HIPAA Compliance Policy
Last Updated: January 1, 2025
Overview
QG MED is committed to maintaining the highest standards of privacy and security for all Protected Health Information (PHI) in accordance with the Health Insurance Portability and Accountability Act (HIPAA) of 1996, and its subsequent amendments including the HITECH Act and the HIPAA Omnibus Rule.
This policy outlines our practices and procedures to ensure the confidentiality, integrity, and availability of all PHI that we create, receive, maintain, or transmit.
Protected Health Information (PHI)
PHI includes any individually identifiable health information transmitted or maintained in any form or medium, including:
- Patient names, addresses, dates of birth, and Social Security numbers
- Medical record numbers and health insurance information
- Diagnosis and treatment information
- Prescription and medication records
- Laboratory and test results
- Any other health-related information that can identify an individual
Administrative, Physical, and Technical Safeguards
Administrative Safeguards
- Security Management Process: Regular risk assessments and security incident procedures
- Workforce Training: All employees receive HIPAA training and regular updates
- Access Management: Role-based access controls limiting PHI access to authorized personnel only
- Security Awareness: Ongoing education about security threats and proper handling of PHI
Physical Safeguards
- Facility Access Controls: Secure facilities with restricted access and monitoring
- Workstation Security: Policies governing the use and positioning of workstations
- Device and Media Controls: Proper disposal and reuse procedures for electronic media
Technical Safeguards
- Encryption: All PHI is encrypted both in transit (using TLS 1.2+) and at rest (AES-256)
- Access Controls: Unique user identification, automatic logoff, and emergency access procedures
- Audit Controls: Comprehensive logging and monitoring of all PHI access and modifications
- Transmission Security: Secure protocols for electronic PHI transmission
- Authentication: Multi-factor authentication for system access
Privacy Practices
Uses and Disclosures of PHI
We use and disclose PHI only for the following purposes:
- Treatment: Providing, coordinating, or managing healthcare services
- Payment: Billing and collection activities, insurance verification
- Healthcare Operations: Quality assessment, training, and business management
- Required by Law: When disclosure is mandated by federal, state, or local law
- With Authorization: Any other use requires written patient authorization
Minimum Necessary Standard
We adhere to the minimum necessary standard by limiting PHI access, use, and disclosure to the minimum amount necessary to accomplish the intended purpose.
Patient Rights Under HIPAA
Patients have the following rights regarding their PHI:
- Right to Access: Request and receive copies of their medical records
- Right to Amend: Request corrections to inaccurate or incomplete information
- Right to Accounting: Receive an accounting of PHI disclosures
- Right to Restrict: Request restrictions on certain uses and disclosures
- Right to Confidential Communications: Request communications by alternative means
- Right to Notice: Receive a copy of our Notice of Privacy Practices
- Right to Complain: File complaints without retaliation
Breach Notification
In the event of a breach of unsecured PHI, we will:
- Notify affected individuals without unreasonable delay and no later than 60 days after discovery
- Notify the Department of Health and Human Services (HHS) as required
- For breaches affecting 500 or more individuals, notify prominent media outlets
- Provide information about the breach, steps taken, and recommended actions
- Maintain documentation of all breach notification activities
Business Associate Agreements
All third-party vendors and business associates who handle PHI on our behalf are required to:
- Sign comprehensive Business Associate Agreements (BAAs)
- Implement appropriate safeguards to protect PHI
- Report any security incidents or breaches
- Comply with all applicable HIPAA requirements
- Allow audits and inspections of their security practices
Training and Compliance
All workforce members receive:
- Initial HIPAA training within 30 days of employment
- Annual refresher training and updates on policy changes
- Specialized training based on job responsibilities
- Acknowledgment and certification of policy understanding
Non-compliance with this policy may result in disciplinary action, up to and including termination, and civil or criminal penalties as provided by law.
Audit and Monitoring
We conduct regular audits and monitoring activities including:
- Annual comprehensive risk assessments
- Regular security audits and vulnerability scans
- Access log reviews and anomaly detection
- Compliance monitoring and policy reviews
- Third-party security assessments
Policy Updates
This HIPAA Compliance Policy is reviewed and updated annually or as needed to reflect changes in:
- Federal and state regulations
- Organizational structure or business practices
- Technology and security standards
- Industry best practices
Contact Information
Privacy Officer
For questions about this policy, to exercise your privacy rights, or to file a complaint:
QG Med
Email: info@qgmed.org
Phone: 786-949-4191
Physical Address: 11900 Biscayne Blvd, Miami, FL 33181
Mailing Address: 18117 Biscayne Blvd, Suite 61795, Miami, FL 33160
You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights if you believe your privacy rights have been violated.
By using QG MED's services, you acknowledge that you have read and understood this HIPAA Compliance Policy and agree to its terms. We reserve the right to modify this policy at any time, and changes will be effective immediately upon posting to our website.
