with laws related to workers’ compensation or other similar programs.

Fundraising. We may use certain information (such as demographic information, dates of services, department of service, treating physicians, outcomes, and health insurance status) to send fundraising communications to you. However, you may opt out of receiving any such communications.

Please be aware that state and other federal laws may have additional requirements that we must follow or may be more restrictive than HIPAA on how we use and disclose certain of your health information. If there are specific more restrictive requirements, even for some of the purposes listed above, we may not disclose your health information without your written permission as required by such laws. For example, we may be required by law to obtain your written permission to use and/or disclose your mental illness, developmental disability, or substance use disorder treatment records, HIV, STD, or other communicable disease related information, or your genetic test results in certain situations.

OTHER USES AND DISCLOSURES:

Disclosure of your health information or its use for any purpose other than those listed above requires your specific written authorization. Some examples include:
• Psychotherapy Notes: We usually do not maintain psychotherapy notes about you. If we do, we will not use and disclose your psychotherapy notes without your written authorization except as otherwise permitted by law.
• Marketing: We will not use or disclose your health information for marketing purposes without your written authorization except as otherwise permitted by law.
• Sale of Your Health Information: We will not sell your health information without your written authorization except as otherwise permitted by law.

If you change your mind after authorizing a use or disclosure of your health information, you may withdraw your permission by revoking the authorization. However, your decision to revoke the authorization will not affect or undo any use or disclosure of your health information that occurred before you notified us of your decision, or any actions that we have taken based upon your authorization. To revoke an authorization, you must notify us in writing at Shields Health Care Group, Attn: Privacy Officer, 700 Congress Street, Quincy, MA 02169.

YOUR RIGHTS REGARDING YOUR HEALTH INFORMATION:

This section describes your rights regarding the health information we maintain about you. All requests or communications to us to exercise your rights discussed below must be submitted in writing to Shields Health Care Group, Attn: Privacy Officer, 700 Congress Street, Quincy, MA 02169.

Right to Request Restrictions. You have the right to request restrictions on how your health information is used or disclosed for treatment, payment, or health care operations activities. However, we are not required to agree to your requested restriction, unless that restriction is regarding disclosure of health information to your health insurance company and: (1) the disclosure is for the purpose of carrying out payment or health care operations and is not otherwise required by law; and (2) the health information pertains solely to a health care item or service for which you or another person (other than your health insurance company) paid for in full. If we agree to your requested restriction, we will comply with your request unless the information is needed to provide you emergency treatment.

Right to Request Confidential Communications. You have the right to request that we communicate your health information to you in a certain manner or at a certain location. For example, you may wish to receive information about your health status through a written letter sent to a private address. We will grant reasonable requests. We will not ask you the reason for your request.

Right to Inspect and Copy. You have the right to inspect and receive a copy of your health information. We may charge you a fee as authorized by law to meet your request. You may request access to your health information in a certain electronic form and format, if readily producible, or, if not readily producible, in a mutually agreeable electronic form and format. We may deny your request to inspect and copy in certain very limited circumstances. If you are denied access to your health information, you may request that the denial be reviewed by a licensed health care professional chosen by us. The person conducting the review will not be the person who denied your request. We will comply with the outcome of the review.

Right to Amend. You have a right to request that we amend or correct your health information that you believe is incorrect or incomplete. For example, if your date of birth is incorrect, you may request that the information be corrected. To request a correction or amendment to your health information, you must make your request in writing and provide a reason for your request. You have the right to request an amendment for as long as the information is kept by or for us. Under certain circumstances we may deny your request. If your request is denied, we will provide you with information about our denial and how you can file a written statement of disagreement with us that will become part of your medical record.

Right to an Accounting of Disclosures. You have the right to request an accounting of disclosures we make of your health information. Please note that certain disclosures need not be included in the accounting we provide to you. Your request must state a time period which may not go back further than six years. You will not be charged for this accounting, unless you request more than one accounting per year, in which case we may charge you a reasonable cost-based fee for providing the additional accounting(s). We will notify you of the costs involved and give you an opportunity to withdraw or modify your request before any costs have been incurred.

Right to a Paper Copy of This Notice. You have the right to receive a paper copy of this Notice at any time, even if you previously agreed to receive this Notice electronically. A paper copy of this Notice can be obtained from the receptionist at any of our facilities and is also available at our website at www.shields.com.

CONTACT INFORMATION:

If you have questions or concerns about your privacy rights, or the information contained in this Notice, please contact the Shields Privacy Officer in writing at 700 Congress Street, Quincy, MA 02169 or by telephone at 1-800-258-4674.