notice of privacy practices
NOTICE OF PRIVACY PRACTICES
Effective Date: August 26, 2026
Last Updated: August 26, 2026
YOUR INFORMATION. YOUR RIGHTS. OUR RESPONSIBILITIES.
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
This Notice of Privacy Practices (“Notice”) applies to Sigla Health, operated by Mitchell Advanced Practice Nursing & Wellness Inc. (“Sigla Health,” “we,” “us,” or “our”).
We are committed to protecting the privacy and security of your health information.
This Notice explains:
how we may use and disclose your protected health information;
your rights regarding that information;
our responsibilities to protect your information; and
how you may contact us or file a privacy complaint.
1. WHAT INFORMATION IS PROTECTED?
This Notice applies to individually identifiable health information that we create, receive, maintain, or transmit in connection with your healthcare.
This information is commonly referred to as Protected Health Information (“PHI”) and may include information relating to:
your past, present, or future physical or mental health;
healthcare services provided to you;
medications and prescriptions;
laboratory or diagnostic results;
medical history;
allergies;
treatment plans;
photographs used for clinical purposes;
appointment information;
billing and payment information;
insurance information;
communications with your healthcare provider; and
other information that identifies you and relates to your healthcare.
PHI may exist in electronic, paper, photographic, verbal, or other forms.
2. YOUR RIGHTS
You have important rights regarding your health information.
Get an Electronic or Paper Copy of Your Medical Record
You may ask to inspect or receive an electronic or paper copy of your medical record and other health information we maintain about you.
We will generally provide access or a copy within the period required by applicable law.
We may charge a reasonable, cost-based fee where permitted by law.
In limited circumstances permitted by law, we may deny access to certain information. If access is denied, you may have the right to request that the denial be reviewed.
Ask Us to Correct Your Medical Record
If you believe health information we maintain about you is incorrect or incomplete, you may ask us to amend or correct it.
We may deny your request in certain circumstances permitted by law, such as when we believe the information is accurate and complete.
If we deny your request, we will explain the reason in writing and inform you of any additional rights you may have.
Request Confidential Communications
You may ask us to contact you in a specific way or at a specific location.
For example, you may ask us to:
call only a particular telephone number;
communicate through a particular email address;
send mail to a different address; or
avoid leaving detailed voicemail messages.
We will accommodate reasonable requests as required by law.
You are responsible for keeping your contact information current.
Ask Us to Limit What We Use or Share
You may ask us not to use or disclose certain health information for treatment, payment, or healthcare operations.
We are generally not required to agree to every requested restriction.
However, if:
you pay for a healthcare service or item entirely out of pocket; and
you ask us not to disclose information about that service or item to your health plan for payment or healthcare operations purposes,
we will honor the request when required by law, unless disclosure is otherwise required by law.
Get a List of Certain Disclosures
You may request an accounting of disclosures, which is a list of certain instances in which we disclosed your health information.
The accounting generally does not include disclosures made for:
treatment;
payment;
healthcare operations;
disclosures made directly to you;
disclosures you specifically authorized; or
certain other disclosures excluded by law.
You may request an accounting for the period permitted under applicable law.
We will generally provide one accounting within a 12-month period without charge. We may charge a reasonable fee for additional requests during the same period where permitted by law.
Get a Copy of This Notice
You may request a paper copy of this Notice at any time, even if you previously agreed to receive it electronically.
The current Notice will also be available on our Website and at our practice location.
Choose Someone to Act for You
If you have given someone medical power of attorney, if someone is your legal guardian, or if another person is legally authorized to make healthcare decisions for you, that person may exercise your privacy rights on your behalf where permitted by law.
We may require documentation verifying the person's authority before allowing access to your health information.
File a Complaint
If you believe your privacy rights have been violated, you may file a complaint with Sigla Health.
You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights (“OCR”).
We will not retaliate against you for filing a privacy complaint or exercising your privacy rights.
3. YOUR CHOICES
For certain health information, you may tell us your preferences regarding how we use or disclose your information.
Where you have a clear preference, we will follow your instructions when required by law.
Family Members, Friends, and Others Involved in Your Care
Unless you object, we may share information relevant to your care with:
a family member;
a close personal friend;
a caregiver; or
another person involved in your healthcare or payment for your healthcare.
When possible, we will ask for your permission or give you an opportunity to object.
If you are unable to express your preferences—for example, because you are unconscious or experiencing an emergency—we may disclose information when we reasonably believe doing so is in your best interest and is permitted by law.
Disaster Relief
We may disclose limited information to organizations assisting with disaster-relief efforts when permitted by law so family members or others responsible for your care can be notified about your condition or location.
You may tell us not to share this information when circumstances allow.
Marketing
We will not use or disclose your PHI for marketing purposes when HIPAA or other applicable law requires your written authorization unless you provide that authorization.
Communications concerning your treatment, healthcare alternatives, or services that may benefit you may be permitted without a marketing authorization in certain circumstances.
Sale of Health Information
We will not sell your PHI where applicable law requires your written authorization.
Sigla Health does not sell patient medical information to data brokers or advertisers.
Fundraising
If Sigla Health ever conducts fundraising using information permitted under HIPAA, you will have the right to opt out of future fundraising communications.
4. HOW WE MAY USE AND DISCLOSE YOUR INFORMATION
HIPAA permits or requires us to use and disclose PHI in certain circumstances without obtaining a separate written authorization from you.
The following are common examples.
Treatment
We may use or disclose your health information to provide, coordinate, or manage your healthcare.
For example, we may share information with:
another healthcare professional;
a specialist;
a laboratory;
a pharmacy;
an imaging provider;
another treating clinician; or
another healthcare organization involved in your care.
This allows healthcare professionals involved in your care to coordinate treatment safely and appropriately.
Payment
We may use and disclose PHI to bill and obtain payment for healthcare services.
For example, where applicable we may provide information to:
health insurers;
payment processors;
billing companies;
healthcare plans; or
other entities involved in payment.
If Sigla Health does not bill insurance for a particular service, we may still use information necessary to process patient payments, refunds, account balances, or other financial transactions.
Healthcare Operations
We may use and disclose PHI as necessary to operate our healthcare practice.
Examples include:
quality assessment;
quality improvement;
staff training;
credentialing;
compliance activities;
auditing;
patient-safety activities;
business planning;
legal services;
accounting;
technology management;
cybersecurity;
customer service;
internal administrative functions; and
evaluating the quality of care and services.
Appointment Reminders and Patient Communications
We may use your health information to:
remind you about appointments;
confirm or reschedule appointments;
communicate follow-up instructions;
notify you that results are available;
discuss treatment;
provide administrative information; or
communicate regarding your healthcare.
Messages may be delivered by telephone, voicemail, email, secure portal, or text message, depending on your preferences and our communication systems.
Because ordinary email and SMS messaging may have security limitations, patients are encouraged to use designated secure communication systems for sensitive health information whenever available.
Treatment Alternatives and Health-Related Services
We may contact you regarding:
treatment alternatives;
follow-up care;
preventive health services;
wellness services;
other services offered by Sigla Health; or
other health-related options that may be relevant to your care.
Where a communication constitutes marketing under applicable law, we will obtain any authorization required by law.
5. BUSINESS ASSOCIATES
We may disclose PHI to third-party companies or individuals that perform services on our behalf and require access to PHI.
These organizations may include:
electronic health record providers;
patient portal providers;
telehealth platforms;
billing services;
laboratories;
technology companies;
secure data-storage providers;
consultants;
attorneys;
accountants;
cybersecurity providers;
communication vendors; and
other service providers.
When HIPAA requires it, these organizations are considered Business Associates.
We require Business Associates to appropriately safeguard PHI through agreements that comply with applicable HIPAA requirements.
6. PHARMACIES AND PRESCRIPTIONS
When necessary for your treatment, we may disclose health information to pharmacies and pharmacy-related service providers.
Information disclosed may include:
your identifying information;
medication information;
allergies;
diagnosis information when appropriate;
prescription information;
dosage;
prescriber information; and
other information necessary to safely process a prescription.
Pharmacies are responsible for their own privacy practices and legal obligations.
7. LABORATORIES AND DIAGNOSTIC PROVIDERS
We may disclose information to laboratories, imaging centers, diagnostic facilities, pathology providers, and other healthcare organizations when necessary to order, perform, interpret, or coordinate testing.
These entities may independently maintain records relating to services they provide.
8. TELEHEALTH
If you receive care through telehealth, your health information may be created, transmitted, received, or stored electronically.
We may use telehealth technology to:
conduct healthcare visits;
communicate with patients;
document treatment;
exchange health information; and
coordinate care.
We take reasonable steps to use telehealth technologies consistent with applicable privacy and security requirements.
You can also help protect your privacy by participating from a private location and using secure devices and internet connections whenever possible.
9. PUBLIC HEALTH AND SAFETY
We may disclose health information when permitted or required by law for public-health and safety purposes.
Examples may include:
preventing or controlling disease;
reporting certain communicable diseases;
reporting adverse reactions to medications or products;
reporting problems with medical products;
notifying individuals of recalls;
preventing or reducing a serious threat to health or safety;
reporting suspected abuse, neglect, or domestic violence when legally required or permitted; and
complying with public-health reporting requirements.
10. HEALTH OVERSIGHT ACTIVITIES
We may disclose PHI to health-oversight agencies for activities authorized by law.
Examples may include:
audits;
investigations;
inspections;
licensure activities;
regulatory reviews;
disciplinary proceedings; and
governmental oversight of healthcare programs.
11. LEGAL PROCEEDINGS
We may disclose PHI in response to lawful legal processes when permitted or required by law.
These may include:
court orders;
subpoenas;
discovery requests;
administrative orders;
warrants; or
other lawful processes.
We will disclose only the information permitted or required under applicable law.
12. LAW ENFORCEMENT
We may disclose health information to law-enforcement officials in limited circumstances permitted by law.
Examples may include disclosures:
required by law;
in response to certain lawful court orders or warrants;
regarding certain victims of crime;
to locate certain individuals;
concerning suspected criminal activity on our premises; or
in emergencies involving certain criminal conduct.
HIPAA imposes limitations on such disclosures.
13. CORONERS, MEDICAL EXAMINERS, AND FUNERAL DIRECTORS
We may disclose PHI to:
coroners;
medical examiners; and
funeral directors
when permitted or required by law to allow them to perform their duties.
14. ORGAN AND TISSUE DONATION
We may disclose PHI to organizations involved in organ, eye, or tissue procurement, banking, or transplantation when permitted by law.
15. RESEARCH
We may use or disclose health information for research only when applicable legal protections have been satisfied.
This may include:
your written authorization;
approval by an Institutional Review Board or Privacy Board;
use of de-identified information; or
another legally permitted basis.
Sigla Health will not simply provide identifiable patient information to researchers for unrestricted use.
16. WORKERS' COMPENSATION
We may disclose health information as permitted or required by law for workers' compensation programs or similar programs providing benefits for work-related injuries or illness.
17. GOVERNMENT AND SPECIALIZED FUNCTIONS
We may disclose PHI when legally permitted for certain government functions, including:
military and veterans' activities;
national security;
intelligence activities;
protective services;
correctional institutions; or
other specialized government functions.
Only information permitted by applicable law will be disclosed.
18. REQUIRED BY LAW
We will disclose PHI when federal, state, or local law requires us to do so.
When a law imposes stricter privacy protections than HIPAA, we will comply with the stricter applicable requirement.
19. CALIFORNIA MEDICAL PRIVACY PROTECTIONS
Sigla Health operates in California and recognizes that California law may provide additional privacy protections beyond HIPAA.
These laws may include the California Confidentiality of Medical Information Act (“CMIA”) and other California statutes governing medical, mental-health, reproductive-health, HIV-related, genetic, substance-use, and other sensitive information.
Where California law provides greater privacy protection than HIPAA, we will follow the more protective applicable law.
Certain types of records may require specific patient authorization before disclosure except when another law permits or requires disclosure.
20. REPRODUCTIVE HEALTHCARE INFORMATION
Federal law places additional limits on certain uses and disclosures of PHI potentially related to lawful reproductive healthcare.
Where required by applicable law, we will not use or disclose PHI for purposes of:
investigating;
imposing liability upon; or
identifying a person
for seeking, obtaining, providing, or facilitating lawful reproductive healthcare.
Where legally required, we may obtain an attestation from a person requesting potentially related information before making certain disclosures.
21. SUBSTANCE USE DISORDER INFORMATION
Federal law provides heightened confidentiality protections for certain records relating to substance use disorder treatment.
As of February 16, 2026, HIPAA Notices of Privacy Practices must address certain protections applicable to records governed by 42 U.S.C. § 290dd-2 and 42 C.F.R. Part 2.
If Sigla Health receives or maintains records that are protected by Part 2, we will use and disclose those records only as permitted by applicable law.
Part 2 records generally receive heightened protection from use or disclosure in civil, criminal, administrative, or legislative proceedings against a patient without the patient's written consent or a court order that satisfies applicable legal requirements.
Sigla Health does not represent through this Notice that it operates a federally assisted substance-use-disorder treatment program subject to Part 2. This section is intended to describe protections that may apply if we receive or maintain records governed by Part 2.
22. MENTAL HEALTH INFORMATION
Certain mental-health information may receive additional protection under federal or California law.
Where additional authorization or consent is legally required before disclosure, we will obtain it unless another law permits or requires disclosure.
23. PSYCHOTHERAPY NOTES
Psychotherapy notes receive additional protection under HIPAA.
Except in limited circumstances permitted by law, we generally must obtain your written authorization before using or disclosing psychotherapy notes.
Sigla Health may not create psychotherapy notes as that term is defined under HIPAA unless services involving such records are provided.
24. HIV/AIDS AND OTHER SPECIALLY PROTECTED INFORMATION
Certain health information, including information relating to HIV/AIDS and other categories designated by law, may be subject to additional confidentiality requirements.
We will comply with applicable federal and California protections governing such records.
25. USES AND DISCLOSURES REQUIRING YOUR WRITTEN AUTHORIZATION
We will obtain your written authorization before using or disclosing PHI when HIPAA or other applicable law requires it.
This commonly includes certain:
marketing activities;
sales of PHI;
disclosures of psychotherapy notes;
uses of patient photographs for marketing when legally required;
testimonial uses of identifiable patient information; and
uses or disclosures not otherwise described in this Notice or permitted by law.
If you authorize us to use or disclose your PHI, you may generally revoke that authorization in writing at any time.
Your revocation will not affect actions already taken in reliance on your authorization.
26. PATIENT PHOTOGRAPHS AND AESTHETIC SERVICES
Sigla Health may take photographs for legitimate clinical purposes, including:
documenting baseline appearance;
monitoring treatment;
evaluating outcomes;
treatment planning; and
maintaining the medical record.
Clinical photographs that identify you or are part of your medical record are treated as PHI.
We will not use identifiable patient photographs for advertising, social media, testimonials, Website content, or other marketing purposes when applicable law requires authorization unless you have signed an appropriate authorization.
You may generally decline a marketing-photo authorization without affecting your eligibility for medically appropriate treatment.
27. EMAIL, TEXTING, AND ELECTRONIC COMMUNICATIONS
We may communicate electronically regarding your healthcare.
Electronic communications may include:
appointment reminders;
scheduling;
billing information;
treatment instructions;
follow-up messages;
patient education; and
other healthcare communications.
Standard email and text messaging may carry privacy and security risks that are outside our full control.
We may encourage or require use of a secure patient portal for highly sensitive information.
You may request alternative reasonable methods of communication.
28. OUR RESPONSIBILITIES
Sigla Health is required by law to:
maintain the privacy and security of your PHI;
provide you with this Notice describing our legal duties and privacy practices;
follow the terms of the Notice currently in effect;
notify affected individuals when required if a breach occurs that may have compromised the privacy or security of unsecured PHI; and
comply with applicable federal and state privacy laws.
We will not use or disclose your information other than as described in this Notice unless:
you provide written authorization; or
another use or disclosure is permitted or required by law.
If you authorize a use or disclosure, you may generally revoke that authorization in writing.
29. BREACH NOTIFICATION
We maintain safeguards designed to protect PHI.
If an unauthorized acquisition, access, use, or disclosure of unsecured PHI constitutes a reportable breach under applicable law, we will notify affected individuals as required by law.
Where legally required, we may also notify:
the U.S. Department of Health and Human Services;
government regulators; and
the media.
30. SECURITY OF YOUR HEALTH INFORMATION
We use reasonable administrative, technical, and physical safeguards appropriate to our operations to protect PHI.
Safeguards may include:
role-based access controls;
passwords and authentication;
secure electronic systems;
encryption where appropriate;
workforce training;
confidentiality requirements;
security policies;
secure record-storage practices;
cybersecurity protections;
vendor oversight; and
Business Associate Agreements where required.
No system can eliminate every cybersecurity or privacy risk, but we are committed to complying with applicable safeguards and breach-response requirements.
31. MINIMUM NECESSARY STANDARD
When HIPAA's minimum-necessary requirement applies, we make reasonable efforts to limit the PHI we use, disclose, or request to the minimum amount reasonably necessary to accomplish the intended purpose.
The minimum-necessary rule does not apply to certain disclosures, including disclosures for treatment or disclosures specifically authorized by the patient.
32. PATIENT PORTAL
Where Sigla Health provides access to a patient portal or electronic-health-record portal, you may be able to use that system to:
access certain medical information;
complete forms;
communicate with our team;
review results;
request appointments; or
perform other permitted functions.
You are responsible for protecting your portal login credentials and for notifying us if you believe your account has been compromised.
33. CHANGES TO THIS NOTICE
We reserve the right to change the terms of this Notice and our privacy practices as permitted by law.
Changes may apply to all PHI we maintain, including information created or received before the change.
If we materially revise this Notice, the revised Notice will be made available:
on our Website;
at our office;
upon request; and
through other methods required by applicable law.
The effective date will appear at the beginning of the Notice.
34. PRIVACY COMPLAINTS
If you believe your privacy rights have been violated, you may submit a complaint to Sigla Health.
You will not be denied treatment, penalized, intimidated, or retaliated against for filing a good-faith privacy complaint.
You may also submit a complaint to the:
U.S. Department of Health and Human Services
Office for Civil Rights
Information about filing a federal HIPAA complaint is available through the U.S. Department of Health and Human Services Office for Civil Rights.
35. PRIVACY CONTACT
If you have questions regarding this Notice, wish to exercise a privacy right, request records, request an amendment, request an accounting of disclosures, request confidential communications, or submit a privacy complaint, contact:
Privacy Officer
Sigla Health
Mitchell Advanced Practice Nursing & Wellness Inc.
2060 Otay Lakes Road, Suite 220
Chula Vista, California 91913
Email: info@siglahealth.com
Website: www.siglahealth.com
Telephone: (619) 500-5657