Privacy Policy
Privacy Policy – BreezeMed Urgent Care
This Privacy Policy describes how BreezeMed Urgent Care (Health Wellness Medical Astoria PLLC) collects, uses, and safeguards Personal Information from patients and visitors to our website and services, including telehealth. This Policy is designed to comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), applicable New York State laws, and other privacy and consumer protection requirements.
1. Who We Are
BreezeMed Urgent Care is a medical practice owned and operated by Health Wellness Medical Astoria PLLC. Administrative and management support services are provided by Shifa Care Group LLC (MSO). The MSO does not practice medicine and does not direct clinical decision‑making.
2. Information We Collect
We may collect the following categories of information:
- Protected Health Information (PHI): clinical data, diagnoses, treatments, lab results, prescriptions, and other data needed for care.
- Identification and contact details: name, date of birth, address, email, phone.
- Insurance and billing data: plan details, eligibility, claims, and payment information.
- Technical data (website): IP address, device and browser type, pages visited, cookies/analytics.
- Telehealth data: audio/video session metadata, chat messages, and uploaded files for clinical use.
3. How We Use Information
- Treatment, payment, and healthcare operations (TPO) under HIPAA.
- Scheduling, care coordination, and patient communications (e.g., appointment reminders).
- Insurance eligibility, claims processing, and billing.
- Quality improvement, auditing, compliance, and legal/regulatory reporting.
- Website security, analytics, and service enhancement (non‑identifiable data when possible).
4. Disclosures of Information
We may disclose information as permitted or required by law, including to:
- Treating providers and pharmacies; laboratories and radiology centers (e.g., CLIA‑waived testing partners).
- Health plans/insurers and billing vendors for claims processing.
- Business Associates under HIPAA (with BAAs in place).
- Public health authorities, law enforcement, courts, and regulators where legally required.
- In limited situations, family or caregivers involved in your care (as permitted by HIPAA).
5. Your Rights (HIPAA & NYS)
- Right to access and obtain a copy of your medical records.
- Right to request corrections (amendments).
- Right to request restrictions and confidential communications.
- Right to receive an accounting of disclosures (as applicable).
- Right to a paper copy of this Notice and our Notice of Privacy Practices (NPP).
6. Telehealth Privacy
Telehealth visits use secure, encrypted platforms. Do not record sessions unless explicitly authorized. We recommend you participate from a private location and a secure network. Telehealth is subject to the same HIPAA protections as in‑person care.
7. Website & Cookies
We use standard cookies/analytics to improve website performance. You can adjust browser settings to limit cookies. We do not sell Personal Information.
8. Data Security
We implement administrative, technical, and physical safeguards designed to protect PHI and Personal Information. No method of transmission or storage is 100% secure; we continuously improve our security controls.
9. Children’s Privacy
We do not knowingly collect information online from children under 13 without appropriate parental/guardian consent, consistent with applicable law.
Last Updated: 30/10/2025
