HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA)

To meet expectations in today’s health care environment where data privacy is vital, we at Evaluations Plus, Inc. (EPI) stand committed to comply with HIPAA and stress the common sense protection of confidential health information as an important and enforceable corporate principle.

As our clients "third party business associate" EPI recognizes that corporations are seeking to ensure that our organization is actively assessing and preparing for compliance with the Health Insurance Portability and Accountability Act (HIPAA).

CONFIDENTIALITY STATEMENT

CONFIDENTIALITY REQUIREMENTS — PROTECTING THE PRIVACY OF PATIENTS’ HEALTH INFORMATION.

  1. INFORMATION REQUIRED TO BE PROTECTED.
  2. The privacy of all medical records and other individually identifiable health information must be protected at all times. Information relating to a patient’s health care history, diagnosis, condition, treatment or evaluation shall be considered individually identifiable health information. Confidentiality of this health information must be maintained at all times and may only be disclosed with the express written consent of the patient.

  3. BOUNDARIES ON HEALTH INFORMATION USE AND RELEASE
  4. An individual’s health information can be used for health purposes only.

    1. Evaluations Plus, Inc. (EPI) shall not publish or otherwise make generally available any information or data that identifies a patient for purposes other than treatment, payment or other health care operations, without his or her express written consent. This does not restrict the internal use of such information or data that is required in the performance of the scope of work that EPI has been engaged to perform for a client. EPI also maintains physical, electronic and procedural safeguards to protect individually identifiable health information.

    2. Patient information can be used or disclosed only for the purposes of health care treatment, payment, and operations. Health information cannot be used for purposes not related to health care without explicit authorization from the patient.

    3. All individually identifiable health information shall be maintained by EPI in a confidential manner, which prevents unauthorized or inadvertent disclosure to third parties.

EPI would be happy to provide a copy of its "Notice of Privacy Policy".