Privacy Policy
Effective Date: September 18, 2023
Voafit, LLC (“Voafit,” “us,” “we,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect your personal information when you access or use our website (“Website”) and services (“Services”). By using our Website and Services, you agree to the practices described in this Privacy Policy.
1. Information We Collect
Personal Information: We may collect personal information when you register for an account, subscribe to our Services, or contact us. This may include your name, email address, phone number, and billing information.
Usage Information: We automatically collect information about your interaction with our Website and Services. This may include your IP address, device information, browser type, and pages visited.
2. How We Use Your Information
Provide Services: We use your personal information to deliver and manage our Services, including processing payments, sending notifications, and providing customer support.
Improve Services: We analyze usage data to improve our Website and Services, enhance user experiences, and develop new features.
Communications: We may use your contact information to send you service-related announcements, updates, and promotional material. You can opt out of receiving promotional emails at any time.
3. Data Security
We take reasonable measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. However, no data transmission over the internet or electronic storage method is entirely secure. Therefore, we cannot guarantee the absolute security of your data.
4. Sharing of Information
We may share your personal information with trusted third parties, including payment processors, service providers, and partners, to fulfill our Services. We do not sell or rent your personal information to third parties.
We may disclose your information to comply with legal obligations, enforce our Terms and Conditions, protect our rights, privacy, safety, or property, and respond to lawful requests from public authorities.
5. Cookies and Tracking
We use cookies and similar tracking technologies to collect information about your interaction with our Website. You can control cookies through your browser settings, but disabling cookies may limit your ability to use some features of our Website.
6. Changes to This Policy
We may update this Privacy Policy from time to time. The most current version will be posted on our Website with the effective date. Your continued use of our Website and Services after any changes constitutes your acceptance of the updated policy.
7. Contact Us
For any questions or concerns about this Privacy Policy or our data practices, please contact us at admin@voafit.com.
Thank you for choosing Voafit and entrusting us with your personal information.
HIPAA Compliance Addendum
Effective Date: June 8, 2023
This addendum ensures Voafit maintains compliance with the Health Insurance Portability and Accountability Act (HIPAA) when delivering healthcare services via telemedicine, protecting the privacy and security of patients’ protected health information (PHI).
Privacy Rule Compliance
- Minimum Necessary Standard: Voafit workforce members must only access the minimum necessary PHI to perform their duties.
- Notice of Privacy Practices: Voafit provides a HIPAA-compliant privacy notice to patients outlining their rights and how their PHI is used.
- Patient Rights: Right to access medical records, request amendments, request restrictions on disclosure, and receive an accounting of disclosures.
- Consent and Authorization: Patients must provide consent for treatment and authorization for any use of PHI outside of treatment, payment, and healthcare operations.
Security Rule Compliance
Administrative Safeguards
- Assigned Privacy Officer and Security Officer
- Annual HIPAA training for all staff
- Risk assessments with maintained documentation
- Policies for incident response, workforce sanctions, and data access control
Physical Safeguards
- Secure workstations for telemedicine
- Limited physical access to areas where PHI is stored
- Access control for mobile devices used in telehealth delivery
Technical Safeguards
- End-to-end encrypted video conferencing platforms
- Unique user IDs, strong passwords, and automatic logoff
- Encryption of data at rest and in transit
- Audit controls to log access to PHI
Business Associate Agreements
Voafit executes BAAs with all vendors handling PHI, including telehealth platforms, cloud storage providers, EHR systems, and payment processors. Each BAA outlines the responsibilities of the business associate to safeguard PHI in accordance with HIPAA.
Breach Notification
In the event of a data breach involving PHI, Voafit will notify affected individuals within 60 days, notify the HHS Office for Civil Rights, and notify the media if the breach affects 500 or more individuals. A log of breaches affecting fewer than 500 individuals is maintained and reported annually.
Telehealth Considerations
- Informed consent obtained for telehealth from each patient
- All communications conducted via HIPAA-compliant platforms
- Patient identity verified at the beginning of each visit
- Each encounter documented in the EHR
- Sessions limited to private, secure locations on both ends
This guideline is reviewed and updated annually or whenever significant changes to regulations or technologies occur.