Privacy Policy & HIPAA Notice

Your privacy and health information security is our top priority

AES-256 Encryption

All PHI encrypted at rest and in transit

Audit Logging

Every access to your data is tracked

Minimal Collection

Only necessary health information collected

Notice of Privacy Practices

Effective Date: 11/12/2025

This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully.

HIPAA Compliance

ChiroFix Acupuncture & Functional Medicine complies with the Health Insurance Portability and Accountability Act (HIPAA) and protects your Protected Health Information (PHI).

  • We maintain physical, electronic, and procedural safeguards
  • All staff receive HIPAA training
  • Business Associate Agreements signed with all vendors handling PHI
  • Regular security audits and risk assessments conducted

How We Use Your Information

Treatment

We use your health information to provide, coordinate, and manage your healthcare and related services.

Payment

We may use and disclose your information to bill and collect payment for treatment and services provided.

Healthcare Operations

We may use your information for quality assessment, staff training, and other healthcare operations.

Your Rights

You have the right to:

  • Request restrictions on uses and disclosures of your PHI
  • Request confidential communications
  • Inspect and copy your health information
  • Request amendments to your health records
  • Receive an accounting of disclosures
  • Request a paper copy of this notice
  • Revoke authorization (except where already acted upon)

Data Security

We implement multiple layers of security to protect your information:

  • Encryption: AES-256-GCM encryption for all PHI
  • Access Controls: Role-based permissions for staff
  • Audit Trails: Complete logging of all PHI access
  • Secure Transmission: TLS 1.3 for all data in transit
  • Regular Backups: Encrypted backups stored securely
  • Vendor Oversight: BAAs with all service providers

Breach Notification

In the unlikely event of a breach of your PHI, we will notify you within 60 days as required by HIPAA. We will also notify the Department of Health and Human Services if required.

Changes to This Notice

We reserve the right to change this notice. Any revised notice will apply to information we already have as well as information received in the future. The current notice will be posted in our office and on our website.

Complaints

If you believe your privacy rights have been violated, you may file a complaint with:

Our Privacy Officer:

ChiroFix Acupuncture & Functional Medicine

9175 Quaday Ave. NE, Otsego, MN 55330

Phone: (612) 888-2353

Email: info@thechirofix.com

Or the Secretary of Health and Human Services:

Office for Civil Rights

U.S. Department of Health and Human Services

You will not be retaliated against for filing a complaint.

Questions About Privacy?

Contact our Privacy Officer for any questions or concerns about how we handle your health information.

Email Privacy Officer