Office Privacy Policy

Privacy Policy and Protection of Protected Health Information (PHI)

Effective Date: August 5, 2026

At Greenway Orthodontics, we are committed to protecting the privacy and confidentiality of our patients’ Protected Health Information (PHI). This Privacy Policy describes how we collect, use, disclose, safeguard, and protect your health information in accordance with the Health Insurance Portability and Accountability Act (HIPAA) and other applicable federal and state laws.

Our Commitment to Privacy

We understand that your medical and dental information is personal. We are dedicated to maintaining the privacy and security of your PHI and have implemented administrative, physical, and technical safeguards to protect it from unauthorized access, use, or disclosure.

What Is Protected Health Information (PHI)?

Protected Health Information (PHI) includes information that identifies you and relates to:

Your past, present, or future physical or mental health.

The health care services you receive.

PHI may exist in electronic, paper, or verbal form.

Payment for your health care services.

How We Use and Disclose PHI

We may use or disclose your PHI for the following purposes without your written authorization:

Treatment

To provide, coordinate, and manage your dental care.
To consult with specialists, laboratories, pharmacies, or other healthcare providers involved in your treatment.

Payment

To bill and collect payment from you, your insurance company, or another responsible party.
To verify insurance benefits and obtain prior authorizations.

Health Care Operations

We may disclose PHI when required or permitted by law, including:
Except as permitted by law, we will obtain your written authorization before:
You may revoke your authorization at any time in writing, except to the extent action has already been taken based on your authorization.

Patient Rights

You have the right to:
Our practice protects PHI by implementing:
Access to PHI is limited to workforce members and authorized business associates who need the information to perform their job responsibilities

Business Associates

We may share PHI with trusted vendors or service providers who perform functions on our behalf. These organizations are required by law and contract to protect your PHI and may use it only for authorized purposes.

Electronic Communications

If you choose to communicate with us by email, text message, or other electronic methods, there may be some risk that the information could be accessed by unauthorized individuals. Where appropriate, we use secure communication methods and will obtain any necessary consent before communicating electronically.

Data Retention

We retain patient records in accordance with applicable federal and state laws and professional record-retention requirements. Records are securely disposed of when they are no longer required to be retained.

Breach Notification

If a breach of unsecured PHI occurs that affects your information, we will notify you as required by HIPAA and applicable law.

Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy at any time. Updated versions will be available in our office and will apply to all PHI maintained by the practice unless otherwise required by law.

Contact Information

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact:
Privacy Officer: Office Manager

Dental Practice: Greenway Orthodontics

Address: 30 Greenway St NW Ste 4, Glen Burnie, MD 21061, United States

Telephone: +1 410-760-8888

Filing a Complaint

If you believe your privacy rights have been violated, you may file a complaint with our Privacy Officer or with the U.S. Department of Health and Human Services, Office for Civil Rights. Filing a complaint will not affect the quality of care you receive.
By receiving dental services from our practice, you acknowledge that you have been offered access to our Notice of Privacy Practices as required by HIPAA.
One important distinction: under HIPAA, patients must be provided with a Notice of Privacy Practices (NPP) that contains specific required elements. A general “privacy policy” alone does not satisfy that requirement. If you need a document for patient intake or your website, I can also draft a HIPAA-compliant Notice of Privacy Practices that includes all required disclosures and acknowledgment language.