Privacy Notice for Injured Workers
For Injured Workers, Claimants, and Individuals Whose Health Information We Handle
Who This Notice Covers
This Notice is issued jointly by PriMedical, Inc. and PriCare, Inc. d/b/a PriMed Solutions (together, the “Company,” “we,” “us,” or “our”). Both entities may receive, maintain, and use your protected health information (PHI) in connection with workers’ compensation medical case management services, and both are bound by the practices described in this Notice.
Important: Understanding Our Role in Your Case
The Company is a workers' compensation medical case management company. We do NOT provide direct medical treatment. Your treating physicians and healthcare providers are your actual medical care providers.
Why We Have Your Information: The Company is retained by workers' compensation insurance carriers to coordinate and facilitate your medical care. Your insurance carrier obtained authorization for medical record release to us (often via standard authorization forms executed at claim inception). We receive, maintain, and use your PHI to perform case management services.
How HIPAA Applies: Workers’ compensation insurers are not health plans under HIPAA, and PriMedical is not a health plan. Even so, we receive health information from nurse case managers and, electronically, from healthcare providers, and we handle all of it to HIPAA privacy and security standards. Where a specific arrangement makes us a business associate of a HIPAA covered entity, the business associate agreement for that arrangement also applies.
This Notice explains how we use, share, and protect that information, and the rights we offer you. If you have a question about how it applies to your claim, contact our Privacy Officer (Section 13).
1. Our Commitments
Whether or not HIPAA applies to a particular claim, the Company will:
- Maintain the privacy of your PHI using appropriate administrative, physical, and technical safeguards
- Provide this Notice describing our privacy practices for your health information
- Follow the terms of this Notice currently in effect
- Notify you of a breach of your unsecured health information as required by applicable law
- Permit you to exercise your rights regarding PHI as described below
- Document privacy-related activities and maintain records as required by law
2. How We May Use and Disclose Your Health Information
2.1 For Treatment Facilitation (Care Coordination)
| Use | Example |
|---|---|
| Provider Communication | Communicating with treating physicians about your case status, treatment progress, and care coordination needs |
| Specialist Referrals | Arranging referrals to specialists when indicated by your case needs |
| IME Coordination | Scheduling and coordinating independent medical examinations |
| Care Planning | Developing and communicating comprehensive care plans |
| Return-to-Work Facilitation | Coordinating with providers on work restrictions and transitional duty programs |
2.2 For Payment Purposes
- Billing insurance carriers for case management services
- Processing and verifying claim authorizations
- Coordinating with adjusters regarding treatment approval
- Responding to payment-related inquiries from carriers
- Verifying coverage and eligibility for authorized services
2.3 For Healthcare Operations
| Operation | Purpose |
|---|---|
| Quality Improvement | Assessing the effectiveness of our case management services |
| Peer Review | Evaluating case manager performance and clinical appropriateness |
| Compliance Auditing | Monitoring adherence to HIPAA and state regulations |
| Business Management | Planning and management of Company operations |
| Training | Educating staff on HIPAA compliance and case management protocols (using de-identified information where feasible) |
2.4 Workers' Compensation Disclosures (45 CFR §164.512(l))
Without your individual authorization, we may disclose your PHI as necessary to comply with workers' compensation laws and similar programs, including to:
| Recipient | Purpose |
|---|---|
| Workers' compensation insurance carriers | Claim administration, treatment authorization |
| Self-insured employer representatives | Claim oversight, return-to-work coordination |
| State workers' compensation boards | Regulatory reporting, adjudication proceedings |
| Third-party administrators (TPAs) | Claims processing and oversight |
| Vocational rehabilitation providers | Job placement and transitional duty coordination |
| Defense counsel (in proceedings) | Litigation support related to your claim |
These disclosures are permitted by federal HIPAA regulations specifically for workers' compensation contexts. State-specific workers' compensation statutes may impose additional requirements or limitations (see Section 9).
2.5 Return-to-Work Program Coordination
We may use and disclose limited PHI to facilitate your return to employment, including communicating work restrictions and functional capacity to employers (applying the minimum-necessary standard), coordinating transitional duty assignments, and sharing work status reports with authorized parties to your claim. We limit these disclosures to only the information necessary to accomplish return-to-work objectives.
3. Other Uses and Disclosures Allowed by Law
3.1 Required by Law
- Mandatory disease reporting to public health authorities
- Required regulatory filings with workers' compensation boards
- Court orders or subpoenas (subject to appropriate legal review)
- Law enforcement requests meeting regulatory criteria
3.2 Public Health Activities
- Reporting communicable diseases to health departments
- Adverse event reporting to the FDA
- Exposure notifications where permitted by law
3.3 Health Oversight Activities
- Responding to audits or investigations by oversight agencies
- Licensing and accreditation reviews
- Medicare/Medicaid program oversight (where applicable)
3.4 Judicial and Administrative Proceedings
- Responses to court orders from workers' compensation tribunals
- Discovery requests in litigation (with appropriate legal review and safeguards)
- Depositions and hearings related to your claim
3.5 Law Enforcement Purposes
Under limited circumstances, PHI may be disclosed for law enforcement purposes consistent with 45 CFR §164.512(f).
3.6 To Avert Serious Threats
If we determine there is a serious and imminent threat to health or safety, we may disclose PHI to prevent or lessen that threat, consistent with applicable law and ethics.
5. Your Rights Regarding Your Health Information
We offer the rights below to every injured worker whose health information we handle, whether or not HIPAA applies to the claim. State law may give you additional rights. To exercise any right below, submit a written request to our Privacy Officer.
5.1 Right to Inspect and Obtain Copies
Submit a written request to the Privacy Officer. We will respond within 30 days (one 30-day extension possible with written notice). We may charge reasonable, cost-based fees for copies and postage; there is no fee for processing access requests. Access may be denied in certain circumstances (e.g., PHI compiled for anticipated litigation); if denied, you may request review by a licensed healthcare professional designated by the Company.
5.2 Right to Request Amendments
Submit a written request specifying the amendment and rationale. We have 60 days to act, with one 30-day extension possible. We may deny the request if the information was not created by us, is not part of our designated record set, or is already accurate and complete; if denied, you may submit a statement of disagreement for inclusion in your record.
5.3 Right to an Accounting of Disclosures
You may request a list of PHI disclosures the Company made in the past six years, except as noted in 45 CFR 164.528(a)(1). This excludes disclosures for treatment, payment, or healthcare operations; disclosures to you or with your authorization; national security/intelligence disclosures; disclosures to correctional institutions/law enforcement custodians; and disclosures prior to April 14, 2003 (or the applicable compliance date). The first accounting in a 12-month period is free; subsequent requests may incur reasonable cost-based fees. We will respond within 60 days, with one 30-day extension possible.
5.4 Right to Request Restrictions
You may request restrictions on uses/disclosures of your PHI for treatment, payment, or operations purposes under 45 CFR 164.522(a), however, under 45 CFR 164.512(l), you do not have such right when the disclosure of medical information is required or authorized by law to comply with worker’s compensation or similar programs.
5.5 Right to Request Confidential Communications
You may request communication about your PHI via alternative means or locations (e.g., a specific phone number or mailing address). We will accommodate all reasonable requests; submit a written request specifying your preferred method or location.
5.6 Right to Receive a Paper Copy of This Notice
You may request a paper copy of this Notice at any time, even if you previously agreed to receive it electronically.
5.7 Right to Breach Notification
If there is a breach of your unsecured PHI, you have the right to written notification no later than 60 days after discovery, describing what occurred, the types of information involved, steps you can take to protect yourself, what the Company is doing in response, and contact information for questions.
5.8 Right to File Complaints
You may file complaints internally (Section 11.1) or with the U.S. Department of Health and Human Services Office for Civil Rights, without retaliation.
7. How We Protect Your Information
7.1 Administrative Safeguards
- Designated Privacy Officer and Security Officer
- Workforce HIPAA training upon hire and annually thereafter
- Access controls and role-based permissions
- Sanction policies for workforce violations
- Contingency planning and disaster recovery
- Regular risk assessments and compliance audits
7.2 Physical Safeguards
- Facility access controls at all Company offices
- Secure storage for physical records
- Workstation security policies
- Device and media disposal controls
7.3 Technical Safeguards
- Encryption of PHI at rest (AES-256)
- Encryption in transit (TLS 1.2+)
- Unique user authentication
- Automatic logoff and session timeout
- Audit logging and access monitoring
- Intrusion detection and prevention systems
8. Business Associate Agreements
When PHI is handled by vendors, subcontractors, or third parties performing functions on our behalf, the Company executes Business Associate Agreements (BAAs) consistent with 45 CFR §164.504(e). These agreements obligate business associates to protect PHI at HIPAA-required standards and report any breaches.
9. State-Specific Protections
Workers' compensation privacy requirements vary by state. The Company complies with federal HIPAA standards as a baseline and adheres to more stringent state requirements where applicable. If you have a question about how your state's law affects your claim, contact our Privacy Officer — we maintain internal jurisdiction-specific compliance guidance for every state in which we operate and will answer specific inquiries directly.
Illustrative Examples
| State | Enhanced Protection |
|---|---|
| California | Confidentiality of Medical Information Act (Civ. Code §§56–56.37); stricter consent requirements |
| Texas | Specific medical-records exchange requirements under the Texas Workers' Compensation framework |
| Florida | Chapter 440 provisions; specific timeframe mandates for record production |
| New York | WCB mandatory authorization language requirements |
| Illinois | Specific notice requirements for PHI disclosures |
10. No Retaliation Policy
The Company will NOT retaliate against you for filing a privacy complaint, exercising your HIPAA rights, participating in compliance investigations, or opposing privacy practices believed to be unlawful. Exercising your rights will not negatively impact the quality or nature of case management services you receive.
11. Complaints and Enforcement
11.1 Filing a Complaint With the Company
Privacy Officer, PriMedical, Inc., 5727 NW 7th Street, Suite #84, Miami, FL 33126. Phone: 888-370-0883. Email: privacy@primedicalinc.com
11.2 Filing a Complaint With HHS Office for Civil Rights
U.S. Department of Health and Human Services, Office for Civil Rights, 200 Independence Avenue SW, Washington, DC 20201. Online: https://ocrportal.hhs.gov/ocr/smartscreen/main.jsf. Phone: 1-877-696-6775.
11.3 Time Limits
Complaints should be filed within 180 days of when you knew or should have known of the alleged violation, though HHS may waive this deadline for good cause.
12. Notice Availability & Acknowledgment
This Notice is available on our website at https://primedicalinc.com/privacy/hipaa/ and is provided to injured workers and claimants at the first delivery of case management services. You may request a paper copy at any time (Section 5.6). We ask that you confirm receipt of this Notice where feasible; if you have questions about this Notice, contact our Privacy Officer (Section 13).
13. Contact Information
PriMedical, Inc.
5727 NW 7th Street, Suite #84, Miami, FL 33126
General Case Management — Phone: 888-370-0883 | Email: referral@primedicalinc.com
Privacy Officer: Frank Imperato | Email: privacy@primedicalinc.com | Phone: 888-370-0883
Privacy Office hours: Monday – Friday, 8:00 AM – 6:00 PM ET (referral intake is available 24/7)
PriCare, Inc. d/b/a PriMed Solutions
5727 NW 7th Street, Suite #84, Miami, FL 33126
General Case Management — Phone: 866-846-2442 | Email: info@primed-solutions.com
Privacy Officer: Frank Imperato | Email: privacy@primed-solutions.com | Phone: 866-846-2442
Privacy Office hours: Monday – Friday, 8:00 AM – 6:00 PM ET (referral intake is available 24/7)
14. Definitions
| Term | Definition |
|---|---|
| Protected Health Information (PHI) | Individually identifiable health information maintained or transmitted by the Company in any form or medium |
| Business Associate | A person/entity that performs functions involving PHI on behalf of the Company or a covered entity |
| Covered Entity | A health plan, healthcare clearinghouse, or healthcare provider subject to HIPAA |
| Designated Record Set | Records containing PHI used to make decisions about individuals |
| Minimum Necessary | Standard requiring limitation of PHI uses/disclosures to what is necessary |
| Treatment, Payment, Healthcare Operations (TPO) | The three primary categories of permitted PHI uses under HIPAA |
| Breach | Impermissible use or disclosure of unsecured PHI that compromises its security or privacy |
| Workers' Compensation | State-administered system providing benefits for work-related injuries/illnesses |
16. Revision History
| Version | Effective Date | Summary of Changes |
|---|---|---|
| Current | September 11, 2026 | Split from combined Privacy Policy; added joint-entity coverage, state-law updates; issued as a privacy notice for injured workers with a statement of how HIPAA applies |