HIPAA Notice of Privacy Practices
Version 2026.06.09 · Effective June 9, 2026
This notice describes how Protected Health Information ("PHI") may be used and disclosed by clinicians and Customer facilities using the Epithel platform, and how you can get access to this information. Please review carefully.
1. Roles under HIPAA
The Customer facility (skilled nursing facility, SNF management group, or clinician group) is the Covered Entity and the data controller of the PHI it enters into Epithel. Epithel acts as a Business Associate processing PHI solely under the written Business Associate Agreement (BAA) with the Covered Entity. See the BAA Notice.
2. Permitted uses & disclosures of PHI
- Treatment: Documenting wound assessments, care plans, photographs, and orders.
- Payment: Submitting claims and supporting reimbursement (the facility's claim flow, not Epithel directly).
- Health Care Operations: QA, infection-control surveillance, care coordination, audits, and training (de-identified when possible).
- As required by law: Reporting to public-health authorities for HAI surveillance, court orders, valid subpoenas, or law enforcement requests with appropriate process.
- To business associates: Only sub-processors under written agreements (see Privacy Policy §5).
3. Uses requiring authorization
Marketing, sale of PHI, and most disclosures of psychotherapy notes require the patient's written authorization. Epithel does not engage in marketing using PHI and does not sell PHI.
4. Patient rights
- Right to inspect and copy PHI maintained about you.
- Right to request amendment of PHI you believe is incorrect.
- Right to an accounting of disclosures made outside of treatment, payment, or operations.
- Right to request restrictions on certain uses or disclosures.
- Right to request confidential communications by alternative means or location.
- Right to a paper copy of this Notice on request.
- Right to file a complaint with the facility's Privacy Officer, with Epithel, and with the U.S. Department of Health & Human Services without retaliation.
Patients should direct rights requests to the facility's Privacy Officer first. Epithel will assist the facility in fulfilling those requests within HIPAA timeframes.
5. Safeguards we maintain
- Administrative: documented workforce training, risk analysis, sanction policy, access-management procedures.
- Physical: sub-processors operate from SOC-2 audited data centers; no on-premise device requirements.
- Technical: TLS 1.2+ in transit, AES-256 at rest, unique user IDs, automatic 15-minute logoff, audit logging of PHI access, role- and facility-scoped access control, encrypted backups.
6. Breach notification
If Epithel discovers a breach of unsecured PHI, we will notify the affected Covered Entity without unreasonable delay and within 60 days of discovery, with the information required by 45 CFR §164.410. The Covered Entity is responsible for notifying affected individuals, HHS, and (when applicable) media as required by 45 CFR §§164.404-408 and applicable state breach-notification statutes.
7. State-specific protections
Where state law provides stricter privacy protection than HIPAA (e.g., California CMIA, Texas Medical Records Privacy Act, New York SHIELD Act), the stricter standard applies. Customers must identify applicable state requirements and configure use of the service accordingly.
8. Reporting a privacy concern
Use the in-app Report a Privacy Concern form, email privacy@epithelcare.life, or contact your facility's Privacy Officer. You may also file a complaint with the HHS Office for Civil Rights at hhs.gov/ocr. Retaliation is prohibited.
9. Changes to this notice
We reserve the right to change this Notice. Material changes will be posted at this URL and communicated in-app at least 30 days before they take effect.
10. Contact
Epithel HIPAA Privacy Officer: privacy@epithelcare.life