HIPAA Notice
How protected health information is used and disclosed when processed through Reinfora, and how we fulfill business associate obligations.
Last updated May 29, 2026
Purpose of this notice
This notice describes how protected health information ("PHI") may be used and disclosed when processed through Reinfora, and how Reinfora fulfills its obligations as a business associate to covered entities and other business associates.
Important:Reinfora is generally not the covered entity for PHI stored in customer workspaces. Your healthcare organization remains responsible for providing legally required notices to individuals. This document explains Reinfora's role and practices as a platform provider.
Permitted uses and disclosures
Reinfora uses and discloses PHI only as permitted or required by HIPAA and the BAA, including to:
- Provide, maintain, and support the Service at the customer's direction;
- Implement administrative, physical, and technical safeguards;
- Report security incidents and assist with breach notification;
- Comply with applicable law and lawful requests;
- De-identify data where appropriate and permitted.
Reinfora personnel access PHI only on a need-to-know basis for support, engineering, or security purposes under workforce policies and agreements.
Individual rights under HIPAA
HIPAA provides individuals with rights regarding PHI held by covered entities, including:
- Right to access and obtain a copy of PHI;
- Right to request amendment of PHI;
- Right to an accounting of certain disclosures;
- Right to request restrictions and confidential communications (where applicable);
- Right to receive a notice of privacy practices from the covered entity.
Requests concerning PHI in Reinfora should be submitted to your provider organization's privacy officer. Reinfora will assist customers in responding as required by the BAA.
Safeguards
Reinfora maintains safeguards required for business associates, including access controls, encryption, audit controls, workforce training, contingency planning, and evaluation. See Security & Compliance for an overview.
Breach notification
Reinfora will notify customers without unreasonable delay upon discovery of a breach of unsecured PHI and will cooperate with investigation and mitigation. Customers remain responsible for notifying affected individuals and regulators as required by law.
Complaints
If you believe your privacy rights have been violated, contact your provider organization first. You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights:
- Website: hhs.gov/ocr/privacy/hipaa/complaints
- Toll-free: 1-800-368-1019
Reinfora will not retaliate against anyone for filing a good-faith complaint.
Changes
We may update this notice when our practices or legal requirements change. Material updates will be posted with a revised date.
Contact
Privacy Officer: celoeman@gmail.com