Legal & Compliance
Legal Documents
Effective date: June 6, 2026
This Privacy Policy describes how Ashworth Health, PLLC ("we," "us," or "our") collects, uses, and protects your personal and health information when you use our website and patient portal. We are committed to safeguarding your privacy in accordance with applicable federal and state laws, including the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
1. Information We Collect
We may collect the following categories of information:
- Identifying Information: Name, date of birth, address, phone number, and email address.
- Health Information (PHI): Medical history, diagnoses, treatment records, prescriptions, and appointment notes — all protected under HIPAA.
- Insurance Information: Insurance carrier, policy number, and coverage details.
- Portal Usage Data: Login timestamps, pages visited, and messages sent within the patient portal.
- Technical Data: IP address, browser type, and device information collected automatically when you visit our website.
2. How We Use Your Information
We use your information only for the following purposes:
- Providing, coordinating, and managing your healthcare treatment.
- Processing billing and insurance claims.
- Communicating appointment reminders and care updates.
- Complying with legal and regulatory obligations.
- Improving our services and patient experience.
We will never sell, rent, or trade your personal health information to third parties for marketing purposes.
3. HIPAA Compliance
As a covered healthcare entity, we comply fully with HIPAA and the HITECH Act. Your Protected Health Information (PHI) is accessed only by authorized workforce members on a need-to-know basis. All electronic PHI (ePHI) is encrypted in transit and at rest. We maintain a Business Associate Agreement (BAA) with all third-party vendors who handle PHI, including our electronic health records provider, SimplePractice.
4. Information Sharing
We may share your information in the following limited circumstances:
- Treatment: With other providers involved in your care, with your written consent where required.
- Payment: With insurance companies to process claims.
- Operations: With business associates under a HIPAA-compliant BAA.
- Legal Requirements: When required by law, court order, or public health authorities.
- Emergency: To prevent serious threat to health or safety.
5. Data Security
We implement administrative, physical, and technical safeguards to protect your information, including encrypted data transmission (TLS/SSL), role-based access controls, audit logging, regular security risk assessments, and workforce HIPAA training. Despite these measures, no system is 100% secure. If a breach occurs, we will notify you as required by the HIPAA Breach Notification Rule.
6. Your Rights
Under HIPAA and applicable law, you have the right to:
- Access and obtain a copy of your health records.
- Request corrections to your medical information.
- Request restrictions on certain uses and disclosures.
- Receive an accounting of disclosures.
- Receive communications through alternative means or locations.
- Revoke any prior authorization at any time in writing.
To exercise any of these rights, contact us at lashworth@ashworthhealthpllc.com.
7. Cookies & Tracking
Our website uses essential cookies necessary for secure login and portal functionality. We do not use advertising tracking cookies. You may disable cookies in your browser settings; however, some portal features may not function properly.
8. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact our Privacy Officer:
Ashworth Health, PLLC
Privacy Officer
Email: lashworth@ashworthhealthpllc.com
