VitalCare Health (“Provider,” “we,” “us,” or “our”) is a cash-pay healthcare provider based in Minneapolis, Minnesota. We provide healthcare services directly to patients through in-person appointments, telehealth services, and related healthcare channels, without submitting claims to health insurance companies.
We are committed to protecting the privacy, confidentiality, and security of information entrusted to us. This Privacy Policy explains how we collect, use, disclose, maintain, and protect personal information and protected health information (“PHI”) when you receive healthcare from us or use our website, patient portal, mobile applications, telehealth platforms, electronic communications, in-person services, and related services (collectively, the “Services”).
This Policy addresses applicable federal and Minnesota privacy requirements, including the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, the HITECH Act, the Minnesota Health Records Act, and other applicable federal and Minnesota laws.
1. ABOUT US
Legal Name: VitalCare Health
Business Address: 2600 East 25th Street, Upstairs Suite, Minneapolis, MN 55406
Telephone: +1 (612) 633-7898
Email: info@vitalcarehealth.org
Website: www.vitalcarehealth.org
VitalCare Health provides healthcare services through a combination of in-person and virtual care, including primary care, psychiatry, therapy, weight management, wellness services, and other healthcare services offered by the Provider.
Our Services are provided on a cash-pay basis. Patients are responsible for paying our fees directly, and we do not submit claims to health insurance companies on behalf of patients.
Where other healthcare professionals or organizations independently provide care, they may have their own privacy policies and legal responsibilities.
2. INFORMATION WE COLLECT
We collect information necessary to provide safe, effective, and lawful healthcare services.
i. Personal Information
This may include:
- Full name
- Date of birth
- Address
- Telephone number
- Email address
- Emergency contact information
- Identification information where necessary
- Account and login information
- Information necessary to verify your identity
ii. Health Information
To provide healthcare, we may collect:
- Medical history
- Current symptoms
- Diagnoses
- Medications
- Allergies
- Laboratory and diagnostic information
- Treatment history
- Clinical notes
- Prescriptions
- Referrals
- Health measurements
- Information provided during in-person appointments
- Information provided during telehealth consultations
Health information is treated as confidential and protected under applicable federal and Minnesota law.
iii. Payment Information
Because our Services are cash-based, we collect information necessary to process your direct payment, such as:
- Payment amount
- Transaction date
- Payment status
- Billing information
- Limited payment card information, where applicable
Payment card information may be processed by a third-party payment processor. We generally do not retain complete payment card numbers.
We do not submit claims to health insurance companies for our Services.
iv. Technical Information
When you use our website, patient portal, mobile applications, telehealth platform, or other electronic systems, we may collect:
- IP address
- Device information
- Browser type
- Operating system
- Login information
- Date and time of access
- Technical and diagnostic information
- Security-related information
3. HOW WE COLLECT INFORMATION
We may collect information:
- Directly from you
- When you register for our Services
- Through patient intake forms
- During in-person appointments
- During telehealth consultations
- Through our patient portal
- Through communications with our healthcare professionals
- From other healthcare providers involved in your care, where permitted
- From laboratories or pharmacies where necessary for your care
- From payment processors
- Automatically through our website and technology systems
4. HOW WE USE YOUR INFORMATION
We use your information primarily to provide and manage your healthcare.
Providing Healthcare
We may use your information to:
- Schedule appointments
- Conduct in-person consultations and examinations
- Conduct telehealth consultations
- Assess your health
- Diagnose and treat medical conditions
- Provide medical advice
- Prescribe medications where clinically and legally appropriate
- Order or review laboratory or diagnostic testing
- Make referrals
- Coordinate care
- Provide follow-up services
- Maintain your medical records
Payment and Administration
We may use your information to:
- Process direct payments
- Manage your account
- Provide receipts
- Respond to questions
- Schedule appointments
- Communicate with you about our Services
- Maintain business and financial records
Healthcare Operations
Where permitted by law, information may be used for:
- Quality improvement
- Patient safety
- Staff training
- Compliance activities
- Auditing
- Security
- System maintenance
- Business administration
5. CASH-PAY MODEL AND INSURANCE
Our Services are provided directly to patients on a cash-pay basis.
We do not bill health insurance companies for Services provided by this practice.
We generally do not need to collect insurance policy numbers, insurance member IDs, or insurance claims information.
If you choose to seek reimbursement independently from an insurance company or another third party, you are responsible for determining whether your insurer will reimburse you.
If we provide you with a receipt or superbill, you are responsible for submitting it to your insurer if you choose to do so.
Providing a receipt or superbill does not mean that we will submit an insurance claim on your behalf.
6. HIPAA AND PROTECTED HEALTH INFORMATION
VitalCare Health is a HIPAA Covered Entity, and your PHI is protected under HIPAA.
We may use or disclose PHI without your separate authorization where permitted or required by law, including for:
- Treatment
- Payment
- Healthcare operations
- Public health activities
- Certain legal proceedings
- Required reporting
- Serious threats to health or safety
- Other purposes authorized by law
For uses or disclosures that require your authorization, we will obtain that authorization before proceeding.
Our separate Notice of Privacy Practices provides additional information about your HIPAA rights and how we may use and disclose PHI.
7. MINNESOTA HEALTH RECORDS
Minnesota law provides additional protections for health records.
Under the Minnesota Health Records Act, healthcare providers generally must obtain appropriate patient consent before releasing health records, subject to exceptions provided by law.
We will comply with applicable Minnesota requirements when accessing, using, or disclosing your health records.
8. SHARING YOUR INFORMATION
We do not sell your medical records or PHI.
We may disclose information when permitted or required by law.
Healthcare Providers
We may share relevant information with healthcare professionals involved in your care, including specialists, laboratories, pharmacies, and other providers.
Service Providers
We may use third-party companies to support our operations, including:
- Telehealth technology providers
- Electronic health record providers
- Cloud hosting providers
- Payment processors
- Appointment scheduling platforms
- Cybersecurity providers
- Patient communication platforms
Where HIPAA applies, appropriate Business Associate Agreements will be used where required.
Legal Requirements
We may disclose information when required by federal, Minnesota, or other applicable law.
Emergencies
Information may be disclosed where reasonably necessary to protect a person’s life, health, or safety, as permitted by law.
9. IN-PERSON PRIVACY
When you receive care at our physical location, we take reasonable administrative, technical, and physical measures to protect the privacy and confidentiality of your information.
These measures may include:
- Conducting consultations and examinations in appropriate private areas
- Limiting access to patient records to authorized personnel
- Maintaining appropriate safeguards for paper and electronic records
- Using secure systems for storing and accessing health information
- Protecting patient information during registration and check-in
- Taking reasonable steps to prevent unauthorized persons from overhearing confidential conversations
- Properly securing and disposing of paper records and other materials containing PHI
Patients may be asked to confirm their identity before receiving services or accessing health information.
While we take reasonable precautions, no physical or electronic environment can be guaranteed to be completely free from privacy or security risks.
10. TELEHEALTH PRIVACY
Telehealth involves the electronic transmission of healthcare information.
We use reasonable administrative, technical, and physical safeguards designed to protect your information. However, no electronic communication system is completely risk-free.
For your protection, we recommend that you:
- Participate from a private location
- Use a secure internet connection
- Keep your device’s operating system updated
- Protect your passwords
- Do not share your patient portal credentials
- Avoid using public computers for healthcare communications
- Use a private device where possible
- Take reasonable steps to prevent others from overhearing your consultation
11. TELEHEALTH RECORDING
We generally do not record telehealth consultations.
If we intend to record a consultation, we will provide appropriate notice and obtain any consent or authorization required by applicable law.
Patients should understand that recording a consultation themselves may be subject to applicable federal and state laws.
12. SENSITIVE HEALTH INFORMATION
Certain categories of health information may receive additional protection under federal or Minnesota law.
Depending on the Services we provide, this may include information concerning:
- Mental health
- Substance use disorder treatment
- HIV/AIDS
- Genetic information
- Reproductive healthcare
- Sexual health
- Other specially protected healthcare services
We will comply with additional legal requirements applicable to such information.
13. REPRODUCTIVE HEALTHCARE INFORMATION
Where applicable, reproductive healthcare information will be handled in accordance with federal and Minnesota law.
We will not knowingly use or disclose protected reproductive healthcare information for purposes prohibited by applicable law.
Where an authorization, attestation, or other legal requirement applies, we will comply with that requirement.
14. PAYMENT PROCESSING
Because we operate on a cash-pay basis, payment processing is an important part of our Services.
Payments may be made by:
- Credit or debit card
- Electronic payment
- Bank transfer
- Other payment methods we make available
Third-party payment processors may process payment information under their own privacy policies and security requirements.
We do not sell payment information.
15. MARKETING COMMUNICATIONS
We may communicate with you about:
- Your appointments
- Healthcare services
- Educational information
- Practice announcements
- New or expanded services
Where applicable law requires authorization for marketing involving PHI, we will obtain the appropriate authorization.
You may opt out of non-essential marketing communications.
You cannot opt out of necessary communications concerning your healthcare, appointments, account, payments, security, or other essential Services.
16. WEBSITE COOKIES AND TRACKING
Our website may use cookies and similar technologies for:
- Security
- Essential functionality
- User preferences
- Website performance
- Analytics
- Service improvement
Because our website may be used to access healthcare-related Services, we take care to ensure that online tracking technologies are used consistently with applicable privacy laws and HIPAA requirements.
Where required, we will obtain appropriate consent before using non-essential tracking technologies.
17. DATA SECURITY
We maintain reasonable administrative, technical, and physical safeguards designed to protect your information.
These may include:
- Encryption
- Secure authentication
- Access controls
- Role-based permissions
- Security monitoring
- Employee confidentiality requirements
- Cybersecurity procedures
- Data backup
- Incident response procedures
Only authorized personnel with a legitimate need should have access to your health information.
18. DATA BREACHES
If we discover a breach involving unsecured PHI or other protected personal information, we will investigate and respond in accordance with applicable federal and Minnesota law.
Where required, we will notify affected individuals and appropriate regulatory authorities.
19. DATA RETENTION
We retain medical records and other personal information for the period required by applicable law and as necessary to:
- Provide healthcare
- Comply with professional obligations
- Resolve disputes
- Maintain appropriate business records
- Protect our legal interests
When information is no longer required, we will take reasonable steps to securely dispose of or anonymize it.
20. YOUR PRIVACY RIGHTS
Depending on applicable law, you may have rights including:
- Accessing your health information
- Obtaining copies of certain health records
- Requesting correction or amendment of inaccurate information
- Requesting restrictions on certain uses or disclosures
- Requesting confidential communications
- Receiving information about certain disclosures
- Receiving a copy of our applicable Notice of Privacy Practices
- Revoking certain authorizations where permitted
- Filing a privacy complaint without retaliation
Some rights are subject to legal exceptions.
21. CHILDREN’S PRIVACY
Our Services may be available to minors where legally permitted.
Where required, we will obtain appropriate consent from a parent, guardian, or other legally authorized representative.
Minnesota law permits minors to consent independently to certain healthcare services in specified circumstances. Where applicable, confidentiality requirements may limit disclosure of such information to parents or guardians.
22. THIRD-PARTY SERVICES
Our Services may connect with third-party technology and healthcare services.
These may include:
- Electronic health record systems
- Telehealth platforms
- Payment processors
- Laboratories
- Pharmacies
- Scheduling platforms
- Secure communication systems
We take reasonable steps to ensure that vendors handling PHI on our behalf meet applicable contractual and legal requirements.
23. YOUR CHOICES REGARDING INFORMATION
You may contact us to:
- Ask questions about our privacy practices
- Request access to your health information
- Request correction of information
- Ask about disclosures
- Withdraw certain consents where legally permitted
- Request confidential communications
- Submit a privacy complaint
Requests should be directed to our Privacy Officer.
24. PRIVACY COMPLAINTS
You may submit a privacy complaint directly to us.
Email: info@vitalcarehealth.org
Telephone: +1 (612) 633-7898
You may also file a complaint with the U.S. Department of Health & Human Services Office for Civil Rights if you believe your HIPAA rights have been violated.
We will not retaliate against you for making a privacy complaint.
25. CHANGES TO THIS POLICY
We may update this Privacy Policy periodically.
Changes may be made to reflect:
- Changes in our Services
- Changes in technology
- Changes in applicable law
- Changes in our privacy practices
The current version will be posted on our website with the applicable effective date.
26. CONTACT US
For questions about this Privacy Policy or our privacy practices:
VitalCare Health
2600 East 25th Street, Upstairs Suite
Minneapolis, MN 55406
Email: info@vitalcarehealth.org
Telephone: +1 (612) 633-7898
Website: www.vitalcarehealth.org