Privacy Policy
Last updated: September 21, 2026
The Mindbridge Care is committed to protecting the privacy and security of your personal and health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our home healthcare services. We comply with all applicable federal and state privacy laws, including HIPAA.
HIPAA Compliance
The Health Insurance Portability and Accountability Act (HIPAA) of 1996 is the primary federal law protecting the privacy of your health information. As a home healthcare provider, we are classified as a "covered entity" under HIPAA and must comply with its Privacy and Security Rules.
Your HIPAA Rights Include:
- Right to Access: You may request copies of your medical records and health information.
- Right to Amend: You may request corrections to your health records if you believe they contain errors.
- Right to Accounting: You may request a list of disclosures we have made of your health information.
- Right to Restrict: You may request restrictions on how we use or share your information.
- Right to Confidential Communications: You may request that we communicate with you in a specific way or location.
- Right to Notice: You have the right to receive this notice of our privacy practices.
Protected Health Information (PHI)
Under HIPAA, Protected Health Information includes any information that can identify you and relates to:
- Your past, present, or future physical or mental health
- Healthcare services provided to you
- Payment for healthcare services
- Demographic information (name, address, SSN, etc.)
How We Use Your PHI:
We may use and disclose your PHI without your authorization for the following purposes:
- Treatment: To provide, coordinate, and manage your healthcare and related services.
- Payment: To obtain payment for services, including billing insurance companies.
- Healthcare Operations: For quality assessment, training, licensing, and business planning.
- Required by Law: When required by federal, state, or local law.
- Public Health: To report diseases, injuries, and vital statistics as required by law.
Home Healthcare Privacy Regulations
Home healthcare agencies are subject to additional privacy protections specific to in-home care:
Medicare Conditions of Participation (42 CFR Part 484)
Home health agencies participating in Medicare must maintain the confidentiality of patient records and provide patients with written notice of their privacy rights. Records must be safeguarded against loss, destruction, or unauthorized use.
Patient Self-Determination Act
We must inform you of your rights under state law to make decisions about your medical care, including the right to accept or refuse treatment and to prepare advance directives.
21st Century Cures Act - Information Blocking Rule
Effective April 2021, healthcare providers must not engage in practices that unreasonably limit the access, exchange, or use of electronic health information. You have the right to access your electronic health records without unnecessary barriers.
State Privacy Laws
Many states have additional privacy protections that may be more stringent than HIPAA. We comply with all applicable state laws, including those governing mental health records, substance abuse treatment records, HIV/AIDS information, and genetic information.
Our Security Measures
We implement comprehensive administrative, physical, and technical safeguards to protect your information:
Administrative
- • Staff privacy training
- • Access controls
- • Incident response procedures
- • Business associate agreements
Physical
- • Secure record storage
- • Facility access controls
- • Device security policies
- • Secure document disposal
Technical
- • Data encryption
- • Secure authentication
- • Audit logging
- • Firewall protection
Breach Notification
Under the HIPAA Breach Notification Rule, we are required to notify you if there is a breach of your unsecured protected health information. Notification will be made without unreasonable delay and no later than 60 days following discovery of the breach.
If a breach affects more than 500 residents of a state, we must also notify prominent media outlets and the Secretary of Health and Human Services.
Questions or Complaints
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact our Privacy Officer:
The Mindbridge Care Privacy Officer
8200 Beckett Park Dr, Suite 112
West Chester, OH 45069
Phone: (513) 299-8112
Email: contact@tmbcare.com
You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at www.hhs.gov/ocr or by calling 1-800-368-1019. We will not retaliate against you for filing a complaint.