Scope & Covered Entity Overview
This Notice of Privacy Practices describes how medical information about you may be used and disclosed and how you can access this information. Please review it carefully.
This policy applies to all clinical laboratory diagnostic services, mobile phlebotomy operations, telehealth services, care coordination programs, community health worker initiatives, and web platforms operated by SynMed Care Medical & Community Health Services ("SynMed Care", "we", "us", or "our"), headquartered at 6492 Landover Rd STE D5, Cheverly, MD 20785.
Clinical Medical Laboratory & Diagnostic Compliance
SynMed Care adheres strictly to federal, state, and accreditation regulations governing medical diagnostic testing, including the Clinical Laboratory Improvement Amendments of 1988 (CLIA), College of American Pathologists (CAP) guidelines, OSHA Bloodborne Pathogens Standard (29 CFR 1910.1030), and CDC Infection Control Protocols.
- Chain of Custody & Barcode Identification: All biological specimens (blood, urine, swab, saliva, toxicology, DNA) are assigned encrypted barcode identifiers upon collection. Un-barcoded or improperly labeled samples are rejected following CLIA laboratory quality control standards.
- Diagnostic Result Confidentiality: Laboratory test results constitute Protected Health Information (PHI). Test results are released exclusively to the ordering clinician, the patient or verified legal representative through encrypted channels, or authorized public health agencies where required by law.
- Mandatory Public Health Reporting: In compliance with Maryland Department of Health regulations, positive results for specified reportable communicable diseases are transmitted securely to state epidemiologists for public health surveillance.
- Biohazard Disposal: Biological waste and specimens are handled, stored, and incinerated in full accordance with EPA and OSHA biohazard waste regulations.
HIPAA & HITECH Act Privacy Safeguards
Under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act, SynMed Care implements administrative, physical, and technical safeguards to protect Electronic Protected Health Information (ePHI).
Permitted Uses and Disclosures (Treatment, Payment, Operations):
- Treatment: Provision, coordination, or management of healthcare and diagnostic testing with referring physicians, laboratories, or healthcare providers.
- Payment: Processing claims with Medicaid, Medicare, Maryland Health Connection, or private commercial health plans for reimbursement.
- Operations: Quality assurance reviews, laboratory proficiency testing, internal audits, and regulatory compliance monitoring.
Business Associate Agreements (BAAs): All third-party software vendors, reference labs, and cloud EHR providers bound to SynMed Care must execute formal BAAs pledging identical HIPAA Security Rule compliance.
HITECH Breach Notification: In the event of a breach of unencrypted ePHI, SynMed Care will notify affected individuals, the Secretary of the U.S. Department of Health and Human Services (HHS), and required authorities without unreasonable delay and within 60 calendar days of discovery.
Heightened Confidentiality (42 CFR Part 2 & Mental Health)
Special federal and state laws provide enhanced protection for specific categories of sensitive health information:
- Substance Use Disorder (42 CFR Part 2): Records of substance use disorder diagnosis, treatment, or referral for treatment are protected under 42 CFR Part 2 and will not be disclosed without specific, explicit written patient authorization, except under certified medical emergency conditions or valid judicial order.
- Behavioral Health & Counseling Notes: Behavioral health records and psychotherapy notes require explicit written consent and are never shared for commercial or marketing operations.
Media, Photography, Audio/Video Policy & Immediate Deletion Guarantee
SynMed Care maintains a transparent policy regarding photographic, video, and audio media captured during health outreach, facility operations, or public events:
- Media Capture Policy: SynMed Care may capture general photographs, digital video, event documentation, or promotional media during community health outreach, facility operations, or public events with or without prior explicit written consent.
- Immediate Removal & Permanent Deletion Guarantee: Any individual, patient, parent/guardian, or involved party has the absolute right to request the removal of any photo, image, video, or audio recording in which they or their dependent appear. Upon receiving a request by email (
privacy@synmedcare.org), phone (240-316-3121), or in person, SynMed Care will immediately remove and permanently delete the specified media from all active websites, digital platforms, social media channels, internal servers, and promotional materials. - Clinical & Telehealth Recording: Video recordings or screen captures during telehealth consultations are conducted strictly for medical record-keeping and encrypted within your chart.
- No Impact on Services: Requesting media removal or opting out of media capture will never affect your medical care, laboratory testing, care coordination, or eligibility for health services.
To request immediate removal of any media, email privacy@synmedcare.org with a description or link, and our compliance team will process permanent deletion immediately.
Digital Platform Security & Website Privacy
Transmissions through our website (synmedcare.org) and web applications are protected by 256-bit Transport Layer Security (TLS/HTTPS) encryption in transit and AES-256 encryption at rest. We do not sell, rent, or trade patient contact details, appointment histories, or health metrics to third-party ad networks or data brokers.
Your Rights Under HIPAA & Maryland Law
You possess specific statutory rights regarding your health and diagnostic records:
- Right of Access: Inspect and receive digital or paper copies of your lab reports and health records.
- Right to Request Restrictions: Request restrictions on specific disclosures of your PHI. If you pay for a lab test out-of-pocket in full, you may request that details not be shared with your insurance provider.
- Right to Amendment: Submit written requests to correct inaccuracies in your medical record.
- Right to Accounting: Receive a record of non-routine disclosures of your health information.
- Right to Paper Copy: Obtain a paper copy of this Notice upon request at any clinic or lab facility.
Contact Information, Privacy Officer & Complaints
If you have questions regarding this policy or believe your privacy rights have been violated, contact our Privacy & Compliance Officer:
SynMed Care Privacy & Compliance Office
6492 Landover Rd STE D5, Cheverly, MD 20785
240-316-3121
Email: privacy@synmedcare.org
You may also file a formal complaint with the U.S. Department of Health and Human Services Office for Civil Rights (OCR) by sending a letter to 200 Independence Avenue, S.W., Washington, D.C. 20201. SynMed Care will never retaliate against any individual for exercising their right to file a privacy complaint.