Cumplimiento de HIPAA
HIPAA Privacy Notice
Notice of Privacy Practices for Protected Health Information (PHI)
Effective Date: May 29, 2026
About This Notice
Zanason LLC ("Zanason") operates the marketing website at zanason.com. Zanason does not provide medical care and does not collect Protected Health Information ("PHI") through zanason.com.
Clinical care for Zanason patients is operated by Arora Health & Aesthetics, LLC ("Arora"), an independently licensed clinical practice located at 300 Lenora Street, Seattle, WA 98121 (www.arora-health.com). Arora is the HIPAA Covered Entity for clinical PHI, medical records, prescriptions, and treatment relationships.
Bask Health, Inc. ("Bask") serves as Arora's Business Associate and operates the patient portal at my.zanason.com, the clinical workflow, and payment processing on Arora's behalf under a written Business Associate Agreement.
Arora has designated Zanason LLC as its HIPAA Privacy Officer. Patients who wish to exercise the HIPAA rights described in this Notice — including rights regarding their Arora medical records — should contact Zanason's Privacy Officer at hola@zanason.com with the subject line "HIPAA Request."
This Notice describes how Arora may use and disclose your PHI to carry out treatment, payment, or healthcare operations and for other purposes that are permitted or required by law. This Notice also describes your rights regarding your PHI. Arora is required by law to maintain the privacy of your PHI, provide you with this Notice of its legal duties and privacy practices, and to abide by the terms of this Notice.
Uses and Disclosures of PHI
Arora may use and disclose your PHI for the following purposes:
a. Treatment: Arora may use and disclose your PHI to provide, coordinate, or manage your healthcare and related services. This may include communication with other healthcare providers about your treatment and coordinating your care with other providers.
b. Payment: Arora may use and disclose your PHI to obtain payment for healthcare services provided to you. This may include billing and collection activities, and sharing PHI with other healthcare providers or collection agencies.
c. Healthcare Operations: Arora may use and disclose your PHI for healthcare operations, including quality assessment, improvement activities, case management, accreditation, licensing, credentialing, and conducting or arranging for medical reviews, audits, or legal services.
d. As Required by Law: Arora may use and disclose your PHI when required to do so by federal, state, or local law.
e. Public Health and Safety: Arora may use and disclose your PHI to prevent or control disease, injury, or disability, to report child abuse or neglect, to report reactions to medications or problems with products, and to notify persons who may have been exposed to a communicable disease or may be at risk of spreading a disease or condition.
f. Health Oversight Activities: Arora may disclose your PHI to health oversight agencies for activities authorized by law, such as audits, investigations, inspections, and licensure.
g. Judicial and Administrative Proceedings: Arora may disclose your PHI in response to a court or administrative order, subpoena, discovery request, or other lawful process.
h. Law Enforcement: Arora may disclose your PHI for law enforcement purposes, such as to report certain types of wounds or injuries, or to comply with a court order, warrant, or other legal process.
i. Research: Arora may use and disclose your PHI for research purposes when the research has been approved by an institutional review board and privacy protections are in place.
j. Organ and Tissue Donation: If you are an organ donor, Arora may disclose your PHI to organizations that handle organ procurement, transplantation, or donation.
k. Military and Veterans: If you are a member of the armed forces, Arora may disclose your PHI as required by military authorities.
l. Inmates: If you are an inmate, Arora may disclose your PHI to the correctional institution or law enforcement official having custody of you.
Your Rights Regarding PHI
You have the following rights with respect to your PHI. To exercise any of these rights, contact Arora's designated Privacy Officer (Zanason LLC) at hola@zanason.com with the subject line "HIPAA Request."
a. Right to Inspect and Copy: You have the right to inspect and copy the PHI Arora maintains about you, with certain exceptions. To request access, submit a written request to the Privacy Officer. Arora may charge a reasonable fee for the costs of copying, mailing, or other supplies associated with your request.
b. Right to Amend: You have the right to request an amendment to your PHI if you believe it is incorrect or incomplete. To request an amendment, submit a written request to the Privacy Officer, specifying the information you believe is incorrect and why. Arora may deny your request if it believes the information is accurate and complete, or if Arora did not create the information.
c. Right to an Accounting of Disclosures: You have the right to request an accounting of disclosures of your PHI made by Arora in the past six years, except for disclosures made for treatment, payment, or healthcare operations, and certain other disclosures. To request an accounting, submit a written request to the Privacy Officer.
d. Right to Request Restrictions: You have the right to request a restriction on Arora's use or disclosure of your PHI for treatment, payment, or healthcare operations. Arora is not required to agree to your request but will consider it. To request a restriction, submit a written request to the Privacy Officer, specifying the restriction you are requesting and to whom it applies.
e. Right to Request Confidential Communications: You have the right to request that Arora communicate with you about your PHI in a certain way or at a certain location. To request confidential communications, submit a written request to the Privacy Officer, specifying how or where you wish to be contacted.
f. Right to a Paper Copy of This Notice: You have the right to receive a paper copy of this Notice, even if you have agreed to receive it electronically. To obtain a paper copy of this Notice, contact the Privacy Officer.
g. Right to be Notified of a Breach: You have the right to be notified in the event that Arora discovers a breach of your PHI.
Transmission of PHI
Arora, Bask, and Zanason are committed to protecting the privacy of your PHI and will ensure that any electronic transmission of PHI complies with the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule (45 CFR 164). This includes the use of Secure-Socket Layer (SSL) or equivalent technology for the transmission of PHI, as well as adherence to all applicable security standards for online transmissions of PHI.
Changes to This Notice
Arora reserves the right to change this Notice and the revised Notice will be effective for PHI Arora already has about you, as well as any information Arora receives in the future. The current Notice will be posted on zanason.com and the Notice will contain the effective date on the first page.
Complaints
If you believe your privacy rights have been violated, you may file a complaint with Arora's designated Privacy Officer (Zanason LLC) at hola@zanason.com, or with the Secretary of the Department of Health and Human Services. You will not be retaliated against for filing a complaint.
Contact Information
To exercise any of your rights under this Notice, or if you have any questions about this Notice or these privacy practices, please contact Arora's designated Privacy Officer at:
Zanason LLC (designated Privacy Officer for Arora Health & Aesthetics, LLC)
8 The Green #26118
Dover, DE 19901
zanason.com
hola@zanason.com — subject line: "HIPAA Request"
Arora Health & Aesthetics, LLC may also be reached directly at 300 Lenora Street, Seattle, WA 98121 or medicalcompliance@arorahealthgroup.com.
This Notice is provided in accordance with the Notice of Privacy Practices for Protected Health Information from the Department of Health and Human Services' Model and is applicable across all US states.
Rights of Specific Jurisdictions within the US
Certain states may have additional privacy protections that apply to your PHI. The following is an example of specific rights in the state of California. If you reside in a state with additional privacy protections, you may have additional rights related to your PHI.
California Residents
a. Right to Access: In addition to the rights described above, California residents have the right to request access to their PHI in a readily usable electronic format, as well as any additional information required by California law. To request access, submit a written request to our Privacy Officer.
b. Right to Restrict Certain Disclosures: California residents have the right to request restrictions on certain disclosures of their PHI to health plans if they paid out-of-pocket for a specific healthcare item or service in full. To request such a restriction, submit a written request to our Privacy Officer.
c. Confidentiality of Medical Information Act (CMIA): California residents are protected by the Confidentiality of Medical Information Act (CMIA), which provides additional privacy protections for medical information. We are required to comply with CMIA in addition to HIPAA.
d. Marketing and Sale of PHI: California residents have the right to request that their PHI not be used for marketing purposes or sold to third parties without their authorization. To request a restriction on the use of your PHI for marketing or the sale of your PHI, submit a written request to our Privacy Officer.
e. Minor's Rights: If you are a minor (under the age of 18), you have the right to request that certain information related to certain sensitive services, such as reproductive health, mental health, or substance use disorder treatment, not be disclosed to your parent or guardian without your consent. To request a restriction on the disclosure of such information, submit a written request to our Privacy Officer.
If you reside in a state other than California, please consult your state's specific privacy laws for information about any additional rights you may have regarding your PHI. You may also contact our Privacy Officer for more information about your rights under specific state laws.
Zanason LLC Privacy Policy: Notice of Privacy Practices for PHI — State-Specific Provisions
In addition to the privacy practices described in our Notice of Privacy Practices for Protected Health Information, we comply with applicable state-specific privacy laws related to PHI.
The following are examples of a few states with additional privacy protections:
New York
For residents of New York, we comply with the New York State Confidentiality of Information Law, which provides additional privacy protections for HIV-related information, mental health records, and genetic testing results. We will obtain written consent before disclosing such information, even for treatment, payment, or healthcare operations.
Texas
For residents of Texas, we comply with the Texas Medical Privacy Act, which offers privacy protections beyond HIPAA, including requiring consent for certain disclosures of PHI, additional safeguards for electronic PHI, and specific requirements for the destruction of PHI. We also adhere to Texas's specific privacy protections for mental health records and substance use treatment records.
Florida
For residents of Florida, we comply with Florida's privacy laws, which offer additional protections for mental health records, HIV/AIDS-related information, and substance abuse treatment records. We will obtain written consent before disclosing such information, even for treatment, payment, or healthcare operations. We also implement specific security measures to protect electronic PHI, as required by Florida law.
Illinois
For residents of Illinois, we comply with Illinois's specific privacy laws related to mental health records, HIV/AIDS-related information, and genetic testing results. We will obtain written consent before disclosing such information, even for treatment, payment, or healthcare operations. In addition, we will notify patients of any unauthorized access to their electronic PHI, as required by Illinois law.
Massachusetts
For residents of Massachusetts, we comply with Massachusetts's specific privacy laws related to mental health records, HIV/AIDS-related information, and genetic testing results. We will obtain written consent before disclosing such information, even for treatment, payment, or healthcare operations. We also implement specific security measures to protect electronic PHI, as required by Massachusetts law.
California
For residents of California, we comply with the Confidentiality of Medical Information Act (CMIA), as well as California's specific privacy laws related to marketing, sale of PHI, and minors' rights. We will obtain written consent before disclosing certain information and adhere to additional privacy protections, as required by California law.