Notice of Privacy POLICY and Data Protection Policy | English Version

Last Updated: November 7, 2025

This notice describes how your medical and personal information may be used and disclosed, and how you can access it. Please read it carefully.

Caring Bears Health is committed to protecting the privacy and confidentiality of your personal and health information in accordance with U.S. federal and state data protection laws, including the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health Act (HITECH), the Federal Trade Commission (FTC) Safeguards Rule, and, where applicable, the California Consumer Privacy Act (CCPA).


1. Protected Health Information (PHI) and Personal Data

Protected Health Information (PHI) refers to information that can identify you and relates to your physical or mental health condition, health care services, or payment for such services.

Personal Data refers to any information that identifies, relates to, describes, or can reasonably be linked to you, such as your name, address, email, phone number, or online identifiers.

Both PHI and Personal Data are handled with the highest standards of confidentiality and security.


2. How We Use and Disclose Your Information

Caring Bears may use and disclose your PHI and Personal Data only for the following lawful purposes:

a. Treatment

To provide, coordinate, and manage your health care, including sharing information with doctors, nurses, and other health professionals involved in your care.

b. Payment

To bill and collect payment for services rendered, including communication with insurance companies and claims administrators.

c. Health Care Operations

For internal business operations such as quality improvement, audits, staff training, compliance, and performance evaluation.

d. Legal and Regulatory Compliance

To comply with federal, state, or local laws, including those related to public health, law enforcement, and regulatory oversight.

e. Communication and Scheduling

To contact you regarding appointments, test results, care updates, or educational information related to your health.

f. Marketing and Service Communications

We may use your contact information to send you marketing materials, including promotions, special offers, new services, or community engagement activities related to Caring Bears Health. These communications are intended to keep you informed about opportunities and services that may benefit your well-being. You may opt out of receiving these marketing communications at any time by following the unsubscribe instructions included in our messages or by contacting us directly.

We will not sell, rent, or lease your personal or health information to third parties.


3. Other Disclosures Permitted or Required by Law

We may disclose your information without your authorization when required or permitted by law, including:

  • Public Health: For disease control, injury prevention, or safety reporting.
  • Health Oversight: For audits, investigations, or licensure reviews.
  • Law Enforcement and Court Orders: In compliance with legal processes.
  • Organ and Tissue Donation: As required by applicable law.
  • Military and National Security: For authorized national security purposes.
  • Victims of Abuse or Neglect: To authorized government agencies.
  • Emergencies or Serious Threats: To prevent a serious threat to health or safety.

4. Data Protection and Security

Caring Bears implements administrative, physical, and technical safeguards to protect your information from unauthorized access, disclosure, or loss. These include:

  • Encrypted data storage and transmission.
  • Role-based access control for staff.
  • Regular system audits and cybersecurity monitoring.
  • Secure data disposal when no longer required by law.

We comply with the FTC Safeguards Rule, ensuring that all personal information is handled securely and responsibly.


5. Your Rights Under U.S. Privacy and Data Protection Laws

Depending on your location and applicable laws, you may have the following rights:

a. Access and Copies

You have the right to request access to or copies of your Protected Health Information (PHI) or personal data we maintain.

b. Correction and Amendment

You may request corrections if your information is inaccurate or incomplete.

c. Restrictions

You may request restrictions on how your data is used or shared, although we may not always be able to comply with all restrictions.

d. Accounting of Disclosures

You may request a list of certain disclosures made in the past six years, excluding those related to treatment, payment, or operations.

e. Data Portability

You may request that your data be provided to you or another provider in an electronic format.

f. Deletion (CCPA/State Rights)

In certain jurisdictions, such as California, you may request the deletion of your personal data, subject to legal or medical record retention requirements.

g. Opt-Out of Marketing Communications

You may unsubscribe from marketing or non-essential communications at any time by contacting us or replying “STOP” to SMS or WhatsApp messages.


6. HIPAA and HITECH Compliance

As a Covered Entity under HIPAA, Caring Bears Health:

  • Protects all Protected Health Information (PHI) in compliance with HIPAA Privacy and Security Rules.
  • Notifies affected individuals in the event of a data breach, as required by the HITECH Act.
  • Regularly trains employees on privacy and security standards.
  • Limits PHI access strictly to authorized personnel.

7. Use of Phone Numbers for SMS/MMS Communications

By providing your phone number, you consent to receive appointment reminders, health updates, and service notifications via SMS/MMS.
You can opt out at any time by replying “STOP” to a message or contacting us directly.
We do not share or sell phone numbers to third parties.


8. Data Retention

We retain personal and health information only as long as necessary to fulfill the purposes described in this notice or as required by law, professional standards, or contractual obligations.


9. Minors’ Privacy

We do not knowingly collect or disclose PHI or personal information from individuals under the age of 18 without parental or guardian consent, except as permitted by law.


10. Changes to This Policy

We may update this Notice and Data Protection Policy periodically.
Any updates will be posted on our website with a new effective date.
We encourage you to review it regularly.


11. Contact Information

If you have any questions, requests, or complaints regarding this policy or believe your privacy rights have been violated, please contact us:

Caring Bears Health
Address: 25 Braintree Hill Office Park Suite 200, Braintree MA 02184
Phone: +1 (857) 544-1791
Email: info@caringbearshealth.com
Website: www.caringbearshealth.com

You may also file a complaint with the U.S. Department of Health and Human Services (HHS).
You will not be penalized for filing a privacy complaint.