Notice of Privacy Practices
Nifely Health — Behavioral Mental Health Practice
This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully.
Effective Date: January 1, 2025 · Last Revised: August 2025
Our Legal Duty
We are required by law to maintain the privacy of your Protected Health Information (PHI) and to provide you with this Notice of our legal duties and privacy practices. We are required to abide by the terms of this Notice currently in effect. We may change the terms of this Notice at any time. If we change this Notice, we will make the new Notice available upon request and post it in our office and on our website.
Nifely Health is a covered entity under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act. We are required to:
- Maintain the privacy of your PHI
- Provide you with this Notice of our privacy practices
- Follow the terms of the Notice currently in effect
- Notify you if there is a breach of your unsecured PHI
For more information about HIPAA and your rights, visit the U.S. Department of Health & Human Services: hhs.gov/hipaa/for-individuals
How We May Use and Disclose Your Health Information
The following categories describe the ways we may use and disclose your PHI. Not every use or disclosure in a category will be listed, but all of the ways we are permitted to use and disclose information will fall within one of the categories.
Treatment
We may use and disclose your PHI to provide, coordinate, or manage your mental health care and related services. For example, we may disclose your PHI to a referring physician, psychiatrist, therapist, or other healthcare provider involved in your care.
Payment
We may use and disclose your PHI to obtain payment for services we provide to you. For example, we may contact your health insurer to certify that you are eligible for benefits and to obtain approval for a planned course of treatment.
Healthcare Operations
We may use and disclose your PHI in connection with our healthcare operations, including quality assessment, employee review, training, licensing, and conducting or arranging for other business activities.
Appointment Reminders
We may use and disclose your PHI to contact you as a reminder that you have an appointment for treatment or medical care at Nifely Health.
As Required by Law
We will disclose your PHI when required to do so by federal, state, or local law, including mandatory reporting requirements in Washington, Wyoming, and Texas.
Public Health Activities
We may disclose your PHI for public health activities and purposes, including to prevent or control disease, injury, or disability; to report births and deaths; to report child abuse or neglect; and to report reactions to medications or problems with products.
Abuse, Neglect, or Domestic Violence
We may disclose your PHI to a government authority if we believe you are a victim of abuse, neglect, or domestic violence. We will make this disclosure only when required or authorized by law.
Health Oversight Activities
We may disclose your PHI to a health oversight agency for activities authorized by law, such as audits, investigations, inspections, and licensure.
Judicial and Administrative Proceedings
We may disclose your PHI in response to a court or administrative order, subpoena, discovery request, or other lawful process.
Law Enforcement
We may release your PHI if asked to do so by a law enforcement official in response to a court order, subpoena, warrant, summons, or similar process; to identify or locate a suspect, fugitive, material witness, or missing person; or in emergency circumstances to report a crime.
Serious Threats to Health or Safety
We may use and disclose your PHI when necessary to prevent a serious threat to your health and safety or the health and safety of the public or another person. Any disclosure, however, would only be to someone able to help prevent the threat.
Telehealth Services
Nifely Health provides HIPAA-compliant telehealth services. All video sessions are conducted through a HIPAA-compliant platform. Electronic communications, including scheduling and messaging, are conducted through HIPAA-compliant systems. We do not use standard consumer video platforms (e.g., regular Zoom, FaceTime, Skype) for clinical sessions.
Business Associates
We may share your PHI with third-party "business associates" that perform services on our behalf, such as billing companies, electronic health record (EHR) vendors, telehealth platforms, and appointment scheduling systems. We require all business associates to appropriately safeguard your PHI through a Business Associate Agreement (BAA).
Uses and Disclosures Requiring Your Written Authorization
Other uses and disclosures of your PHI will be made only with your written authorization, unless otherwise permitted or required by law as described in this Notice. You may revoke this authorization in writing at any time. If you revoke your authorization, we will no longer use or disclose your PHI as described in that authorization. We are unable to take back any disclosures we have already made with your authorization.
The following uses and disclosures require your written authorization:
- Most uses and disclosures of psychotherapy notes
- Uses and disclosures of PHI for marketing purposes
- Disclosures that constitute a sale of PHI
- Other uses and disclosures not described in this Notice
Special Protections for Mental Health Information: Washington, Wyoming, and Texas law may provide additional protections for mental health records beyond those required by HIPAA. We comply with all applicable state laws regarding the privacy of mental health information.
Your Rights Regarding Your Health Information
You have the following rights regarding the PHI we maintain about you:
Right to Inspect and Copy
You have the right to inspect and copy your PHI that may be used to make decisions about your care. To inspect and copy your PHI, submit your request in writing to our Privacy Officer. We may charge a reasonable fee for the costs of copying, mailing, or other supplies associated with your request. We may deny your request to inspect and copy in certain limited circumstances.
Right to Amend
If you feel that the PHI we have about you is incorrect or incomplete, you may ask us to amend the information. You have the right to request an amendment for as long as the information is kept by or for our practice. To request an amendment, your request must be made in writing and submitted to our Privacy Officer. We may deny your request for an amendment if it is not in writing or does not include a reason to support the request.
Right to an Accounting of Disclosures
You have the right to request an "accounting of disclosures." This is a list of the disclosures we made of your PHI for purposes other than treatment, payment, and healthcare operations. To request this list, you must submit your request in writing to our Privacy Officer. Your request must state a time period, which may not be longer than six years.
Right to Request Restrictions
You have the right to request a restriction or limitation on the PHI we use or disclose about you for treatment, payment, or health care operations. You also have the right to request a limit on the PHI we disclose about you to someone who is involved in your care or the payment for your care. We are not required to agree to your request. If we do agree, we will comply with your request unless the information is needed to provide you emergency treatment.
Right to Request Confidential Communications
You have the right to request that we communicate with you about medical matters in a certain way or at a certain location. For example, you can ask that we only contact you at work or by mail. To request confidential communications, you must make your request in writing to our Privacy Officer.
Right to a Paper Copy of This Notice
You have the right to a paper copy of this Notice. You may ask us to give you a copy of this Notice at any time. Even if you have agreed to receive this Notice electronically, you are still entitled to a paper copy.
Right to Notification of a Breach
You have the right to be notified if there is a breach of your unsecured PHI. We will notify you without unreasonable delay and in no case later than 60 days following the discovery of a breach.
Breach Notification
In the event of a breach of unsecured PHI, we will notify affected individuals, the Secretary of the U.S. Department of Health and Human Services (HHS), and, when required, prominent media outlets, in accordance with the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414).
Notification to individuals will be provided without unreasonable delay and in no case later than 60 calendar days after discovery of the breach. The notification will include:
- A brief description of what happened, including the date of the breach and the date of discovery
- A description of the types of unsecured PHI involved
- Steps individuals should take to protect themselves from potential harm
- A brief description of what we are doing to investigate the breach, mitigate harm, and protect against further breaches
- Contact information for individuals to ask questions or learn additional information
Security Safeguards
Nifely Health implements administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of your electronic PHI (ePHI), in accordance with the HIPAA Security Rule (45 CFR Part 164, Subpart C).
Administrative Safeguards
- Designated Privacy and Security Officer responsible for HIPAA compliance
- Workforce training on HIPAA policies and procedures
- Risk analysis and risk management program
- Sanction policy for workforce members who fail to comply with privacy policies
Physical Safeguards
- Facility access controls for our Kent, WA clinical office
- Workstation use and security policies
- Device and media controls for equipment containing ePHI
Technical Safeguards
- Access controls — unique user identification and automatic logoff
- Audit controls — hardware, software, and procedural mechanisms to record and examine activity
- Integrity controls — measures to protect ePHI from improper alteration or destruction
- Transmission security — encryption of ePHI transmitted over electronic communications networks
- HIPAA-compliant EHR system with BAA in place
- HIPAA-compliant telehealth platform with BAA in place
- HIPAA-compliant scheduling and messaging systems with BAAs in place
Business Associate Agreements (BAAs)
We maintain executed BAAs with all vendors and service providers that create, receive, maintain, or transmit ePHI on our behalf, including but not limited to our EHR provider, telehealth platform, appointment scheduling system, billing services, and cloud hosting provider.
State-Specific Privacy Protections
Washington State
Washington's Uniform Health Care Information Act (RCW 70.02) provides additional protections for health information beyond HIPAA. Mental health records in Washington are subject to heightened confidentiality protections under RCW 71.05.390. We comply with all applicable Washington State privacy laws.
Wyoming
Wyoming's Mental Health Professions Practice Act and related statutes provide confidentiality protections for mental health records. We comply with all applicable Wyoming privacy laws, including Wyo. Stat. § 33-38-113.
Texas
Texas Health & Safety Code Chapter 611 provides confidentiality protections for mental health records. We comply with all applicable Texas privacy laws, including the Texas Medical Records Privacy Act (Health & Safety Code Chapter 181).
Where state law provides greater privacy protections than HIPAA, we follow the more protective state law.
Privacy of Minors
Nifely Health provides services to patients ages 6 and older. For minor patients, a parent or legal guardian generally has the right to access the minor's PHI. However, there are exceptions under state law where a minor may have the right to consent to certain types of treatment and where the minor's PHI may be kept confidential from parents or guardians. We will comply with applicable state laws regarding the privacy rights of minors in Washington, Wyoming, and Texas.
For patients ages 6–17, we work collaboratively with parents/guardians and the minor patient to establish appropriate boundaries for confidentiality, consistent with applicable law and clinical best practices.
How to File a Complaint
If you believe your privacy rights have been violated, you may file a complaint. To file a complaint with us, please email: [email protected]. To file a complaint with HHS, visit:
hhs.gov/hipaa/filing-a-complaint
You will not be penalized or retaliated against for filing a complaint.
Contact for Privacy Questions
For questions about this Notice or to exercise your rights, contact:
Nifely Health — Privacy Questions
Administrative / Mailing: 1915 140th Ave NE #1807, Bellevue, WA 98005
Clinical Office: 1215 Central Ave S, Suite #178, Kent, WA 98032
Hours: Mon–Fri 7 AM – 5 PM PST