It explains Sinta's practices when we handle protected health information for healthcare providers. Your treating provider or clinical entity may give you a separate Notice of Privacy Practices that governs its medical records.
Sinta Health, LLC ("Sinta") provides technology and administrative services. Sinta is not a healthcare provider and does not itself provide medical care. Independent licensed providers made available through OpenLoop and/or its affiliated professional entities are responsible for clinical services and their provider-patient relationships.
1. Sinta's HIPAA role
When Sinta creates, receives, maintains, or transmits protected health information ("PHI") on behalf of a HIPAA-covered healthcare provider or health plan, Sinta acts as a Business Associate. In that role, we must safeguard PHI, use and disclose it only as permitted by our Business Associate Agreements and applicable law, and report certain improper uses, disclosures, or breaches to the covered entity.
The treating provider or professional entity remains responsible for its medical record and for providing the official Notice of Privacy Practices required of a covered entity. Sinta may assist that entity with operational and privacy functions.
2. How health information may be used and disclosed
Treatment
We may use or disclose PHI on behalf of a provider to support intake, scheduling, telehealth visits, care coordination, laboratory orders and results, prescriptions, pharmacy fulfillment, follow-up, and communications among authorized participants.
Payment
We may use or disclose PHI to process and document cash-pay services, confirm payment status, address billing questions, and support refunds or transaction review. Sinta programs are cash-pay and Sinta does not bill insurance.
Healthcare operations
We may support quality assessment, provider and vendor administration, auditing, compliance, platform security, customer support, training, and other healthcare operations permitted under HIPAA and applicable agreements.
Other permitted or required purposes
As directed by a covered entity or as allowed by law, PHI may be used or disclosed for public health activities, health oversight, judicial or administrative proceedings, law enforcement, workers' compensation, prevention of a serious threat to health or safety, and other purposes permitted or required by law. Only the minimum necessary information will be used or disclosed when that rule applies.
3. When your authorization is required
Uses or disclosures of PHI not otherwise permitted by law or an applicable provider notice generally require your written authorization. This includes most uses of psychotherapy notes, most marketing uses involving PHI, and a sale of PHI. You may revoke an authorization in writing, except to the extent action has already been taken in reliance on it.
Sinta does not sell PHI and does not use PHI for third-party advertising.
4. Your health-information rights
Subject to HIPAA's conditions and exceptions, you may have the right to:
- Inspect or obtain a copy of PHI in the designated record set;
- Ask that inaccurate or incomplete PHI be amended;
- Receive an accounting of certain disclosures;
- Request reasonable restrictions on uses or disclosures;
- Request confidential communications by a particular method or at a particular location;
- Receive a paper copy of the provider's Notice of Privacy Practices; and
- Choose someone with legal authority to act on your behalf.
Because your treating provider or clinical entity maintains the official medical record, requests should ordinarily be submitted to that entity using the contact information in its notice. Sinta can help route a request received at help@sintahealthapp.com.
5. Safeguards and breach notification
Sinta uses administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of PHI. Access is limited based on role and need, and vendors that handle PHI are required to accept appropriate privacy and security obligations.
If unsecured PHI is affected by a breach, Sinta will notify the applicable covered entity without unreasonable delay and support legally required investigation and notification. The covered entity is generally responsible for notifying affected individuals unless the parties' agreement or law assigns that responsibility differently.
6. Questions and complaints
You may raise a privacy concern with your treating provider or contact Sinta at help@sintahealthapp.com. You may also submit a complaint to the U.S. Department of Health and Human Services Office for Civil Rights. You will not be retaliated against for filing a complaint.
7. Changes to this notice
We may revise this notice when our services, contractual responsibilities, or legal requirements change. A revised version will be posted here with its new effective date. Any covered entity's own Notice of Privacy Practices remains controlling for that entity's medical records and privacy practices.
Contact us
Questions about this document?
Sinta Health, LLC
926 Banyan Dr
Delray Beach, FL 33483