Notice of Privacy Practices (HIPAA NPP)
Effective July 23, 2026 · Last updated September 1, 2026
Covered Entity: Nora Bassam Khoury, MD, PLLC, a Florida professional limited liability company doing business as Nomad Health (the "Practice," "we," "us," or "our")
Practice Address: 400 Arthur Godfrey Rd #200-01, Miami Beach, FL 33140
Privacy Officer: Steven A. Pino, Director of Clinical Operations
Contact: info@mynomadhealth.com · Tel (305) 680-0566, or by mail at the practice address above.
Website: https://mynomadhealth.com
Version: 1.2
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
(The capitalized header sentence above is required verbatim by 45 C.F.R. § 164.520(b)(1)(i).)
1. Who We Are and Our Legal Duties
Nomad Health is a direct primary care ("DPC") medical practice organized under Florida law. We provide primary care through telehealth visits (including video visits conducted inside our own patient portal), home visits within our service area, and related services — including school and sports physicals, laboratory testing performed in our office or ordered through an outside laboratory, and medications dispensed to you in our office by a Florida-registered dispensing practitioner.
We are required by law to:
- Maintain the privacy and security of your protected health information ("PHI");
- Provide you with this Notice of our legal duties and privacy practices with respect to your PHI;
- Notify you following a breach of your unsecured PHI, as required by the HIPAA Breach Notification Rule (45 C.F.R. Part 164, Subpart D) and, where applicable, the Florida Information Protection Act, § 501.171, Fla. Stat.;
- Follow the terms of the Notice currently in effect; and
- Not use or disclose your PHI other than as described in this Notice, unless you authorize it in writing.
"Protected health information" means information that identifies you (or could reasonably be used to identify you) and relates to your past, present, or future physical or mental health, the health care we provide to you, or payment for that care.
2. How We May Use and Disclose Your PHI Without Your Authorization
2.1 Treatment
We use and disclose your PHI to provide, coordinate, and manage your medical care. Examples specific to our practice:
- Our providers and clinical staff record your history, examinations, diagnoses, medications, allergies, clinical notes, visit summaries, and care plans in our electronic health record (EHR) system.
- Forms you complete and sign in the patient portal (intake, medical history, medications and allergies, consents, release-of-information requests, financial policy, and school/sports physical forms) are filed into your chart for review by our clinical staff.
- Some laboratory tests are performed by our own staff in our office during your visit. No specimen and no PHI leaves the practice for those tests; the result is entered directly into your chart.
- For tests sent out, we generate a lab requisition containing your name, date of birth, sex, phone, address, ordered tests, and diagnosis codes, which you present at the patient service center of the laboratory we direct you to (currently Finlay Clinical Laboratories and/or Quest Diagnostics) for specimen collection. That laboratory receives the PHI printed on that requisition. There is no electronic lab interface, so the requisition you carry and the result document our staff files into your chart are the only data flows.
- If your provider dispenses a medication to you in our office, we create a dispensing record and a container label as Florida law requires (§ 465.0276, Fla. Stat.), and file that record in your chart. We do not send it to any pharmacy benefit manager, prescription-history aggregator, or data broker. You may always choose to have a prescription filled at a pharmacy of your choice instead.
- If you authorize release of your records (for example, to a school or athletic association for a physical clearance, or to another provider), we disclose the records you authorize.
2.2 Payment
We use and disclose PHI to obtain payment for services. Because we are a self-pay, membership-based practice that does not bill health insurance, payment uses are limited. Examples:
- We generate invoices and receipts for visits and services, which identify you and the services provided.
- Membership and per-service payments are processed by our payment processor (Stripe, Inc.). We do not send your clinical records to the payment processor; the processor receives the information needed to process your payment (such as your name, email, payment card details you enter on the processor's own hosted checkout page, and the product/membership tier purchased).
2.3 Health Care Operations
We use and disclose PHI for our internal operations, such as quality review, co-signature review of clinical notes, staff training and supervision, audit-log review, business planning, and administration, including the security monitoring and audit logging described in our Website & Patient Portal Privacy Policy.
2.4 Business Associates
We share PHI with contractors and vendors ("business associates") that perform services for us and that agree in writing (a Business Associate Agreement, "BAA") to protect your PHI as HIPAA requires. Our business associates include:
- Brickell Bay Group LLC — developer and operator of the SanaLogs Chart Pro software platform (patient portal, EHR interface, and supporting services) used by the Practice.
- Amazon Web Services, Inc. (AWS) — cloud hosting of our EHR and portal, including encrypted storage and backups.
As a matter of practice policy, we require a Business Associate Agreement with any vendor that creates, receives, maintains, or transmits protected health information on our behalf — including our software provider, our hosting provider, and any future e-fax, transcription, lab-interface, telehealth, or documentation vendor — before it handles protected health information.
2.5 Other Uses and Disclosures Permitted or Required by Law Without Your Authorization
To the extent applicable, and subject to the conditions in the HIPAA Privacy Rule and Florida law, we may use or disclose PHI:
- As required by law, including reporting required by Florida statutes;
- For public health activities (e.g., disease reporting to the Florida Department of Health, vital statistics, FDA-regulated product safety reporting);
- About victims of abuse, neglect, or domestic violence, to authorized authorities (including mandatory reports concerning children and vulnerable adults under Florida law);
- For health oversight activities (audits, licensure, inspections by agencies such as the Florida Department of Health or the U.S. Department of Health and Human Services);
- For judicial and administrative proceedings, in response to a court order, or in response to a subpoena or discovery request meeting the Privacy Rule's conditions and Florida's stricter patient-records requirements (§ 456.057, Fla. Stat.);
- For law enforcement purposes, in the limited circumstances HIPAA permits;
- To coroners, medical examiners, and funeral directors;
- For organ and tissue donation purposes;
- For research, only under an IRB/privacy-board waiver or other HIPAA-compliant mechanism (we do not currently conduct research);
- To avert a serious threat to health or safety;
- For specialized government functions (e.g., military, national security, correctional institutions);
- For workers' compensation as authorized by law.
Florida law provides additional protections for certain categories of records (including, without limitation, HIV/AIDS test results, mental health records, and substance use disorder records). Where Florida law or 42 C.F.R. Part 2 is more protective than HIPAA, we follow the more protective rule (see Section 10 regarding 42 C.F.R. Part 2).
2.6 Family, Friends, and Persons Involved in Your Care
We may disclose relevant PHI to a family member, friend, or other person you identify as involved in your care or payment for your care, if you agree, are given an opportunity to object and do not, or, in an emergency or incapacity, if we determine in our professional judgment that disclosure is in your best interest. Parents or legal guardians of minor patients generally may access the minor's records, subject to exceptions under Florida law where a minor may lawfully consent to their own care.
2.7 Appointment Reminders and Communications
We may contact you (by phone, email, text message, or through the patient portal) for appointment reminders, follow-up, membership and billing matters, and information about treatment alternatives or health-related services we offer. You may ask us to use a specific contact method (see "Confidential Communications" below). We will obtain any consent required by law before sending marketing text messages, and we do not sell your PHI. See the Website & Patient Portal Privacy Policy for how interest-list ("waitlist") contact information is used.
3. Uses and Disclosures Requiring Your Written Authorization
The following uses and disclosures will be made only with your written authorization:
- Marketing (except face-to-face communications or promotional gifts of nominal value);
- Sale of PHI (we do not sell PHI);
- Most uses and disclosures of psychotherapy notes, if any are ever created;
- Any other use or disclosure not described in this Notice.
You may revoke an authorization at any time by writing to the Privacy Officer, except to the extent we have already acted in reliance on it. The portal's "Authorization for Release of Medical Information" form states that, unless you specify an earlier date, an authorization expires one year from signing.
4. Your Rights Regarding Your PHI
You have the following rights. To exercise any of them, contact the Privacy Officer at the address above. We may require a written request; forms are available from the office and, for some requests, in the patient portal.
4.1 Right to Access and Obtain Copies (45 C.F.R. § 164.524)
You may inspect and obtain a copy of PHI in your designated record set, including an electronic copy if we maintain it electronically (we do). Much of your record is available to you directly through the patient portal (visit summaries, submitted forms, invoices, and documents shared with you). We will respond within 30 days (with one 30-day extension permitted with written notice). Electronic copies of records you access through the patient portal are provided at no charge. For paper copies or copies in other formats, we may charge a reasonable, cost-based fee at the rates permitted by Florida law (§ 456.057, Fla. Stat., and applicable Florida Administrative Code rules), consistent with HIPAA.
4.2 Right to Request Amendment (45 C.F.R. § 164.526)
You may request that we amend PHI that you believe is incorrect or incomplete, for as long as we maintain it. We may deny the request in limited circumstances (for example, if the record is accurate and complete or was not created by us); if we deny it, we will explain why in writing, and you may submit a written statement of disagreement that will be kept with your record.
4.3 Right to an Accounting of Disclosures (45 C.F.R. § 164.528)
You may request a list of certain disclosures of your PHI made in the six years before your request, other than disclosures for treatment, payment, and health care operations, disclosures to you or made with your authorization, and certain other exceptions. The first accounting in any 12-month period is free; we may charge a reasonable, cost-based fee for additional requests after notifying you of the fee.
4.4 Right to Request Restrictions (45 C.F.R. § 164.522(a))
You may request restrictions on how we use or disclose your PHI for treatment, payment, or health care operations. We are not required to agree to most requested restrictions, but if we agree, we will honor the restriction except in an emergency. Exception we must honor: if you (or someone on your behalf other than a health plan) pay for an item or service in full, out of pocket, and you request that we not disclose that item or service to a health plan for payment or operations purposes, we must comply. Because we are a self-pay practice that does not bill insurance, this restriction is effectively our default posture.
4.5 Right to Confidential Communications (45 C.F.R. § 164.522(b))
You may request that we communicate with you by alternative means or at alternative locations (for example, only by email, or only at a specific phone number). We will accommodate reasonable requests and will not ask you why.
4.6 Right to a Paper Copy of This Notice
You may request a paper copy of this Notice at any time, even if you agreed to receive it electronically. It is also posted at https://mynomadhealth.com/notice-of-privacy-practices and available in the patient portal.
4.7 Right to Be Notified of a Breach
You have the right to be notified following a breach of your unsecured PHI. See Section 6.
5. Acknowledgment of Receipt
We will ask you to sign an acknowledgment that you received this Notice (the patient portal presents a "HIPAA Notice of Privacy Practices Acknowledgment" form for this purpose, signed with a drawn electronic signature). Your treatment is not conditioned on signing the acknowledgment; if you decline, we will document our good-faith effort to obtain it.
6. Breach Notification
If a breach of your unsecured PHI occurs, we will notify you without unreasonable delay and no later than 60 days after discovery, as required by HIPAA (45 C.F.R. § 164.404). Where the Florida Information Protection Act (§ 501.171, Fla. Stat.) applies, notice to affected Florida residents must be provided within 30 days after determination of a breach (with a possible 15-day extension for good cause shown in writing to the Florida Department of Legal Affairs), and we will provide notice within the shorter applicable period. Notices to the U.S. Department of Health and Human Services, the Florida Department of Legal Affairs (for breaches affecting 500 or more Florida residents), consumer reporting agencies, and the media will be made when and as required by law. Under FIPA, a covered entity that provides individual notice in accordance with HIPAA and notifies the Department of Legal Affairs within 30 days is deemed to be in compliance with FIPA's individual-notice requirement.
7. Changes to This Notice
We reserve the right to change this Notice and our privacy practices at any time, and to make the new terms effective for all PHI we maintain, including PHI created or received before the change. The current Notice, with its effective date, will be posted on our website and in the patient portal, and paper copies will be available on request.
8. Complaints
If you believe your privacy rights have been violated, you may file a complaint with:
- Our Privacy Officer: Steven A. Pino, Director of Clinical Operations, info@mynomadhealth.com, (305) 680-0566, 400 Arthur Godfrey Rd #200-01, Miami Beach, FL 33140; and/or
- The U.S. Department of Health and Human Services, Office for Civil Rights: 200 Independence Avenue S.W., Washington, D.C. 20201; 1-800-368-1019 (TDD 1-800-537-7697); or online at https://www.hhs.gov/ocr/complaints.
We will not retaliate against you for filing a complaint.
9. Telehealth-Specific Privacy
Telehealth visits are conducted over secure video and/or audio technology appropriate for protected health information, and you will be asked to sign a Florida telehealth consent in the patient portal before your first telehealth visit. The same confidentiality protections that apply to in-person visits apply to telehealth visits. Telehealth is provided consistent with § 456.47, Fla. Stat.
The technology we use, stated plainly. Video visits run inside our own patient portal. We do not use an outside video, meeting, or conferencing company, so there is no third-party vendor holding your visit. Audio and video are encrypted between your device and your provider's device by the technology's own mandatory encryption, travel directly between the two devices wherever the network allows, and otherwise are relayed — still encrypted — through a server we operate. Visits are not recorded, and no audio or video is stored. What is kept is the clinical note your provider writes and an audit entry that a call took place, when, and with whom. As a matter of practice policy, we require a Business Associate Agreement with any vendor that handles protected health information on our behalf, and would require one before adopting any outside telehealth technology vendor.
10. Note on Substance Use Disorder Records (42 C.F.R. Part 2)
The Practice does not hold itself out as a substance use disorder ("SUD") diagnosis or treatment program, and this Notice does not assume that 42 C.F.R. Part 2 applies to us. If the Practice ever both (a) holds itself out as providing SUD diagnosis, treatment, or referral for treatment and (b) is federally assisted such that Part 2 attaches, we will follow the stricter consent and disclosure rules Part 2 requires, and we will update this Notice with the required Part 2 language and consent workflows. Regardless, where Florida law provides heightened protection for SUD or mental-health records, we follow the more protective rule.