Obtego Privacy Policy

Effective date: January 30, 2026

1. Purpose and Scope

This document establishes the official internal policy for the protection of Patient Health Information (PHI) for Obtego. This policy applies to all members of our workforce, including employees, volunteers, trainees, and other persons whose conduct, in the performance of work for our organization, is under our direct control. This policy is enacted to ensure full compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule and all other applicable federal and state laws.

2. Definitions

3. Policy: Permitted Uses and Disclosures of PHI

3.1 Without Patient Authorization: We may use and disclose PHI without a patient’s written authorization for the purposes of Treatment, Payment, and Healthcare Operations (TPO).

3.2 With Patient Authorization: Any use or disclosure of PHI for purposes other than TPO requires a specific, written authorization from the patient. This includes, but is not limited to, most uses and disclosures for marketing purposes or the sale of PHI.

3.3 Minimum Necessary Standard: We will make reasonable efforts to limit the use, disclosure of, and requests for PHI to the minimum necessary to accomplish the intended purpose.

4. Patient Rights

All patients of Obtego have the following rights regarding their PHI:

5. Safeguards for Protecting PHI

Obtego will implement and maintain the following safeguards to protect PHI:

6. Breach Notification Procedures

In the event of a breach of unsecured PHI, Obtego will follow its Breach Notification Policy, which includes procedures for timely notification to affected individuals, the Secretary of Health and Human Services, and, where applicable, the media, in accordance with the HIPAA Breach Notification Rule.

7. Privacy Officer

The designated Privacy Officer for Obtego is:

The Privacy Officer is responsible for the development, implementation, and oversight of this policy.

8. Policy Review and Updates

This policy will be reviewed at least annually and updated as needed to reflect changes in federal and state law, technology, and our organization's operations.