privacy data use · Privacy Policy
HealthSpark policy finding
“ We sometimes rely on third-party service providers—such as secure cloud-hosting platforms, claims-clearinghouses, electronic-prescription networks, telehealth infrastructure vendors, and analytics partners—to support our treatment, payment, and health-care-operations activities. These companies, known under HIPAA as Business Associates, may receive, create, or maintain your protected health information on our behalf only after signing a Business Associate Agreement (BAA) that contractually requires them to: (a) use or disclose PHI solely as permitted by us or as required by law; (b) implement appropriate administrative, physical, and technical safeguards to protect the information; (c) report any suspected or confirmed privacy or security breach to HealthSpark without unreasonable delay; and (d) ensure that any of their subcontractors who handle PHI are bound by the same protections. We share the minimum necessary information for them to perform their duties, and we monitor their compliance as part of our ongoing privacy-and-security program. We may also use and disclose your health information to: Comply with federal, state or local laws that require disclosure. Assist in public health activities such as tracking diseases or medical devices. Inform authorities to protect victims of abuse or neglect. Comply with federal and state health oversight activities such as fraud investigations. Respond to law enforcement officials or to judicial orders, subpoenas or other processes. ”
- Document
- Privacy Policy
- Captured
- 2026-07-20
- Location
- Privacy Policy › “Business Associates”
- Snapshot SHA-256
- ac3fb8d6d974b1518f2af934f2baf61f668bd5d70ae628b69b5dd0e765427665
Informational only, not legal advice. Terms change; verify the source and capture date.