HIPAA Notice of Privacy Practices

Effective Date: June 22, 2026
Last Updated: June 22, 2026

This Notice of Privacy Practices describes how medical information about you may be used and disclosed by MEDHERO and how you can access this information. Please review it carefully.

MEDHERO is committed to protecting the privacy and security of your medical information. We are required by law to maintain the privacy of protected health information, provide you with this Notice of our legal duties and privacy practices, and follow the terms of the Notice currently in effect.

This Notice applies to protected health information created, received, maintained, or transmitted by MEDHERO in connection with the health care services we provide.

Contact Information

For questions about this Notice, your privacy rights, or MEDHERO’s privacy practices, please contact:

MEDHERO Privacy Officer
905 Calle Amanecer, Suite 115
San Clemente, CA 92673
Phone: (949) 207-3603
Email: info@medhero.com

Your Rights

When it comes to your protected health information, you have certain rights. This section explains your rights and some of our responsibilities.

Get an electronic or paper copy of your medical record

You may ask to see or receive an electronic or paper copy of your medical record and other health information we maintain about you.

We will provide a copy or summary of your health information within the timeframe required by law. We may charge a reasonable, cost-based fee when permitted by law.

Ask us to correct your medical record

You may ask us to correct health information about you that you believe is incorrect or incomplete.

We may deny your request in certain circumstances, but we will explain the reason in writing.

Request confidential communications

You may ask us to contact you in a specific way, such as by phone, email, patient portal, or mail, or to send communications to a different address.

We will accommodate reasonable requests when required by law.

Ask us to limit what we use or share

You may ask us not to use or share certain health information for treatment, payment, or health care operations.

We are not always required to agree to your request, but we will consider it carefully. If you pay for a service out of pocket in full and ask us not to share that information with your health plan for payment or health care operations purposes, we will honor that request unless disclosure is required by law.

Get a list of those with whom we have shared information

You may request an accounting of certain disclosures of your protected health information.

This accounting will not include every type of disclosure, such as disclosures made for treatment, payment, health care operations, disclosures made to you, disclosures made with your written authorization, or disclosures made for certain other purposes permitted by law.

Get a copy of this Notice

You may request a paper copy of this Notice at any time, even if you previously agreed to receive it electronically.

Choose someone to act for you

If you have given someone medical power of attorney, if someone is your legal guardian, or if another person is legally authorized to act on your behalf, that person may exercise your rights and make certain choices about your health information.

We may take reasonable steps to verify that the person has authority to act on your behalf before we take action.

Receive notice of a breach

You have the right to be notified if a breach occurs that may have compromised the privacy or security of your protected health information.

File a complaint if you believe your rights are violated

You may file a complaint with MEDHERO if you believe your privacy rights have been violated.

You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.

MEDHERO will not retaliate against you for filing a complaint.

Your Choices

For certain health information, you may tell us your preferences about what we share. If you have a clear preference for how we share your information in the situations described below, please tell us.

You may choose whether we share information:

  • With family, close friends, or others involved in your care
  • With someone helping pay for your care
  • In certain disaster relief situations
  • For certain marketing communications, when written authorization is required
  • For other uses or disclosures that require your written authorization

If you are unable to tell us your preference, for example if you are unconscious or otherwise unable to communicate, we may share information if we believe it is in your best interest. We may also share information when needed to lessen a serious and imminent threat to health or safety.

Our Uses and Disclosures

We typically use or share your health information in the following ways.

Treatment

We may use your health information and share it with other professionals who are treating you.

For example, a MEDHERO provider may review your medical history, lab results, medications, imaging, or other health information to create a care plan or coordinate with another health care provider.

Payment

We may use and share your health information to bill and receive payment from you, your health plan, or another responsible party.

For example, we may share information with a health plan or payment processor to confirm payment, process a claim, or provide documentation related to services provided.

Health Care Operations

We may use and share your health information to operate our practice, improve your care, train staff, manage business operations, and contact you when necessary.

For example, we may use health information to review quality of care, evaluate provider performance, improve services, conduct compliance reviews, support administrative operations, and improve the patient experience.

Additional Ways We May Use or Share Information

We are allowed or required to share your information in other ways, usually in ways that contribute to public health, safety, legal compliance, or health care oversight.

Public health and safety

We may share health information for certain situations, such as:

  • Preventing disease
  • Reporting adverse reactions to medications or products
  • Reporting suspected abuse, neglect, or domestic violence when required or permitted by law
  • Preventing or reducing a serious threat to anyone’s health or safety

Compliance with law

We will share information about you when required to do so by federal, state, or local law.

Health oversight activities

We may share health information with health oversight agencies for activities authorized by law, such as audits, investigations, inspections, licensing, and disciplinary actions.

Legal proceedings

We may share health information in response to a court or administrative order, subpoena, discovery request, or other lawful process, when legally permitted or required.

Law enforcement

We may share health information for certain law enforcement purposes when permitted or required by law.

Coroners, medical examiners, and funeral directors

We may share health information with a coroner, medical examiner, or funeral director when permitted or required by law.

Organ and tissue donation

If applicable, we may share health information with organizations involved in organ, eye, or tissue donation.

Workers’ compensation

We may share health information as authorized by and necessary to comply with workers’ compensation laws.

Research

We may use or share health information for research only when permitted by law and with appropriate privacy protections.

Specialized government functions

We may share health information for certain government functions, such as military, national security, protective services, or correctional institution purposes, when permitted or required by law.

Uses and Disclosures That Require Written Authorization

Certain uses and disclosures of your protected health information require your written authorization unless otherwise permitted or required by law. These may include:

  • Most uses and disclosures of psychotherapy notes, if applicable
  • Uses and disclosures of protected health information for marketing purposes when authorization is required by law
  • The sale of protected health information
  • Other uses and disclosures not described in this Notice

If you authorize us to use or disclose your protected health information, you may revoke that authorization in writing at any time. We will stop using or disclosing your information for that purpose, except to the extent we have already relied on your authorization.

Sensitive Health Information

Certain types of health information may receive additional protection under federal or state law. This may include information related to reproductive health, mental health, substance use disorder treatment, HIV/AIDS, genetic information, and other sensitive medical information.

MEDHERO will comply with applicable federal and state laws that provide additional privacy protections for sensitive health information.

California Medical Privacy Protections

MEDHERO is located in California and will comply with applicable California medical privacy laws, including the Confidentiality of Medical Information Act where applicable.

California law may provide additional protections for medical information and may restrict the disclosure of patient medical information without authorization unless an exception applies.

Marketing, Advertising, and Communications

MEDHERO may contact you with appointment reminders, care-related communications, service updates, administrative messages, and other communications related to your care or relationship with the practice.

We will not use or disclose your protected health information for marketing purposes when written authorization is required by law, unless you have provided that authorization.

General educational content, service information, promotional messages, and practice updates may be sent through email or SMS only where permitted by law and based on your communication preferences and consent.

MEDHERO does not intentionally send protected health information, lab results, diagnosis information, treatment instructions, or urgent medical communications through general marketing platforms, including email or SMS marketing tools.

Website, Online Forms, and Non-Secure Communications

MEDHERO’s website is intended to provide general information about our services and practice.

Please do not submit sensitive medical information, symptoms, diagnoses, lab results, medication details, insurance information, urgent medical concerns, or other confidential medical information through general website forms, marketing forms, email, SMS, or other non-secure channels unless MEDHERO specifically provides a secure method for doing so.

For patient-specific medical questions, please contact MEDHERO through the secure communication method provided by the practice or call the office directly.

If you are experiencing a medical emergency, call 911 or seek emergency medical care immediately.

Online Tracking and Third-Party Marketing Tools

MEDHERO may use website analytics, cookies, pixels, tags, and similar technologies to understand website performance, improve the user experience, measure advertising effectiveness, and provide relevant marketing.

Because MEDHERO is a medical practice, MEDHERO does not intentionally use online tracking technologies to disclose protected health information, medical records, diagnosis information, treatment information, appointment details, lab results, or patient-specific care information to advertising platforms.

MEDHERO does not intentionally use general marketing platforms, advertising platforms, or ecommerce tools to collect, store, or transmit protected health information. Patient-specific medical communications should occur through secure channels approved by MEDHERO.

Our Responsibilities

MEDHERO is required by law to:

  • Maintain the privacy and security of your protected health information
  • Notify you if a breach occurs that may have compromised the privacy or security of your protected health information
  • Follow the duties and privacy practices described in this Notice
  • Provide you with a copy of this Notice
  • Not use or share your information other than as described here unless permitted by law or authorized by you in writing

Changes to This Notice

We may change the terms of this Notice at any time. Changes will apply to the health information we already have about you as well as any information we receive in the future.

The current Notice will be posted on our website and will include the effective date.

Complaints

If you believe your privacy rights have been violated, you may file a complaint with MEDHERO by contacting:

MEDHERO Privacy Officer
905 Calle Amanecer, Suite 115
San Clemente, CA 92673
Phone: (949) 207-3603
Email: info@medhero.com

You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.

MEDHERO will not retaliate against you for filing a complaint.

Contact

For questions about this Notice, MEDHERO’s privacy practices, or your rights, please contact:

MEDHERO Privacy Officer
905 Calle Amanecer, Suite 115
San Clemente, CA 92673
Phone: (949) 207-3603
Email: info@medhero.com