Notice of Privacy Practices

Effective Date: July 7, 2026

 

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

 

WHO WE ARE

 

This Notice of Privacy Practices describes the privacy practices of Arora Health and Aesthetics LLC, an affiliated group of physician-owned professional corporation and the members of its Affiliated Covered Entity (collectively “we” or “our”).

 

When HIPAA applies, we have an Affiliated Covered Entity that shares your Protected Health Information (PHI) among members for treatment, payment, and healthcare operations purposes. For a list of members, please contact Genesis Health Solutions LLC, contact information below.

 

WHAT PROTECTED HEALTH INFORMATION (PHI) IS

 

"Protected health information" or "PHI" is information about you, including demographic information, that may identify you and that relates to your past, present, or future physical or mental health or condition, treatment, or payment for healthcare services.

 

USES AND DISCLOSURES OF PROTECTED HEALTH INFORMATION

 

We may use and disclose PHI for the following purposes:

 

TREATMENT: We will use and disclose your PHI to provide, coordinate, or manage your healthcare. This includes coordination with third-party providers, sharing information with specialists you've been referred to, communicating with pharmacies, and ordering laboratory testing.

 

PAYMENT: As a cash-based practice, we do not bill insurance companies, health plans, or third-party payers. We may use your PHI to process direct payments, manage billing and accounting, and handle payment-related inquiries.

 

HEALTHCARE OPERATIONS: We may use or disclose PHI to support business activities, including quality improvement, case management, staff training, legal services, auditing, compliance programs, and IT system maintenance.

 

APPOINTMENT REMINDERS: We may contact you by text, phone, or email regarding appointments, follow-up visits, or required lab work.

 

USES AND DISCLOSURES THAT DO NOT REQUIRE YOUR AUTHORIZATION

 

We may use or disclose your PHI without your authorization in these circumstances:

 

  • As required by federal, state, or local law
  • Public health activities (disease reporting, FDA adverse event reporting, product recalls)
  • Health oversight activities (audits, investigations, licensing)
  • Reporting abuse, neglect, or domestic violence as required by law
  • Judicial and administrative proceedings (court orders, subpoenas)
  • Law enforcement purposes (limited disclosures as required by law)
  • Coroners, medical examiners, funeral directors, and organ donation agencies
  • Serious threat to health or safety of person or public
  • Essential government functions (national security, protective services)
  • Workers' compensation (as authorized by law)
  • Research (under certain conditions with IRB approval)

 

We must make certain disclosures to you upon request and to the Secretary of HHS to investigate our HIPAA compliance.

 

USES AND DISCLOSURES THAT REQUIRE YOUR AUTHORIZATION

 

Other uses and disclosures will be made only with your written consent or authorization. You may revoke an authorization at any time in writing, except to the extent we have taken action in reliance on it.

 

Without your authorization, we are prohibited from using or disclosing your PHI for marketing purposes.

 

GENESIS HEALTH SOLUTIONS, LLC DOES NOT SELL YOUR PROTECTED HEALTH INFORMATION TO ANY THIRD PARTY UNDER ANY CIRCUMSTANCES.

 

YOUR RIGHTS REGARDING PROTECTED HEALTH INFORMATION

 

You have the following rights:

 

RIGHT TO INSPECT AND COPY: You may inspect and obtain a copy of your PHI maintained in a designated record set. Submit a written request. We will respond within 30 days (with one 30-day extension possible if notified). A reasonable, cost-based fee may apply. State laws requiring shorter timelines will be honored where applicable.

 

RIGHT TO AMEND: You may request amendment of PHI you believe is incorrect or incomplete. Submit a written request with explanation. We will respond within 60 days. If denied, you may file a statement of disagreement.

 

RIGHT TO REQUEST RESTRICTIONS: You may request restrictions on how we use or disclose PHI for treatment, payment, or healthcare operations. Your request must be in writing stating the specific restriction and who it applies to. We are not required to agree unless: (1) the disclosure is to a health plan for payment/operations regarding a service paid in full out-of-pocket, OR (2) HIPAA requires the restriction. We may accommodate other requests at our discretion.

 

RIGHT TO CONFIDENTIAL COMMUNICATIONS: You may request to receive confidential communications by alternative means or at an alternative location. Submit a written request specifying how or where you want communications. We will comply with all reasonable requests.

 

RIGHT TO AN ACCOUNTING OF DISCLOSURES: You may request a list of certain PHI disclosures made in the past six (6) years, except for disclosures for treatment, payment, healthcare operations, authorizations, or certain other purposes. Submit a written request. The first request within one year is free; subsequent requests may incur a reasonable, cost-based fee.

 

RIGHT TO A PAPER COPY: You may obtain a paper copy of this Notice at any time, even if you agreed to receive it electronically.

 

RIGHT TO BREACH NOTIFICATION: We will notify you if a reportable breach of unsecured PHI is discovered. See Breach Notification section below.

 

RIGHT TO FILE A COMPLAINT: Complaints about this Notice or how we handle your PHI should be directed to our Privacy Officer. You may also submit a formal complaint to the U.S. Department of Health and Human Services, Office for Civil Rights:

 

 

We will not retaliate against you for filing a complaint.

 

STATE-SPECIFIC PROVISIONS

 

Where state law provides greater protections than HIPAA, we will comply with the stricter standard:

 

Texas (HB 300): Prior written authorization required for electronic PHI disclosure (with exceptions); role-based workforce training; 30-day breach notification.

 

Florida (§ 501.171): 30-day breach notification from discovery.

 

New York (SHIELD Act): Electronic records access within 10 business days; breach notification without unreasonable delay.

 

Illinois (BIPA): Telehealth video biometric data is covered under HIPAA healthcare treatment exemption; no sale or commercial use outside treatment. Prior consent obtained for any collection outside HIPAA scope.

 

State Breach Notification Timelines:

 

State Timeline
Florida 30 days
Ohio 45 days
Vermont 45 days
North Carolina 45 days
New York Without unreasonable delay
California Most expedient

 

SECURITY STANDARDS

 

We transmit PHI electronically during virtual visits and related communications. Protective measures include:

 

  • Encryption: PHI encrypted in transit (TLS 1.2+)
  • HIPAA Security Rule: Administrative, physical, and technical safeguards
  • SOC 2 Type II: Independently audited security controls
  • HL7 Interoperability Standards: Secure electronic health information exchange
  • Business Associate Agreements: All third-party service providers sign written BAAs

 

No electronic transmission is completely secure. Use private internet connections and ensure privacy during telehealth appointments.

 

BREACH NOTIFICATION

 

In the event of a breach of your unsecured PHI:

 

HIPAA Timeline: We will notify you within 60 days of discovery. Where state law requires shorter timelines (see above), we will comply with the stricter standard.

 

Content of Notification:

 

  • Description of what happened (date of breach and discovery)
  • Types of PHI involved
  • Steps you can take to protect yourself
  • Actions we are taking to investigate and remediate
  • Contact procedures for questions

 

Notification Methods: First-class mail, email (if previously agreed), website posting (if insufficient contact info), or media outlets (for breaches affecting 500+ residents).

 

Breaches of 500+ Individuals: Media notification and simultaneous HHS Secretary notification.

 

Smaller Breaches (<500): Annual log submitted to HHS within 60 days after calendar year-end.

 

REVISIONS TO THIS NOTICE

 

We reserve the right to revise this Notice. Changes will apply to PHI we already have about you as well as information received in the future. Significant changes will be posted on our website with an updated effective date. You may request a copy of the current Notice at any time.

 

CONTACT INFORMATION

 

Genesis Health Solutions, LLC 

 

Attention: HIPAA Privacy

 

30 N Gould St, #51485 Sheridan, WY 82801 

 

Email: support@gen3health.com 

 

Phone: 877-343-8004

 

We will maintain the privacy of your protected health information and will notify affected individuals following a breach of unsecured protected health information as required by law.

 

© 2026 Genesis Health Solutions, LLC. All rights reserved.

Veteran-owned telehealth for people carrying a heavy load. We provide clear, personalized care for testosterone, hormones, weight loss, and more — no jargon, no hidden fees, no guesswork. Just straightforward guidance and real results.

Subscribe to Our Newsletter.

Genesis Health Solutions © 2026 All Rights Reserved.