HIPAA Privacy Policy & Notice of Privacy Practices

Effective Date: September 7, 2026
Website: ExpedientMed.com
Entity Name: Expedient MD LLC

This Privacy Policy describes how Expedient MD LLC (“ExpedientMed,” “we,” “us,” or “our”) collects, uses, protects, and discloses Protected Health Information (PHI) and personal data collected through ExpedientMed.com.

1. Understanding Protected Health Information (PHI)

Protected Health Information (PHI) includes individually identifiable health information that relates to your past, present, or future physical or mental health condition, the provision of healthcare to you, or the payment for healthcare services. Under HIPAA, we are required by law to maintain the privacy and security of your PHI.

2. How We Collect Your PHI

We collect PHI when you interact with ExpedientMed.com, including when you:

  • Register for an account or patient portal.
  • Request telehealth services, consultations, or appointments.
  • Fill out medical intake forms, questionnaires, or communication requests.
  • Submit payment or insurance information for medical services.

3. How We Use and Disclose PHI

We may use and disclose your PHI without explicit written authorization for the following primary purposes:

  • Treatment: To provide, coordinate, or manage your healthcare services across providers.
  • Payment: To bill and collect payment from you, insurance plans, or third parties.
  • Healthcare Operations: To support business activities, quality assessment, staff reviews, and service improvement.

Uses Requiring Your Written Authorization

For any purpose outside Treatment, Payment, or Healthcare Operations—such as marketing, sale of PHI, or highly sensitive medical records—we will obtain your explicit written authorization before disclosure. You may revoke this authorization at any time in writing.

4. Technical Safeguards and Data Security

We implement administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI collected on ExpedientMed.com:

  • Encryption: End-to-end SSL/TLS encryption for all data transmitted across the website.
  • Secure Storage: PHI stored on encrypted, HIPAA-compliant cloud server infrastructure.
  • Access Controls: Strict multi-factor authentication (MFA) and role-based access restricted strictly to authorized healthcare personnel.

5. Your Rights Regarding Your PHI

Under HIPAA, you have the following rights regarding health information we maintain about you:

  • Right to Inspect and Copy: You have the right to request and receive electronic copies of your health records.
  • Right to Amend: If you feel the PHI we have is incorrect or incomplete, you may request an amendment.
  • Right to Request Restrictions: You can ask us not to use or share certain PHI for treatment, payment, or operations.
  • Right to Confidential Communications: You can request that we contact you in a specific way (e.g., home phone or mail).

6. Third-Party Vendors & Business Associates

We may share PHI with third-party service providers (such as hosting partners, telehealth technology platforms, or billing vendors) who perform functions on our behalf. All such vendors are legally bound by Business Associate Agreements (BAAs) to enforce HIPAA-compliant standards.

7. Non-PHI & Website Analytics

For non-identifiable web traffic (such as standard cookies, IP addresses, or browser types), we collect usage statistics to optimize ExpedientMed.com. We do not link automated tracking data to individual PHI without explicit consent.

8. Changes to This Policy

We reserve the right to modify this policy at any time. Any changes will apply to all PHI we maintain. Updated versions will be posted directly on ExpedientMed.com with a revised “Effective Date.”

9. Questions and Complaints

If you believe your privacy rights have been violated, or if you have questions regarding this policy, please contact our Privacy Officer:

You may also file a formal complaint with the U.S. Department of Health and Human Services Office for Civil Rights.