Privacy Policy | DRT Health Services

Legal

Privacy Policy & HIPAA Notice of Privacy Practices

Effective Date: June 1, 2025 ·  Last Updated: June 1, 2025

Important: This document serves as both our Website Privacy Policy and our HIPAA Notice of Privacy Practices as required by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act. Please read it carefully. If you have questions, contact us at DrtHealthServices@yahoo.com.

1. Who We Are

DRT Health Services LLC ("DRT," "we," "us," or "our") is a mobile healthcare provider operating in Wilmington, Xenia, Waynesville, and surrounding Ohio communities. Services are delivered by Danielle Todd, FNP, a licensed Family Nurse Practitioner.

As a covered entity under HIPAA, we are required by law to maintain the privacy of your Protected Health Information (PHI), to provide you with this Notice of Privacy Practices, and to follow the terms of the notice currently in effect.

Privacy Officer Contact:
Danielle Todd, FNP — DRT Health Services LLC
DrtHealthServices@yahoo.com · 937-478-2281

2. Protected Health Information (PHI)

"Protected Health Information" (PHI) is information about you that identifies you and relates to your past, present, or future physical or mental health condition, the provision of healthcare to you, or payment for that healthcare. PHI may be in paper, electronic (ePHI), or verbal form.

Examples of PHI we may collect and maintain include:

  • Your full name, date of birth, address, phone number, and email address
  • Health history, medical conditions, and known allergies
  • Service records, clinical notes, and treatment information
  • Insurance information and billing records
  • Appointment dates, times, and locations
  • Lab results and specimen collection records
  • Payment information related to services rendered

3. How We Use & Disclose Your PHI

We use and disclose your PHI only as permitted or required by HIPAA. The following describes the ways we may use your PHI without your written authorization:

Treatment

We use your PHI to provide, coordinate, and manage your healthcare and treatment. For example, we may share information with other healthcare providers involved in your care (e.g., your primary care physician or a laboratory) as needed to deliver services.

Payment

We may use and disclose your PHI to obtain payment for services rendered, including submitting claims to your insurance company, verifying coverage, and billing.

Healthcare Operations

We may use your PHI for our internal business operations, including quality assessment, staff training, compliance reviews, and business management activities.

As Required by Law

We will disclose your PHI when required by federal, state, or local law, including to public health authorities for disease reporting, to government agencies for oversight activities, and in response to court orders or lawful subpoenas.

Emergency Situations

We may disclose your PHI in emergency situations to prevent or lessen a serious and imminent threat to your health or safety or the health or safety of another person.

Business Associates

We may share your PHI with third-party vendors or service providers ("Business Associates") that perform services on our behalf, such as electronic health record systems, billing services, or email/communication platforms. All Business Associates are required to sign a Business Associate Agreement (BAA) and are bound by the same HIPAA privacy requirements we follow.

Uses Requiring Your Written Authorization

All other uses and disclosures of your PHI not described above — including most marketing communications, sale of PHI, and use of psychotherapy notes — require your separate written authorization. You may revoke any authorization you have given us at any time, in writing.

4. Your HIPAA Rights

You have the following rights regarding your Protected Health Information. To exercise any of these rights, submit a written request to our Privacy Officer using the contact information in Section 1.

Right to Access & Inspect Your PHI

You have the right to inspect and obtain a copy of your medical records and other PHI used to make decisions about your care. We will respond within 30 days of your request. A reasonable fee may be charged for copies.

Right to Request an Amendment

If you believe your PHI is inaccurate or incomplete, you may request that we amend it. We may deny your request under certain circumstances, in which case we will explain our reason in writing.

Right to an Accounting of Disclosures

You may request a list of disclosures of your PHI that we have made other than for treatment, payment, or healthcare operations purposes, or disclosures you authorized. The list covers disclosures made in the six years prior to your request.

Right to Request Restrictions

You may request that we restrict how we use or disclose your PHI for treatment, payment, or healthcare operations. We are not required to agree to every restriction, but we will honor restrictions that you have paid for out-of-pocket in full.

Right to Request Confidential Communications

You may request that we communicate with you in a specific way or at a specific location — for example, by email only or at a specific address. We will accommodate reasonable requests.

Right to a Paper Copy of This Notice

You may request a paper copy of this Notice at any time, even if you agreed to receive it electronically.

Right to Be Notified of a Breach

In the event of a breach of unsecured PHI affecting you, we will notify you without unreasonable delay and no later than 60 days after discovery of the breach, as required by HITECH and the HIPAA Breach Notification Rule.

5. Website & Online Booking Data

Information You Submit

When you use our online booking form or contact form, you voluntarily provide personal information such as your name, email address, phone number, and requested service. This information is used to schedule and confirm your appointment and to communicate with you about your care.

Booking Confirmation Emails

When you submit a booking request, you will receive email communications from us regarding the status of your appointment (confirmation or cancellation). These emails are sent to the address you provide. You may contact us to update your communication preferences.

Cookies & Tracking

Our website may use essential cookies to support basic site functionality. We do not use third-party advertising cookies or cross-site tracking technologies. We do not sell your personal information to third parties.

Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites and encourage you to review their privacy policies.

Email Communications

We use Yahoo Mail (a HIPAA-compliant email arrangement) to communicate appointment information. Do not send sensitive medical information by email unless you understand the inherent risks of unencrypted email transmission.

6. Data Security

We implement reasonable administrative, physical, and technical safeguards to protect your PHI and personal information in accordance with HIPAA's Security Rule. These measures include:

  • Limiting access to PHI to authorized personnel only
  • Using encrypted connections (HTTPS/TLS) for all data transmitted through this website
  • Regularly reviewing our security practices and access controls
  • Training staff on privacy and security obligations

No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security. If you suspect a security incident involving your information, please contact us immediately.

7. Minors

Our services are available to patients of all ages; however, our online booking forms and patient portal are intended for use by adults (18 and older) or by a parent or legal guardian acting on behalf of a minor patient. We do not knowingly collect personal information directly from children under 13 without verifiable parental consent as required by COPPA.

If you believe we have inadvertently collected information from a child under 13 without appropriate consent, please contact us and we will take steps to delete that information promptly.

8. Changes to This Notice

We reserve the right to change this Privacy Policy and HIPAA Notice of Privacy Practices at any time. Changes will be effective immediately upon posting to our website. The revised notice will apply to all PHI we maintain, including records created before the effective date of the change. We encourage you to review this page periodically.

We will post a clear notice on our website when material changes are made. If required by law, we will provide additional notification of significant changes.

9. Contact & Complaints

If you have questions about this Notice or wish to exercise your rights, please contact our Privacy Officer:

Danielle Todd, FNP — Privacy Officer

DRT Health Services LLC

Serving Wilmington, Xenia, Waynesville, OH and surrounding communities

DrtHealthServices@yahoo.com

937-478-2281

Right to File a Complaint: If you believe your privacy rights have been violated, you may file a complaint with us directly or with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR):

HHS Office for Civil Rights

200 Independence Avenue, S.W., Washington, D.C. 20201

www.hhs.gov/ocr/complaints

Toll-free: 1-800-368-1019  |  TTY: 1-800-537-7697

We will not retaliate against you for filing a complaint with HHS OCR or with us.

Legal Disclaimer: This document is provided for informational purposes and represents our good-faith effort to comply with applicable privacy laws, including HIPAA and HITECH. It does not constitute legal advice. We recommend consulting a qualified healthcare attorney to ensure full compliance with all applicable federal and state regulations for your specific practice.