Office Privacy Policy
Privacy Policy and Protection of Protected Health Information (PHI)
Effective Date: August 5, 2026
At Putnam Orthodontics, we are committed to protecting the privacy and confidentiality of our patients’ Protected Health Information (PHI). This Privacy Policy describes how we collect, use, disclose, safeguard, and protect your health information in accordance with the Health Insurance Portability and Accountability Act (HIPAA) and other applicable federal and state laws.
Our Commitment to Privacy
We understand that your medical and dental information is personal. We are dedicated to maintaining the privacy and security of your PHI and have implemented administrative, physical, and technical safeguards to protect it from unauthorized access, use, or disclosure.
What Is Protected Health Information (PHI)?
Protected Health Information (PHI) includes information that identifies you and relates to:
Your past, present, or future physical or mental health.
The health care services you receive.
Payment for your health care services.
PHI may exist in electronic, paper, or verbal form.
How We Use and Disclose PHI
We may use or disclose your PHI for the following purposes without your written authorization:
Treatment
To provide, coordinate, and manage your dental care.
To consult with specialists, laboratories, pharmacies, or other healthcare providers involved in your treatment.
Payment
To bill and collect payment from you, your insurance company, or another responsible party.
To verify insurance benefits and obtain prior authorizations.
Health Care Operations
Quality improvement activities.
Staff training and education.
Licensing, accreditation, and compliance activities.
Appointment scheduling and patient communications.
Business management and administrative functions.
Other Permitted or Required Disclosures
We may disclose PHI when required or permitted by law, including:
Public health reporting.
Law enforcement requests as authorized by law.
Judicial or administrative proceedings.
Workers’ compensation claims.
Health oversight agencies.
To prevent or lessen a serious threat to health or safety.
As otherwise required by federal or state law.
Disclosures Requiring Your Authorization
Except as permitted by law, we will obtain your written authorization before:
Releasing records to third parties for purposes not otherwise permitted by HIPAA.
Using your information for marketing where authorization is required.
Selling your PHI.
Other uses and disclosures that require authorization under applicable law.
You may revoke your authorization at any time in writing, except to the extent action has already been taken based on your authorization.
Patient Rights
You have the right to:
Receive a copy of this Privacy Policy.
Request access to your dental records.
Request copies of your records in accordance with applicable law.
Request corrections or amendments to your records if you believe they are inaccurate or incomplete.
Request restrictions on certain uses or disclosures of your PHI.
Request confidential communications by alternative means or at alternative locations.
Receive an accounting of certain disclosures of your PHI.
File a complaint if you believe your privacy rights have been violated without fear of retaliation.
Safeguarding Your Information
Our practice protects PHI by implementing:
Secure electronic health record systems.
Password-protected devices and user access controls.
Encryption where appropriate.
Physical safeguards for paper records.
Employee confidentiality agreements.
HIPAA privacy and security training for workforce members.
Procedures for responding to potential security incidents and data breaches.
Access to PHI is limited to workforce members and authorized business associates who need the information to perform their job responsibilities.
Business Associates
We may share PHI with trusted vendors or service providers who perform functions on our behalf. These organizations are required by law and contract to protect your PHI and may use it only for authorized purposes.
Electronic Communications
If you choose to communicate with us by email, text message, or other electronic methods, there may be some risk that the information could be accessed by unauthorized individuals. Where appropriate, we use secure communication methods and will obtain any necessary consent before communicating electronically.
Data Retention
We retain patient records in accordance with applicable federal and state laws and professional record-retention requirements. Records are securely disposed of when they are no longer required to be retained.
Breach Notification
If a breach of unsecured PHI occurs that affects your information, we will notify you as required by HIPAA and applicable law.
Changes to This Privacy Policy
We reserve the right to modify this Privacy Policy at any time. Updated versions will be available in our office and will apply to all PHI maintained by the practice unless otherwise required by law.
Contact Information
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact:
Privacy Officer: Jaime Bretti
Dental Practice: Putnam Orthodontics
Address:
Carmel:
667 Stoneleigh Ave, Ste 207, Carmel Hamlet, NY 10512
Briarcliff:
1868 Pleasantville Rd, Briarcliff Manor, NY 10510, USA
Jefferson Valley:
3630 Hill Blvd STE 405, Jefferson Valley, NY 10535, USA
Phone: (914) 962-9600
Filing a Complaint
If you believe your privacy rights have been violated, you may file a complaint with our Privacy Officer or with the U.S. Department of Health and Human Services, Office for Civil Rights. Filing a complaint will not affect the quality of care you receive.
By receiving dental services from our practice, you acknowledge that you have been offered access to our Notice of Privacy Practices as required by HIPAA.
One important distinction: under HIPAA, patients must be provided with a Notice of Privacy Practices (NPP) that contains specific required elements. A general “privacy policy” alone does not satisfy that requirement. If you need a document for patient intake or your website, I can also draft a HIPAA-compliant Notice of Privacy Practices that includes all required disclosures and acknowledgment language.