PRIVACY POLICY & TERMS
Privacy Policy & Terms and Conditions
Effective Date: 3/1/2026
This Privacy Policy and Notice of Privacy Practices (“Notice”) describes how medical and personal information about you may be used and disclosed and how you can access this information.
Nusbaum Medical Centers (“we,” “our,” or “the Practice”) is committed to protecting the privacy and security of your information. We comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the HIPAA Privacy Rule, the HIPAA Security Rule, the HIPAA Breach Notification Rule, and applicable New Jersey medical privacy laws.
SECTION 1 – PROTECTED HEALTH INFORMATION (PHI)
Protected Health Information (“PHI”) is individually identifiable health information relating to your past, present, or future physical or mental health, the provision of healthcare services to you, or payment for healthcare services.
PHI may include, but is not limited to:
- Medical records
- Diagnoses and treatment plans
- Test results
- Prescription information
- Billing and insurance information
- Demographic identifiers
This Notice applies to all PHI created, received, maintained, or transmitted by our Practice.
SECTION 2 – HOW WE USE AND DISCLOSE PHI
We may use and disclose PHI without your written authorization for the following purposes:
A. Treatment
To provide, coordinate, or manage your healthcare and related services.
B. Payment
To bill and collect payment from insurance companies, Medicare/Medicaid, or other third parties.
C. Healthcare Operations
For business and administrative activities, including:
- Quality assessment and improvement
- Licensing and accreditation
- Compliance reviews
- Staff training
- Risk management
- Audits
D. As Required by Law
We may disclose PHI when required by federal, state, or local law.
E. Public Health & Safety
We may disclose PHI as permitted or required by law for public health and safety purposes, including:
- Reporting communicable diseases
- Reporting abuse or neglect
- Health oversight activities
- Court orders or lawful subpoenas
F. Business Associates
We may share PHI with third-party vendors (e.g., billing services, EHR providers, IT vendors, telehealth platforms) that perform services on our behalf. These vendors are required to protect PHI under HIPAA-compliant Business Associate Agreements (BAAs).
SECTION 3 – USES REQUIRING WRITTEN AUTHORIZATION
We will obtain your written authorization before:
- Using PHI for marketing not permitted under HIPAA
- Selling PHI
- Disclosing psychotherapy notes (except as permitted by law)
- Any other use not described in this Notice
You may revoke authorization in writing at any time.
SECTION 4 – YOUR RIGHTS UNDER HIPAA
You have the following rights regarding your PHI:
1. Right to Access
You may inspect or obtain a copy of your medical records.
2. Right to Amend
You may request corrections if you believe information is inaccurate or incomplete.
3. Right to an Accounting of Disclosures
You may request a list of certain disclosures made within the previous six (6) years.
4. Right to Request Restrictions
You may request limits on how we use or disclose PHI.
5. Right to Confidential Communications
You may request communications by alternative means (e.g., different address or phone number).
6. Right to a Paper Copy
You may request a paper copy of this Notice at any time.
To exercise these rights, contact our Privacy Officer:
Privacy Officer
Nusbaum Medical Centers[Insert Address]
Phone: [Insert Phone]
Email: [Insert Email]
SECTION 5 – TELEHEALTH PRIVACY DISCLOSURE
If you participate in telehealth services:
- Telehealth visits are conducted using HIPAA-compliant technology platforms.
- Electronic communications may involve transmission of PHI over secure systems.
- While we use encryption and secure networks, no system is 100% immune from cybersecurity risks.
- Telehealth providers and technology vendors operate under HIPAA Business Associate Agreements.
By participating in telehealth, you acknowledge and accept these privacy practices.
SECTION 6 – SMS / TEXT MESSAGE COMMUNICATIONS
If you provide your mobile phone number, you consent to receive SMS/text communications for:
- Appointment reminders
- Scheduling confirmations
- Care coordination messages
- Billing notifications
Important disclosures:
- Message and data rates may apply.
- Frequency varies.
- You may opt out at any time by replying STOP.
- We do not sell your phone number.
- SMS is not intended for emergency communication.
If you wish to withdraw consent, contact our office directly.
SECTION 7 – WEBSITE DATA COLLECTION
When you visit our website, we may collect:
- IP address
- Browser type
- Device information
- Pages visited
- Contact form submissions
We may use cookies and analytics tools for website performance and marketing purposes. Information submitted through website forms may include personal information. Secure forms are transmitted using SSL encryption.
We recommend not submitting detailed medical information through unsecured email.
SECTION 8 – PATIENT PORTAL
If you use our patient portal:
- Access is password-protected.
- Data is encrypted in transit.
- You are responsible for maintaining login confidentiality.
- Portal messaging is part of your designated medical record.
SECTION 9 – SAFEGUARDS
We maintain administrative, physical, and technical safeguards designed to protect PHI, including:
- Encrypted electronic medical records
- Access controls and user authentication
- Workforce HIPAA training
- Secure facility protections
- Periodic risk assessments
- Secure data disposal procedures
SECTION 10 – BREACH NOTIFICATION
In the event of a breach involving unsecured PHI, we will notify affected individuals, the U.S. Department of Health and Human Services, and, when required, the media, in accordance with HIPAA regulations.
SECTION 11 – NEW JERSEY PRIVACY LAW
In addition to HIPAA, we comply with applicable New Jersey laws governing confidentiality of medical records, including heightened protections for certain behavioral health, substance use, and minor patient information where applicable.
SECTION 12 – COMPLAINTS
If you believe your privacy rights have been violated, you may file a complaint with:
Privacy Officer
Nusbaum Medical Centers[Insert Address]
Phone: [Insert Phone]
Email: [Insert Email]
Or with:
U.S. Department of Health and Human Services
Office for Civil Rights
https://www.hhs.gov/ocr/privacy/hipaa/complaints/
We will not retaliate against you for filing a complaint.
SECTION 13 – CHANGES TO THIS NOTICE
We reserve the right to change this Notice at any time. Updated versions will be posted on this page with a revised effective date.
