Email Address hello@onetreehealth.com
Office Working Time Monday–Friday | 8AM–5PM
Contact Number (615) 696-9900
Notice of Privacy Practices

Your information, protected.

This notice describes how medical information about you may be used and disclosed, and how you can get access to this information. Please review it carefully — at OneTreeHealth, protecting your privacy is a foundational part of the care we provide.

Effective Date
January 1, 2026
Last Revised
May 27, 2026
Governing Law
HIPAA · 45 CFR 160 & 164
Applies To
All OneTreeHealth Patients
Section 01

How patient information is used.

OneTreeHealth collects and maintains Protected Health Information (PHI) to provide you with safe, coordinated, and effective care. Below are the routine ways your information is used inside our practice — none of which require your separate written authorization, because they are permitted by the federal HIPAA Privacy Rule.

For treatment

Your information is shared among the clinicians who care for you — neurologists, neurosurgeons, pain management specialists, orthopedic surgeons, nurses, medical assistants, and consulting physicians — so we can coordinate diagnosis, develop your treatment plan, write prescriptions, and follow you through recovery.

For payment

We may use and disclose your PHI to obtain payment for the services we provide. This includes verifying insurance eligibility, submitting claims, providing diagnosis and procedure codes to your insurer, and coordinating with attorneys when care is provided under a medical lien.

For healthcare operations

We use your information internally to run our practice — quality assessment, staff training, accreditation, credentialing, care reviews, legal services, and business planning. We use only the minimum information necessary to perform these functions.

For appointment reminders and care communications

We may contact you by phone, text, email, or mail to confirm appointments, share follow-up instructions, deliver test results through the patient portal, or inform you of services that may benefit your care.

Important

Other uses — such as marketing communications, the sale of PHI, or most disclosures of psychotherapy notes — require your written authorization. You may revoke any authorization in writing at any time.

Section 02

Storage and disclosure practices.

We take the protection of your records seriously. Your PHI is stored using industry-standard administrative, physical, and technical safeguards designed to keep it confidential, accurate, and available only to those who need it for your care.

How records are stored

  • Electronic records are maintained in HIPAA-compliant systems with encryption at rest and in transit, role-based access controls, multi-factor authentication, and continuous audit logging.
  • Paper records, where they exist, are kept in locked storage in access-controlled areas of our facility.
  • Backups and disaster recovery systems are encrypted and tested regularly to safeguard against data loss.
  • Workforce training on privacy and security is required for every team member annually, and on hire.

Disclosures that may be made without your authorization

The HIPAA Privacy Rule permits us — and sometimes requires us — to disclose your PHI in specific situations, including:

  • Public health activities — reporting communicable disease, child abuse or neglect, and adverse events to the FDA.
  • Health oversight — audits, investigations, and licensure activities by government agencies.
  • Judicial and administrative proceedings — in response to a valid court order, subpoena, or discovery request.
  • Law enforcement — under limited circumstances permitted by law, such as identifying a suspect or reporting a crime.
  • To avert a serious threat to the health or safety of a person or the public.
  • Workers' compensation — as required to comply with state workers' compensation laws.
  • Coroners, medical examiners, and funeral directors — to carry out their duties.
  • Military, national security, and correctional institutions — where required by federal law.
  • Business associates — vendors that perform services on our behalf (billing, IT, legal) are bound by written agreements to safeguard your information.

Retention & disposal

We retain medical records in accordance with Tennessee state law and applicable federal requirements. When records are no longer required, they are destroyed using secure shredding (paper) or certified data destruction (electronic media) so that PHI cannot be reconstructed.

Section 03

Your rights as a patient.

Under HIPAA, you have specific rights regarding the health information OneTreeHealth maintains about you. You may exercise any of these rights by submitting a written request to our Privacy Officer (see contact details below). We will respond within the timeframes required by federal law.

01

Right to inspect & copy

You may inspect and obtain a copy of the PHI we maintain about you, in paper or electronic format, subject to limited exceptions.

02

Right to amend

If you believe information in your record is incorrect or incomplete, you may request that we amend it. We may deny the request in specific circumstances and will explain why in writing.

03

Right to an accounting

You may request a list of certain disclosures we have made of your PHI in the six years prior to the date of your request.

04

Right to request restrictions

You may ask us to restrict how we use or disclose your PHI for treatment, payment, or operations. We are not required to agree, except where you pay for a service in full out of pocket.

05

Right to confidential communications

You may request that we communicate with you about medical matters in a specific way (for example, by mail rather than phone) or at a specific location.

06

Right to a paper copy

You may request a paper copy of this Notice at any time, even if you have agreed to receive it electronically.

07

Right to be notified of a breach

If a breach of your unsecured PHI occurs, you have the right to be notified in writing without unreasonable delay.

08

Right to choose someone to act for you

If you have given someone medical power of attorney, or if someone is your legal guardian, that person can exercise your rights and make choices about your information.

09

Right to file a complaint

You may file a complaint with OneTreeHealth or directly with the U.S. Department of Health and Human Services without fear of retaliation.

Section 04

Breach notification.

In the unlikely event of a breach involving unsecured PHI, OneTreeHealth will notify affected patients in writing within 60 days of discovery, as required by the HIPAA Breach Notification Rule. Notice will describe what happened, the types of information involved, steps you can take to protect yourself, what we are doing to investigate and prevent recurrence, and how to contact us with questions.

For breaches affecting more than 500 individuals, we will also notify prominent media outlets and the U.S. Department of Health and Human Services within the timeframes required by law.

Section 05

Changes to this notice.

We reserve the right to change the terms of this Notice and to make the revised Notice effective for all PHI we maintain, including information created or received before the change. When this Notice is materially revised, the new version will be posted in our office and on the OneTreeHealth website. The effective date appears at the top of this Notice.

You may request a copy of the current Notice at any visit, or by contacting our Privacy Officer.

Section 06

Filing a complaint.

If you believe your privacy rights have been violated, you may file a complaint with OneTreeHealth by contacting our Privacy Officer (details in the contact section below). You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights:

  • Mail: 200 Independence Avenue, S.W., Room 509F, HHH Building, Washington, D.C. 20201
  • Phone: 1-877-696-6775
  • Online: www.hhs.gov/ocr/privacy/hipaa/complaints/
No retaliation

OneTreeHealth will never retaliate against you for filing a complaint. Your access to care, treatment plan, and standing as a patient will not be affected in any way.

HIPAA Privacy Statement

Bound by law, guided by trust.

OneTreeHealth is a covered entity under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), and we comply with the HIPAA Privacy Rule (45 CFR Part 164, Subpart E), the Security Rule (Subpart C), and the Breach Notification Rule (Subpart D). We are required by law to maintain the privacy of your Protected Health Information, to provide you with this Notice of our legal duties and privacy practices regarding PHI, to notify you following a breach of unsecured PHI, and to follow the terms of the Notice currently in effect.

Our commitment goes beyond what the law requires. Every clinician, staff member, and business associate at OneTreeHealth is trained, accountable, and personally committed to protecting your information — because the trust you place in us is the foundation of your care.

HIPAA Compliant · Covered Entity
Contact Information

Questions? Reach our Privacy Officer.

For questions about this Notice, requests to exercise your rights, or to file a complaint directly with our practice, please contact our designated Privacy Officer. We respond to all written requests within the timeframes required by HIPAA.

You may also stop by our front desk during business hours — Monday through Friday, 8AM to 5PM — and our team will be happy to assist.

Privacy Officer

OneTreeHealth Privacy & Compliance
HIPAA Privacy Officer · Records Custodian
Address
397 Wallace Rd, Suite #303
Nashville, TN 37211
Hours
Monday – Friday
8:00 AM – 5:00 PM CT
Response
Within 30 days (HIPAA standard)
Acknowledgment of Notice

Care begins with your consent.

You may be asked to sign an acknowledgment that you have received a copy of this Notice. Signing the acknowledgment does not waive any of your rights — it simply confirms that you have received it. If you have any questions before signing, please let us know.

Contact Our Privacy Officer