Notice of Privacy Practices

Orders.Clinic Patient Privacy

Notice of Privacy Practices

Effective date: July 1, 2026

This Notice explains how your protected health information may be used and disclosed, the rights you have concerning that information, and the responsibilities of the healthcare organizations covered by this Notice.

1. Important information about this Notice

This Notice of Privacy Practices, referred to as the “Notice,” describes how protected health information about you may be used and disclosed and how you may access and exercise rights concerning that information.

This Notice applies only to the healthcare organization, healthcare provider, professional practice, covered healthcare component, or organized healthcare arrangement specifically identified as being covered by this Notice.

Orders.Clinic is a technology and administrative platform operated by Clinic Protocols LLC. Healthcare services made available through the platform may be provided by independently owned medical practices and independently licensed healthcare practitioners.

Depending on the structure of a particular service:

  • Clinic Protocols LLC may provide technology or administrative services as a business associate to a healthcare provider.
  • A participating medical practice may be the HIPAA-covered entity responsible for your healthcare records.
  • Clinic Protocols LLC or an affiliated healthcare component may act as a covered entity for certain services.
  • Multiple participating healthcare organizations may agree to follow a joint notice where permitted by law.

Your treating practitioner or medical practice may provide a separate Notice of Privacy Practices. That separate notice governs the privacy practices of the practitioner or practice identified in it.

This Notice is not a contract, treatment authorization, marketing authorization, or general authorization to disclose your information.

2. Who follows this Notice

This Notice is followed by the healthcare organization identified in your patient account, intake materials, consent documents, appointment information, billing records, or other service documentation as the entity covered by this Notice.

Where applicable, the following persons and organizations may also follow this Notice while performing activities for the covered healthcare organization:

  • Licensed physicians, nurse practitioners, physician assistants, pharmacists, nurses, therapists, and other healthcare professionals.
  • Clinical, administrative, operational, and support personnel.
  • Authorized contractors and business associates.
  • Participating locations or healthcare components listed as part of an affiliated covered entity.
  • Participants in an organized healthcare arrangement where one has been formally established.

Independent pharmacies, laboratories, medical practices, specialists, hospitals, manufacturers, suppliers, and other healthcare organizations may maintain separate privacy practices and may provide their own notices.

3. Protected health information

Protected health information, often called “PHI,” generally means individually identifiable information about:

  • Your past, present, or future physical or mental health or condition.
  • Healthcare provided to you.
  • Payment for healthcare provided to you.

PHI may exist in electronic, paper, photographic, video, audio, oral, or other forms.

Examples may include:

  • Your name, date of birth, address, telephone number, and email address.
  • Medical history and reported symptoms.
  • Diagnoses and treatment plans.
  • Medication, prescription, and allergy information.
  • Laboratory orders and results.
  • Photographs, videos, or measurements submitted for clinical review.
  • Telehealth consultation information.
  • Practitioner notes and clinical communications.
  • Insurance, billing, payment, and transaction information.
  • Medical-device or remote-monitoring information.
  • Information concerning products prescribed, ordered, dispensed, or recommended for you.

Not all information collected through Orders.Clinic is necessarily PHI under HIPAA. Information that is not PHI may be governed by the Orders.Clinic Privacy Policy and other applicable privacy laws.

4. Summary of your rights

Subject to applicable law, you may have the right to:

  • Inspect and obtain a copy of your health information.
  • Request that inaccurate or incomplete information be amended.
  • Request confidential communications.
  • Request restrictions on certain uses and disclosures.
  • Receive an accounting of certain disclosures.
  • Receive a paper or electronic copy of this Notice.
  • Designate a personal representative to act for you.
  • Receive notice following certain breaches of unsecured PHI.
  • File a complaint without retaliation.

These rights and the procedures for exercising them are explained in greater detail below.

5. Right to inspect and obtain a copy

You may ask to inspect or receive an electronic or paper copy of PHI maintained about you in a designated record set.

A designated record set generally includes medical and billing records used to make decisions about you.

To submit a request, contact the Privacy Office or use an approved patient-record request process.

We may require:

  • A written or electronic request.
  • Verification of your identity.
  • Verification of the authority of a personal representative.
  • Identification of the records, format, and delivery method requested.

We will generally provide access within the period required by applicable law. HIPAA commonly requires action within 30 calendar days after receiving a request, subject to any permitted extension or exception.

When readily producible, records will be provided in the form and format you request. If the requested format is not readily producible, we will work with you to identify an alternative format.

A reasonable, cost-based fee may be charged when permitted by law. You will be informed in advance when a fee may apply.

In limited circumstances, access may be denied in whole or in part. Some denials may be reviewed by another licensed healthcare professional who was not involved in the original decision.

6. Right to request an amendment

You may ask us to amend PHI that you believe is incorrect or incomplete.

Your request should identify the information you want amended and explain why you believe the information is incorrect or incomplete.

We may deny a request when, for example:

  • We did not create the information and the person or organization that created it remains available to act on the request.
  • The information is not part of the designated record set.
  • The information is not available for inspection under applicable law.
  • We determine that the information is accurate and complete.

If a request is denied, you may submit a written statement of disagreement where permitted. We may prepare a response to that statement, and the relevant documentation may be included with future disclosures of the disputed information.

A request to amend a record does not permit deletion or alteration of an accurate historical entry merely because a later opinion, diagnosis, treatment plan, or circumstance differs.

7. Right to request confidential communications

You may ask us to communicate with you about health matters using a particular method or at an alternative location.

For example, you may request that we:

  • Use a particular telephone number.
  • Send correspondence to an alternative address.
  • Avoid leaving detailed voicemail messages.
  • Use an approved secure patient portal when available.

We will accommodate reasonable requests as required by law. Your request should clearly identify the alternative communication method or location.

We may ask how payment will be handled or require information needed to carry out the request, but a healthcare provider generally will not require you to explain why you are making a reasonable request.

8. Right to request restrictions

You may ask us not to use or disclose certain PHI for treatment, payment, or healthcare operations.

We are generally not required to agree to a requested restriction. If we agree, we will comply with the restriction except when disclosure is needed for emergency treatment or is otherwise permitted or required by law.

If you pay a healthcare provider in full, out of pocket, for a specific healthcare item or service, you may ask the provider not to disclose information about that item or service to your health plan for payment or healthcare operations.

When the request satisfies applicable HIPAA requirements, the provider will agree unless the disclosure is required by law.

This right does not necessarily prevent disclosure to another healthcare provider for treatment or prevent uses or disclosures otherwise required by law.

9. Right to an accounting of disclosures

You may request a list, called an accounting, of certain disclosures of your PHI made during the six years before the date of your request.

An accounting generally does not include every use or disclosure. For example, it may exclude:

  • Uses and disclosures for treatment, payment, or healthcare operations, except where otherwise required.
  • Disclosures made directly to you.
  • Disclosures you specifically authorized.
  • Disclosures to persons involved in your care or payment for your care.
  • Certain disclosures for national security or intelligence purposes.
  • Certain disclosures to correctional institutions or law-enforcement officials.
  • Disclosures made as part of a limited data set.

We will provide one accounting during any 12-month period without charge. A reasonable, cost-based fee may apply to additional accountings requested during the same period. We will notify you before charging the fee so you may modify or withdraw your request.

10. Right to a copy of this Notice

You may request a paper copy of this Notice at any time, even if you previously agreed to receive it electronically.

You may also obtain the current electronic version from the Orders.Clinic website or patient portal when available.

11. Personal representatives

A person legally authorized to act for you may exercise your privacy rights and make choices concerning your PHI.

A personal representative may include:

  • A parent or legal guardian.
  • A person holding a valid healthcare power of attorney.
  • A court-appointed guardian.
  • An executor, administrator, or other authorized representative of a deceased person’s estate.
  • Another person authorized under applicable law.

We may require documentation and identity verification before recognizing a personal representative.

We may decline to treat a person as your personal representative in circumstances permitted by law, including when doing so is reasonably believed to protect you from abuse, neglect, or endangerment.

12. Your choices about certain disclosures

In certain situations, you may tell us whether or how you want your PHI shared.

Subject to applicable law and your instructions, these situations may include:

  • Sharing information with family members, close friends, caregivers, or others involved in your care.
  • Sharing information with persons involved in payment for your care.
  • Sharing information for disaster-relief efforts.
  • Contacting you for fundraising purposes, where applicable.

If you are unable to communicate your preference, we may share information when permitted by law if we determine that doing so is in your best interest.

We may also disclose information when reasonably necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public, consistent with applicable law and professional standards.

13. Treatment

We may use and disclose your PHI to provide, coordinate, or manage your healthcare and related services.

For example, we may share relevant information with:

  • A practitioner evaluating or treating you.
  • Another healthcare professional consulted about your care.
  • A pharmacy processing a prescription.
  • A laboratory performing ordered testing.
  • A specialist to whom you are referred.
  • Another healthcare organization involved in continuity of care.
  • Authorized care-coordination personnel.

Example: A practitioner reviewing your laboratory results may share relevant information with another practitioner who is helping evaluate your treatment plan.

14. Payment

We may use and disclose PHI to bill for, collect payment for, or determine responsibility for healthcare products and services.

Payment activities may include:

  • Confirming eligibility or benefits.
  • Obtaining payment authorization.
  • Submitting or processing claims.
  • Coordinating benefits.
  • Conducting medical-necessity or utilization review.
  • Collecting patient-responsibility amounts.
  • Resolving billing disputes.
  • Providing documentation to payment processors or financial institutions as legally permitted.

Example: We may provide information concerning a healthcare service to a health plan to request payment or confirm coverage.

15. Healthcare operations

We may use and disclose PHI for activities necessary to operate and improve the healthcare organization.

Healthcare operations may include:

  • Quality assessment and improvement.
  • Patient-safety activities.
  • Review of practitioner performance or qualifications.
  • Credentialing and professional verification.
  • Training and education.
  • Licensing, accreditation, certification, and compliance activities.
  • Legal, accounting, auditing, and risk-management activities.
  • Fraud, waste, and abuse prevention.
  • Customer service and complaint resolution.
  • Technology administration and security.
  • Business planning, development, and management.
  • Population-based activities related to improving health or reducing healthcare costs.

Example: We may review patient records to evaluate the quality of care, improve clinical workflows, or train authorized personnel.

16. Business associates and service providers

We may disclose PHI to contractors and service providers that perform functions involving PHI on behalf of the covered healthcare organization.

These parties may include providers of:

  • Electronic health record and patient-portal systems.
  • Telehealth technology.
  • Secure messaging and communications.
  • Cloud hosting and data storage.
  • Billing and payment administration.
  • Pharmacy, laboratory, and fulfillment coordination.
  • Analytics, quality improvement, and reporting.
  • Legal, accounting, auditing, and compliance services.
  • Customer and technical support.
  • Cybersecurity, fraud prevention, and identity verification.

Business associates are required by contract and law, as applicable, to appropriately safeguard PHI and use it only for authorized purposes.

17. Telehealth and electronic healthcare services

We may use and disclose PHI to provide or support telehealth services.

This may include:

  • Scheduling and conducting video or audio consultations.
  • Reviewing asynchronous questionnaires, photographs, videos, and records.
  • Communicating with practitioners and clinical personnel.
  • Coordinating laboratory, pharmacy, and follow-up services.
  • Sending appointment, treatment, testing, or medication-related communications.
  • Maintaining documentation of telehealth encounters.
  • Providing technical and account support.

We use reasonable safeguards for telehealth communications. You are encouraged to participate from a private location, protect your account credentials, and use a secure device and internet connection.

18. Appointment, treatment, and health-related communications

We may contact you using information you provide for purposes related to your care or healthcare operations.

Communications may include:

  • Appointment confirmations and reminders.
  • Requests to complete forms or provide information.
  • Treatment and follow-up instructions.
  • Laboratory-order and result notifications.
  • Prescription and pharmacy communications.
  • Refill, adherence, and monitoring reminders.
  • Information about treatment alternatives.
  • Information about health-related services that may be relevant to your care.
  • Billing, payment, and insurance communications.
  • Account, privacy, security, and consent notices.

Communications may be delivered through secure portal messages, email, telephone, text message, mail, application notifications, or another method you authorize or provide.

Ordinary email and text messaging may involve privacy risks. You may request information about available confidential communication options.

19. People involved in your care or payment

Unless you object, we may share PHI relevant to a person’s involvement in your care or payment for your care.

The recipient may be:

  • A family member.
  • A close personal friend.
  • A caregiver.
  • A person you identify as involved in your care.
  • A person responsible for payment for your care.

We will generally limit the disclosure to information directly relevant to that person’s involvement.

If you are unavailable, incapacitated, or facing an emergency, we may use professional judgment to determine whether a limited disclosure is in your best interest.

20. Public-health and safety activities

We may use or disclose PHI for public-health and safety activities permitted or required by law.

These activities may include:

  • Preventing or controlling disease, injury, or disability.
  • Reporting births or deaths.
  • Reporting suspected child abuse or neglect.
  • Reporting adverse events, product defects, or biological-product deviations.
  • Supporting product recalls, repairs, or replacements.
  • Notifying a person who may have been exposed to a communicable disease.
  • Notifying an employer concerning work-related illness or injury when legally permitted.
  • Preventing or reducing a serious threat to health or safety.

21. Abuse, neglect, and domestic violence

We may disclose PHI to an appropriate government authority when authorized or required to report suspected abuse, neglect, or domestic violence.

When applicable, we will inform you of the disclosure unless doing so would place you at risk or another legal exception applies.

22. Health-oversight activities

We may disclose PHI to a health-oversight agency for activities authorized by law.

Examples include:

  • Audits and investigations.
  • Inspections.
  • Licensing and disciplinary proceedings.
  • Accreditation and certification reviews.
  • Civil, administrative, or criminal proceedings.
  • Oversight of healthcare systems and government benefit programs.

23. Uses and disclosures required by law

We may use or disclose PHI when federal, state, or local law requires or permits the use or disclosure.

We will limit the use or disclosure to the applicable legal requirements.

We may also disclose information to the U.S. Department of Health and Human Services when it requests information to determine our compliance with federal health-privacy requirements.

25. Law-enforcement purposes

We may disclose PHI to law-enforcement officials when permitted or required by law.

Examples may include disclosures:

  • Required by a court order, warrant, subpoena, summons, or similar legal process.
  • Needed to identify or locate a suspect, fugitive, missing person, or material witness.
  • Concerning a suspected victim of a crime.
  • Concerning a death suspected to have resulted from criminal conduct.
  • Concerning criminal conduct occurring on applicable premises.
  • Needed to report a crime in an emergency.

Additional restrictions may apply to reproductive-health information, psychotherapy notes, substance-use-disorder records, genetic information, and other specially protected information.

26. Coroners, medical examiners, and funeral directors

We may disclose PHI to coroners, medical examiners, and funeral directors as permitted by law so they may carry out their duties.

27. Organ and tissue donation

We may disclose PHI to organizations involved in organ, eye, or tissue procurement, banking, transplantation, or donation when permitted by law.

28. Research

We may use or disclose PHI for research when the research satisfies applicable legal requirements.

This may occur when:

  • You provide a valid written authorization.
  • An institutional review board or privacy board approves a waiver or alteration of authorization.
  • The information is used only to prepare for research and does not leave the covered entity as prohibited.
  • The research involves information about deceased individuals and applicable requirements are satisfied.
  • The information has been de-identified.
  • A limited data set is used under an appropriate data-use agreement.

Research treatment may be subject to a separate informed-consent and authorization process.

29. Workers’ compensation

We may disclose PHI as authorized by and to the extent necessary to comply with workers’ compensation laws and similar programs providing benefits for work-related injuries or illnesses.

30. Specialized government functions

We may disclose PHI for certain specialized government functions as permitted by law.

These may include:

  • Military and veterans’ activities.
  • National-security and intelligence activities.
  • Protective services for designated government officials.
  • Medical-suitability or security-clearance determinations.
  • Correctional institutions and lawful custody.

31. Correctional institutions and lawful custody

If you are an inmate or are otherwise in lawful custody, we may disclose PHI to the correctional institution or law-enforcement official when necessary for:

  • Providing healthcare to you.
  • Protecting your health and safety or the health and safety of others.
  • Protecting the safety and security of the institution.
  • Supporting lawful custodial operations.

32. Disaster-relief activities

We may disclose limited PHI to an organization assisting with disaster-relief efforts so that family members or other persons responsible for your care may be notified of your condition, status, or location.

When practicable, we will provide you with an opportunity to agree or object.

33. Deceased individuals

PHI generally remains protected for 50 years after an individual’s death under HIPAA.

We may disclose relevant PHI to a family member or other person who was involved in the deceased individual’s care or payment before death, unless doing so is inconsistent with a preference previously expressed by the individual and known to us.

We may also disclose PHI to a legally authorized personal representative or as otherwise permitted or required by law.

34. Uses and disclosures requiring authorization

Uses and disclosures of PHI that are not otherwise permitted or required by law will generally be made only with your valid written authorization.

A valid authorization generally explains:

  • What information may be used or disclosed.
  • Who may use or disclose it.
  • Who may receive it.
  • The purpose of the use or disclosure.
  • When the authorization expires.
  • Your right to revoke the authorization.

This Notice is not a substitute for an authorization when HIPAA or another law requires a separate authorization.

You may revoke an authorization in writing at any time, except to the extent that action has already been taken in reliance on it or another legal exception applies.

35. Psychotherapy notes

Most uses and disclosures of psychotherapy notes require your written authorization unless a specific legal exception applies.

Psychotherapy notes are treated differently from ordinary mental-health records and generally consist of notes recorded by a mental-health professional documenting or analyzing the contents of private counseling sessions that are maintained separately from the rest of the medical record.

36. Marketing

We will generally obtain your written authorization before using or disclosing PHI for marketing as defined by HIPAA.

An authorization may not be required for certain communications permitted by law, including:

  • Face-to-face communications.
  • Promotional gifts of nominal value.
  • Certain communications concerning treatment, case management, care coordination, or alternative treatments.
  • Certain communications concerning health-related products or services provided by, or included in the benefits of, the covered entity.

Where legally required, a communication will disclose when the covered entity receives financial remuneration from a third party in connection with the communication.

General advertising based on information that is not PHI may instead be governed by the Orders.Clinic Privacy Policy and applicable consumer-privacy and communications laws.

37. Sale of protected health information

We will not sell PHI as defined by HIPAA without your written authorization unless a specific legal exception applies.

When an authorization is required for a disclosure involving remuneration, the authorization will state that remuneration is involved.

38. Fundraising

If the covered healthcare organization conducts fundraising activities, it may use limited information to contact you as permitted by law.

You have the right to opt out of receiving fundraising communications.

Any fundraising communication will provide a clear and convenient method for opting out. Choosing not to receive fundraising communications will not affect your treatment or payment for services.

Orders.Clinic does not currently intend to use PHI for fundraising unless a specific covered healthcare organization informs you otherwise.

39. Substance-use-disorder patient records

Certain records concerning substance-use-disorder diagnosis, treatment, or referral may receive additional protection under 42 U.S.C. § 290dd-2 and 42 C.F.R. Part 2.

To the extent that we maintain records protected by Part 2:

  • We will use and disclose those records only as permitted by applicable law.
  • Your consent may be required for uses and disclosures that would otherwise be permitted under HIPAA.
  • Part 2 records generally may not be used or disclosed in civil, criminal, administrative, or legislative proceedings against you without your specific written consent or an appropriate court order and subpoena.
  • Additional consent, redisclosure, complaint, accounting, and fundraising requirements may apply.

If a participating provider is a federally assisted substance-use-disorder treatment program subject to Part 2, that program may provide a separate or supplemental Part 2 Patient Notice.

This section does not represent that Orders.Clinic or every participating provider operates a Part 2 program.

40. Other specially protected information

Federal or state law may provide additional protection for certain categories of information.

Depending on the circumstances and jurisdiction, these categories may include:

  • Mental-health information.
  • HIV, AIDS, and sexually transmitted infection information.
  • Genetic information.
  • Reproductive and sexual-health information.
  • Substance-use-disorder information.
  • Minor-consented healthcare information.
  • Domestic-violence and sexual-assault information.
  • Psychotherapy notes.
  • Records concerning certain communicable diseases.

When another law is more protective than HIPAA, we will follow the more protective requirement to the extent it applies.

41. Reproductive-health information

We will handle reproductive-health information in accordance with applicable federal and state law.

Where legally required, we may request a signed attestation before disclosing PHI potentially related to reproductive healthcare for:

  • Health-oversight activities.
  • Judicial or administrative proceedings.
  • Law-enforcement purposes.
  • Disclosures to coroners or medical examiners.

We will not knowingly use or disclose PHI for a purpose prohibited by applicable federal privacy requirements.

42. Minimum necessary standard

When the minimum-necessary standard applies, we will make reasonable efforts to limit PHI used, disclosed, or requested to the minimum information reasonably necessary to accomplish the intended purpose.

The minimum-necessary standard does not apply to certain activities, including disclosures to or requests by healthcare providers for treatment and certain disclosures authorized by you or required by law.

43. De-identified and limited data

We may remove identifiers from health information so that it is no longer considered PHI under HIPAA.

De-identified information may be used or disclosed for lawful purposes, including:

  • Analytics and reporting.
  • Quality improvement.
  • Research and statistical analysis.
  • Technology development and testing.
  • Operational planning.
  • Public-health activities.

We may also create and disclose a limited data set under an appropriate data-use agreement when permitted by law.

We will not knowingly attempt to re-identify properly de-identified information except as permitted to test whether the de-identification process satisfies legal requirements.

44. Health-information exchange and care coordination

Where available and legally permitted, we may participate in health-information exchanges, electronic prescribing networks, laboratory networks, pharmacy networks, registries, and other secure information-sharing systems.

These systems may allow authorized healthcare professionals to access relevant information for treatment, payment, healthcare operations, public health, or another permitted purpose.

Your ability to restrict, opt out of, or obtain information about participation may vary based on the system and applicable law.

45. Record retention

We retain health, billing, authorization, consent, disclosure, and privacy records for the periods required by applicable federal and state law and legitimate healthcare, legal, compliance, and operational requirements.

Different records may be subject to different retention periods.

Closing an Orders.Clinic account or ending a practitioner-patient relationship does not require the deletion of records that must or may lawfully be retained.

46. Safeguarding your information

We are required to maintain reasonable and appropriate administrative, technical, and physical safeguards to protect PHI.

Safeguards may include:

  • Access controls and user authentication.
  • Role-based access restrictions.
  • Encryption where appropriate.
  • Audit logging and system monitoring.
  • Workforce privacy and security training.
  • Policies governing permitted access and disclosure.
  • Secure data storage and transmission.
  • Risk assessments and incident-response procedures.
  • Business-associate agreements where required.
  • Facility and device safeguards.

No electronic, physical, or administrative system can guarantee complete security. You should protect your account credentials, use secure devices and networks, and promptly report suspected unauthorized account access.

47. Notification following a breach

We will notify you following a breach of unsecured PHI when notification is required by law.

A breach notice may include:

  • A description of what occurred.
  • The types of information involved.
  • Steps you may take to protect yourself.
  • Actions being taken to investigate, mitigate harm, and prevent recurrence.
  • Contact information for questions.

Not every privacy or security incident constitutes a reportable breach under applicable law.

48. Our responsibilities

When acting as the covered entity responsible for your PHI, we are required to:

  • Maintain the privacy and security of PHI as required by law.
  • Provide you with this Notice describing our legal duties and privacy practices.
  • Follow the terms of the Notice currently in effect.
  • Notify affected individuals following certain breaches of unsecured PHI.
  • Respect and facilitate your privacy rights.
  • Avoid retaliation against a person for filing a privacy complaint or exercising a privacy right.

We will not use or disclose PHI except as described in this Notice, as permitted or required by law, or as authorized by you.

49. Changes to this Notice

We reserve the right to change this Notice and our privacy practices.

A revised Notice may apply to PHI already maintained as well as information received or created after the revision, to the extent permitted by law.

When we make a material change, we will:

  • Revise this Notice.
  • Update the effective date.
  • Make the revised Notice available upon request.
  • Post the revised Notice on the applicable website.
  • Provide or display the revised Notice in another manner required by law.

The current version will be available at:

orders.clinic/notice-of-privacy-practices

50. Privacy complaints

You may file a complaint if you believe your privacy rights have been violated.

You may submit a complaint to the Privacy Office using the contact information below.

You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights.

U.S. Department of Health and Human Services
Office for Civil Rights
200 Independence Avenue, S.W.
Washington, D.C. 20201

Telephone:

1-877-696-6775

Complaint information:

HHS Office for Civil Rights

We will not retaliate against you, deny treatment, or otherwise penalize you for filing a good-faith privacy complaint or exercising a legal privacy right.

51. Privacy Office contact information

Contact the Privacy Office to:

  • Ask a question about this Notice.
  • Request access to records.
  • Request an amendment.
  • Request confidential communications.
  • Request a restriction.
  • Request an accounting of disclosures.
  • Request a paper copy of this Notice.
  • Submit a privacy complaint.
  • Report suspected unauthorized access or disclosure.

Privacy Officer
Clinic Protocols LLC
Doing business as Orders.Clinic
1810 E Sahara Ave
STE 75963
Las Vegas, NV 89104

Privacy email:

privacy@orders.clinic

Support email:

support@orders.clinic

Telephone:

(702) 482-8555

Website:

orders.clinic

Questions about treatment, prescriptions, symptoms, side effects, medical decisions, or clinical records maintained by an independent practice should be directed to the applicable practitioner or medical practice.

52. Acknowledgment of receipt

You may be asked to acknowledge that you received or were given access to this Notice.

Your acknowledgment confirms receipt only.

Signing or electronically acknowledging this Notice:

  • Does not authorize any special use or disclosure of your PHI.
  • Does not waive any privacy right.
  • Does not mean that you agree with every privacy practice described.
  • Does not replace a HIPAA authorization when a separate authorization is required.
  • Does not prevent uses or disclosures otherwise permitted or required by law.

You are not legally required to sign an acknowledgment of receipt. If you decline or are unable to acknowledge receipt, the applicable provider may document its good-faith effort to provide the Notice.

Privacy Preference Center