Notice of Privacy Practices
Health Insurance Portability and Accountability Act (HIPAA) Compliant
Effective Date: May 13, 2026 | Last Revised: May 13, 2026
THIS NOTICE DESCRIBES HOW INFORMATION ABOUT YOU OR YOUR CHILD MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
1. About This Notice
BrightBloom is a healthcare provider specializing in evidence-based, individualized therapeutic services for young children with autism spectrum disorder. We are committed to protecting the privacy and confidentiality of your child’s protected health information (PHI) in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and all applicable state laws.
This Notice of Privacy Practices (“Notice”) applies to all BrightBloom locations, including our centers in Delaware, New Jersey, and Maryland, and describes:
- How we may use and disclose you or your child’s PHI
- Your rights regarding your PHI
- Our legal duties and privacy practices
- How to exercise your rights and file complaints
2. Our Legal Duty
We are required by law to:
- Maintain the privacy and security of PHI
- Provide you with this Notice of our legal duties and privacy practices
- Notify you in the event of a breach of unsecured PHI
- Follow the terms of this Notice currently in effect
We reserve the right to change the terms of this Notice at any time. Revised Notices will be posted at all BrightBloom locations and on our website. The effective date appears at the top of this Notice.
3. How We May Use and Disclose Your PHI
The following describes the ways we may use and disclose PHI without your specific authorization.
3.1 Treatment
We may use and disclose your child’s PHI to provide, coordinate, or manage healthcare and related services. For example, we may share information with other treating professionals, specialists, or agencies involved in your child’s care including BCBA practitioners, occupational therapists, speech-language pathologists, and your child’s pediatrician to ensure coordinated, individualized treatment.
3.2 Payment
We may use and disclose your child’s PHI to obtain payment for services provided. This includes submitting claims to Medicaid (DE, NJ, MD), commercial insurance carriers, and other payers; obtaining prior authorizations; and responding to payer audits or medical necessity reviews. This also includes use of information to process approved financial transactions associated with your purchase of goods or services.
3.3 Healthcare Operations
We may use and disclose your child’s PHI for our internal healthcare operations, including:
- Quality assessment and improvement activities
- Staff training and clinical supervision
- Credentialing and accreditation activities
- Business planning and administrative functions
3.4 Required by Law
We may use or disclose your child’s PHI when required to do so by federal, state, or local law, including mandatory reporting obligations related to abuse, neglect, or public health activities.
3.5 Other Permitted Disclosures
We may also use or disclose PHI without your authorization for the following purposes permitted under HIPAA:
- Limited Health oversight and government agency activities
- Judicial or administrative proceedings (pursuant to a court order)
- Law enforcement purposes as permitted by law
4. We Require Your Consent
The following uses and disclosures require your written authorization:
- Marketing communications
- Sale of PHI
You may revoke your authorization at any time in writing. Revocation does not apply to actions already taken in reliance on your authorization.
5. Your Rights Regarding Personal Health Information
You have the following rights with respect to your PHI:
5.1 Right to Access
You have the right to inspect and obtain a copy of your PHI maintained in a designated record set. Requests must be made in writing. We may charge a reasonable, cost-based fee. We will respond within 30 days of receiving your request.
5.2 Right to Request Corrections
You have the right to request that we amend PHI pertaining to personal information that you believe is incorrect or incomplete. We may deny your request if we determine the information is accurate and complete. If denied, you may submit a formal statement of disagreement.
5.3 Right to Request Restrictions
You have the right to request that we limit how we use or disclose your PHI. We are not required to agree to your request, except when you request that we not disclose PHI to a health plan for services you have paid for in full out of pocket.
5.4 Right to Request Confidential Communications
You have the right to request that we communicate with you about your child’s healthcare in a specific way. We will accommodate all reasonable requests.
5.5 Right to a Paper Copy of This Notice
You have the right to a paper copy of this Notice at any time, even if you have agreed to receive it electronically.
6. Data Security
BrightBloom implements administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic PHI (ePHI), consistent with the HIPAA Security Rule. These safeguards include:
- Access controls limiting PHI access to authorized workforce members
- Encryption of ePHI in transit and at rest
- Regular workforce training on privacy and security practices
- Audit logs for access to electronic records
- Business Associate Agreements (BAAs) with all third-party vendors who handle PHI
Although we use reasonable safeguards, no system can guarantee absolute security.
7. Data Retention
BrightBloom retains information only for as long as reasonably necessary to:
- Provide services
- Comply with legal obligations
- Resolve disputes
- Enforce agreements
- Maintain appropriate business and healthcare records
Retention periods may vary depending on:
- Applicable healthcare laws
- Insurance requirements
- Licensing obligations
- Employment regulations
- Security and backup requirements
Protected Health Information is retained in accordance with HIPAA and applicable state record retention requirements.
8. Breach Notification
In the event of a breach of unsecured PHI, BrightBloom will notify affected individuals without unreasonable delay and within 60 days of discovering the breach, as required by the HIPAA Breach Notification Rule. Notification will be provided by first-class mail or, if agreed upon, by email. For breaches affecting 500 or more individuals in a state, we will notify prominent media outlets and the U.S. Department of Health and Human Services (HHS).
9. Cookies Policy
Our website uses different types of cookies to improve your experience and better understand how visitors use our site.
9.1 Functional Cookies
These cookies help us recognize you when you return to our website and remember your preferences, such as:
- Preferred language
- Geographic location
- Website settings
We use both first-party and third-party cookies for these purposes.
9.2 Advertising Cookies
Advertising cookies may share limited portions of information to allow us and our partners to display advertisements that may be relevant to your interests based on your activity on our website and other websites.
9.3 Analytics Cookies
We may use analytics providers, such as Google Analytics or similar tools, to better understand how visitors interact with our website.
Analytics technologies may collect:
- Pages visited
- Time spent on pages
- Navigation paths
- Device/browser information
- Referral sources
9.4 Managing Cookies
You can choose to disable cookies through your browser settings. Most web browsers also allow you to delete existing cookies.
Please note that disabling cookies may affect the functionality of certain features on our website.
9.5 Disclaimer
The medical and health-related information provided on this website is for informational purposes only and should not be used for diagnosis or treatment.
We recommend that users seek professional advice from qualified healthcare providers, insurance companies, referring providers, and educational professionals regarding any medical, healthcare, insurance, or educational concerns.
10. Third-Party Websites
Our website may contain links to external websites. This privacy policy applies only to our website. If you visit another website through a link on our site, we encourage you to review that website’s privacy policy separately.
11. Special Protections for Minors
BrightBloom serves young children with autism spectrum disorder. All clients are minors. As such, PHI is handled with heightened sensitivity. Access to records is generally limited to parents, legal guardians, and individuals with documented legal authority to act on behalf of the child. We comply with all applicable state minor privacy laws in Delaware, New Jersey, and Maryland, which may afford additional protections beyond HIPAA.
12. How to Exercise Your Rights
For questions about this Notice or our privacy practices or to exercise any of the rights described in this Notice, please submit a written request to:
BrightBloom Privacy Officer
Email: [email protected]
Mail: 510 Philadelphia Pike, Wilmington, DE 19809
We will not retaliate against you for filing a complaint or exercising your privacy rights.
13. How to File a Complaint
If you believe your privacy rights have been violated, you may file a complaint with BrightBloom or with the U.S. Department of Health and Human Services:
Office for Civil Rights, U.S. Department of Health and Human Services
200 Independence Avenue, S.W., Washington, D.C. 20201
Phone: 1-877-696-6775
Website: hhs.gov/ocr/privacy/hipaa/complaints
BrightBloom is committed to evidence-based and individualized care, compassion, and commitment to meaningful outcomes for every child and family we serve. Protecting the privacy of your child’s health information is fundamental to that commitment.