Esthetika HIPAA-Compliant Privacy Policy
Esthetika is committed to protecting your privacy and ensuring the confidentiality, integrity, and security of your Protected Health Information (PHI) in accordance with the Health Insurance Portability and Accountability Act (HIPAA).
What is Protected Health Information (PHI)?
PHI is individually identifiable health information related to your health status, healthcare services you receive, or payment for healthcare services.
Information Collection, Use, and Sharing
We collect PHI provided voluntarily by you through email, direct contact, or secure website forms.
We use your PHI to:
- Provide healthcare-related services
- Communicate and respond to inquiries
- Process payments and fulfill healthcare service requests
- Comply with legal obligations
Permitted Uses and Disclosures without Your Authorization
We may disclose your PHI without explicit authorization for the following purposes:
- Treatment, healthcare operations, and payment processing
- Public health activities (preventing disease, reporting product recalls, adverse reactions, abuse, neglect, or domestic violence, and preventing threats to health and safety)
- Research projects authorized under law
- Legal compliance and oversight (including audits by the Department of Health and Human Services)
- Organ and tissue donation requests
- To coroners, medical examiners, or funeral directors after death
- Workers’ compensation claims, law enforcement purposes, national security, military, or government functions
- In response to court or administrative orders and subpoenas
Sharing PHI with Third Parties
We will not sell or trade your PHI. Trusted third-party service providers (Business Associates) involved in healthcare operations, billing, or administrative functions must sign a HIPAA-compliant Business Associate Agreement (BAA) to safeguard your PHI.
Your HIPAA Privacy Rights
Under HIPAA, you have the right to:
- Request access and receive copies of your PHI (provided within 30 days)
- Request amendments to your PHI (response provided within 60 days; we may decline your request with a written explanation)
- Request restrictions on PHI use or disclosure (we will comply unless legally required or if it affects your care)
- Obtain an accounting of disclosures made for six years prior (excluding disclosures for treatment, payment, and healthcare operations)
- Request confidential communications
- Obtain a paper copy of this Privacy Notice, even if you previously agreed to receive it electronically
- Authorize someone (legal guardian or medical power of attorney holder) to act on your behalf; we will verify their authority
- File a complaint without fear of retaliation
Fundraising
We may contact you for fundraising efforts; however, you have the right to opt out of such communications.
Security of Your PHI
Esthetika implements strict security measures, including encryption and access controls compliant with HIPAA regulations, to protect your PHI.
Breach Notification
In the event of a breach involving your PHI, we will promptly notify you and inform you about affected information and corrective measures.
Changes to this Privacy Policy
Esthetika reserves the right to modify this policy. Changes will apply to all PHI we maintain, including previously collected PHI. Updates will be posted on our website.
Questions or Complaints
To exercise your rights or file a complaint, contact our privacy officer:
Esthetika
Attn: Steffen Obaid-Schmid
Email: info@esthetika.com
2960 Sunridge Heights Pkwy – Suite 200
Henderson, NV 89052
You may also file a complaint directly with the U.S. Department of Health and Human Services Office for Civil Rights:
200 Independence Avenue, S.W.
Washington, D.C. 20201
Phone: 1-877-696-6775
www.hhs.gov/ocr/privacy/hipaa/complaints/
Thank you for entrusting Esthetika with your healthcare needs and protecting your personal health information.