Notice of Privacy Practices
THIS NOTICE DESCRIBES HOW PROTECTED HEALTH INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND
HOW YOU CAN GET ACCESS TO THIS INFORMATION.
PLEASE REVIEW IT CAREFULLY.
Innovultz (“Innovultz,” “we,” “us,” or “our”) provides marketing, outreach, and communication services for insurance
agents, brokers, and health plan organizations. In the course of providing these services, we may receive, create,
transmit, or store Protected Health Information (“PHI”) on behalf of our clients.
Innovultz is committed to protecting the privacy and security of PHI in accordance with the Health Insurance
Portability and Accountability Act of 1996 (“HIPAA”), as amended, and other applicable laws.
1. OUR ROLE
In most cases, Innovultz operates as a Business Associate to Covered Entities such as health insurance plans,
agents, and healthcare-related organizations.
We handle PHI only as permitted by our contractual agreements and applicable law.
2. OUR RESPONSIBILITIES
Innovultz is required to:
-
Maintain the privacy and security of PHI.
-
Use and disclose PHI only as permitted under applicable agreements and law.
-
Implement administrative, physical, and technical safeguards to protect PHI.
-
Notify the appropriate Covered Entity without unreasonable delay if a breach of unsecured PHI occurs.
-
Follow the terms of this Notice currently in effect.
3. HOW WE MAY USE AND DISCLOSE PHI
Innovultz may use or disclose PHI only as permitted by our agreements with our clients and by law.
A. To Provide Services on Behalf of Clients
We may use PHI to perform services such as:
-
Member outreach and engagement communications
-
Marketing campaigns for insurance products
-
SMS, email, and automated communications
-
Enrollment support communications
-
Data management and reporting
These services are performed strictly under the direction of our Covered Entity clients.
B. As Required by Law
We may disclose PHI when required to do so by federal, state, or local law.
C. To Subcontractors
We may share PHI with subcontractors who perform services on our behalf. All subcontractors are required to enter into written agreements requiring them to safeguard PHI in accordance with HIPAA.
D. To Prevent Serious Threats
We may disclose PHI when necessary to prevent or lessen a serious threat to health or safety, consistent with applicable law.
4. COMMUNICATIONS (INCLUDING SMS AND ELECTRONIC MESSAGING)
Innovultz utilizes secure, HIPAA-compliant communication platforms, including encrypted cloud infrastructure and
HIPAA-compliant SMS services.
Electronic communications may include:
-
Appointment reminders
-
Plan updates
-
Enrollment information
-
Benefit-related outreach
While we implement industry-standard security controls, no system can guarantee absolute security. Individuals are
encouraged to safeguard their personal devices and communication channels.
5. HOW WE PROTECT YOUR INFORMATION
Innovultz maintains safeguards including:
-
Role-based access controls
-
Encryption in transit and at rest
-
Multi-factor authentication
-
Secure cloud hosting environments
-
Workforce training on privacy and security
-
Business Associate Agreements with vendors
Access to PHI is limited to authorized personnel who require it to perform job functions.
6. YOUR RIGHTS
Because Innovultz generally acts as a Business Associate, requests related to your health information should
typically be directed to the health plan, insurance agent, or organization that provided your information.
However, under HIPAA, you may have the right to:
-
Access or obtain a copy of your PHI
-
Request corrections to your PHI
-
Request an accounting of certain disclosures
-
Request restrictions on certain uses or disclosures
We will coordinate with the appropriate Covered Entity to ensure requests are handled appropriately.
7. BREACH NOTIFICATION
If unsecured PHI is breached, Innovultz will notify the applicable Covered Entity in accordance with HIPAA
requirements. The Covered Entity is generally responsible for notifying affected individuals unless otherwise agreed.
8. CHANGES TO THIS NOTICE
Innovultz reserves the right to update this Notice at any time. Updated versions will be posted on our website and
available upon request.
9. QUESTIONS OR COMPLAINTS
If you have questions about this Notice or believe your privacy rights may have been violated, please contact
privacy@innovultz.com.
You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights. We will
not retaliate against you for filing a complaint.