Privacy Policy
Amy Wecker M.D., LLC DBA SoBe Functional Medicine
A Functional Medicine Practice Serving Patients in Florida and Georgia
Effective Date: 08/10/26
Last Revised: 07/21/26
1. Introduction and Scope
SoBe Functional Medicine ("the Practice," "we," "us," or "our") is committed to protecting the privacy and security of your personal and health information. This Privacy Policy describes how we collect, use, disclose, and safeguard information obtained from and about you when you interact with our Practice.
SoBe Functional Medicine is a HIPAA-covered entity providing functional medicine services — including but not limited to personalized health assessments, nutritional counseling, lifestyle interventions, advanced laboratory testing, and integrative treatment protocols — to patients located in the states of Florida and Georgia.
This Privacy Policy applies to information collected through all points of interaction with the Practice, including:
- Our website located at sobefunctionalmedicine.com
- Our secure patient portal
- Telehealth sessions (audio and video)
- In-office visits at our physical location(s)
- Telephone, email, and other communications with our staff
Important Notice
This Privacy Policy supplements our Notice of Privacy Practices (NPP) as required under 45 CFR § 164.520 of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended. A copy of our NPP is available upon request, at the front desk of our office(s), and on our website. In the event of any conflict between this Privacy Policy and the NPP, the NPP shall govern with respect to Protected Health Information (PHI).
2. Information We Collect
We collect and maintain several categories of information about you, depending on the nature of your interaction with the Practice.
2.1 Protected Health Information (PHI)
PHI is individually identifiable health information that relates to your past, present, or future physical or mental health condition, the provision of health care, or the payment for health care. We may collect the following types of PHI:
- Medical histories, including family health histories
- Diagnoses, clinical assessments, and problem lists
- Treatment plans, including functional medicine protocols and care plans
- Laboratory results, including advanced functional medicine panels
- Supplement, nutraceutical, and medication lists
- Nutritional assessments, dietary records, and food sensitivity testing results
- Genetic and genomic data (e.g., pharmacogenomic panels, SNP analyses)
- Billing records, claims information, and insurance details
- Clinical notes, progress notes, and consultation records
2.2 Personal Information
We collect personal information necessary for your identification, treatment, and billing, including:
- Full legal name and any preferred names
- Date of birth
- Home address, mailing address, and other contact addresses
- Telephone number(s) and email address(es)
- Social Security number (collected only when necessary for billing or insurance purposes)
- Insurance identification numbers and group numbers
- Emergency contact information
- Driver's license or government-issued identification number (for identity verification)
- By providing your mobile number, you agree that SoBe Functional Medicine may send you text messages regarding appointments, scheduling, treatment updates, billing, and other information related to your care. Message and data rates may apply. Message frequency varies. You may reply STOP at any time to opt out or HELP for assistance.
2.3 Mobile Information and SMS Privacy
Mobile information, including phone numbers and SMS opt-in data, will not be shared with third parties or affiliates for marketing or promotional purposes. This does not include service providers that help us deliver text messages.
2.4 No Sale or External Disclosure of SMS Data
SMS opt-in data, phone numbers, and related consumer information will not be sold, shared, rented, transferred, or otherwise disclosed to external organizations for registration purposes, except where required by law. Your data will not be transferred to external organizations.
2.5 Security and Unauthorized Sharing Protections
We maintain protections against unauthorized access, use, or sharing of your information and retain security measures designed to safeguard mobile information and text messaging data.
2.6 Questions or Contact
If you have questions about this privacy policy or our text messaging practices, please contact the privacy officer using the email address or phone number listed on this website.
2.7 Website and Technical Data
When you visit our website, we may automatically collect certain technical information, including:
- Internet Protocol (IP) address
- Browser type and version
- Device type, operating system, and screen resolution
- Cookies and similar tracking technologies (see Section 9)
- Website analytics data, including pages viewed, time on page, and click paths
- Referral URLs (the website that directed you to our site)
- Date and time of access
2.8 Telehealth Session Data
When you participate in telehealth sessions with our providers, we may collect:
- Session metadata, including date, time, duration, and platform used
- Technical connection data related to the telehealth platform
2.9 Information from Third Parties
We may receive information about you from third-party sources, including:
- Referring healthcare providers (medical records, referral letters, consultation notes)
- Clinical and specialty laboratories
- Pharmacies and compounding pharmacies
- Insurance companies, health plans, and third-party administrators
- Health Information Exchanges (HIEs) in which we participate
- Public health authorities, as permitted by law
3. How We Use Your Information
We use and disclose your information in accordance with HIPAA and applicable state law. The following describes the primary categories of uses and disclosures, as permitted under 45 CFR § 164.502.
3.1 Treatment
We use your PHI to provide, coordinate, and manage your health care and related services. This includes:
- Developing and implementing individualized functional medicine treatment protocols
- Coordinating care among your treatment team, including specialists, therapists, and other providers
- Facilitating consultations with other healthcare professionals
- Processing referrals to or from other providers
- Ordering and interpreting laboratory tests, imaging, and other diagnostic studies
- Recommending supplements, nutraceuticals, dietary plans, and lifestyle modifications
3.2 Payment
We use your information to obtain payment for services rendered. This includes:
- Billing you for services provided
- Engaging in collections activities for outstanding balances
3.3 Health Care Operations
We use your information for operational activities necessary to run the Practice and ensure quality care, including:
- Quality assessment and improvement activities
- Clinical outcomes measurement and population health analytics
- Staff training, credentialing, and professional development
- Compliance auditing, internal investigations, and fraud detection
- Business planning, management, and general administrative activities
- Customer service and patient satisfaction assessments
3.4 Uses and Disclosures Requiring Your Written Authorization
Certain uses and disclosures of your PHI require your prior written authorization on a HIPAA-compliant authorization form. These include:
- Marketing: Using your PHI to send you marketing communications about products or services, unless the communication falls within a HIPAA exception (e.g.,face-to-face communications or promotional gifts of nominal value)
- Sale of PHI: Any disclosure of your PHI where SoBe Functional Medicine receives direct or indirect remuneration from a third party in exchange for your PHI
- Certain Research Uses: Use of your PHI for research purposes that do not qualify for an Institutional Review Board (IRB) waiver
- Psychotherapy Notes: Use or disclosure of psychotherapy notes, if maintained
You may revoke any authorization at any time in writing, except to the extent that we have already acted in reliance on that authorization.
3.5 Uses and Disclosures Required or Permitted by Law
We may use or disclose your PHI without your authorization in certain circumstances required or permitted by federal and state law, including:
- Public Health Activities: Reporting to public health authorities for the purpose of preventing or controlling disease, injury, or disability
- Abuse, Neglect, or Domestic Violence: Reporting suspected child abuse, elder abuse, or domestic violence to appropriate government authorities
- Judicial and Administrative Proceedings: Responding to a court order, subpoena, or other lawful process
- Law Enforcement: Providing information to law enforcement officials for specific law enforcement purposes as permitted by HIPAA
- Workers' Compensation: Disclosing PHI as authorized by and necessary to comply with workers' compensation laws
- Organ and Tissue Donation: Disclosing PHI to organ procurement organizations for the purpose of facilitating organ, eye, or tissue donation and transplantation
- Coroners, Medical Examiners, and Funeral Directors: Disclosing PHI as necessary for these officials to carry out their lawful duties
- Food and Drug Administration (FDA): Reporting adverse events, product defects, or to enable product recalls, repairs, or replacements
- Health Oversight Activities: Disclosing PHI to health oversight agencies for activities authorized by law, including audits, investigations, inspections, and licensure actions
- Serious Threats to Health or Safety: Disclosing PHI when necessary to prevent or lessen a serious and imminent threat to your health or safety or that of another person or the public
- Specialized Government Functions: Disclosures for military and veterans' activities, national security and intelligence, protective services, and correctional institutions, as applicable
- Secretary of HHS: Disclosing PHI to the Secretary of Health and Human Services for compliance investigations and enforcement actions
4. How We Share Your Information
4.1 Business Associates
We may share your PHI with third-party service providers who perform functions on our behalf or provide services that involve access to PHI. These entities are known as "Business Associates" under HIPAA. All Business Associates are required to enter into a written Business Associate Agreement (BAA) with SoBe Functional Medicine before receiving access to any PHI. The BAA contractually obligates the Business Associate to:
- Use and disclose PHI only as permitted by the agreement and applicable law
- Implement appropriate administrative, physical, and technical safeguards to protect PHI
- Report any security incidents or breaches of unsecured PHI
- Ensure that any subcontractors with access to PHI also agree to the same restrictions
Examples of Business Associates may include electronic health record (EHR) vendors, billing services, IT support companies, telehealth platform providers, cloud storage providers, and shredding and document destruction services.
4.2 Referrals and Care Coordination
We may share your PHI with other healthcare providers involved in your care for purposes of treatment continuity. This includes sharing medical records, treatment summaries, and clinical notes with referring physicians, specialists, hospitals, laboratories, and pharmacies.
4.3 Health Information Exchanges (HIEs)
We may participate in state or regional Health Information Exchanges, which allow healthcare providers and entities to electronically share patient medical information for treatment, payment, and health care operations. If we participate in an HIE, your PHI may be available to other participating providers. You may have the right to opt out of HIE participation; please contact our Privacy Officer for more information.
4.4 Legal Disclosures
We may disclose your information in response to valid court orders, subpoenas, warrants, civil investigative demands, or other lawful requests by public authorities, including to meet national security or law enforcement requirements, as described in Section 3.5.
4.5 De-Identified Data
We may use and disclose data that has been fully de-identified in accordance with HIPAA standards. De-identified data does not identify you individually and is not subject to HIPAA restrictions. De-identification is performed using one of the following methods permitted under 45 CFR § 164.514:
- Safe Harbor Method: Removal of 18 categories of identifiers specified by HIPAA
- Expert Determination Method: A qualified statistical expert determines that the risk of identifying an individual is very small
De-identified data may be used for research, population health analytics, Practice improvement initiatives, and other lawful purposes.
4.6 No Sale of PHI; Marketing Restrictions
SoBe Functional Medicine does not sell your PHI. We will not use your PHI for marketing purposes without your prior written authorization, except as expressly permitted by HIPAA (e.g., providing you with appointment reminders, information about treatment alternatives, or health-related benefits and services that we offer).
5. Your Rights Under HIPAA
As a patient of SoBe Functional Medicine, you have the following rights with respect to your Protected Health Information. To exercise any of these rights, please contact our Privacy Officer using the information provided in Section 14.
- Right to Access Your PHI. You have the right to inspect and obtain a copy of your PHI maintained in our designated record set, including medical records, billing records, and other records used to make decisions about your care. You may request copies in electronic format. We may charge a reasonable, cost-based fee for copies as permitted by HIPAA and state law.
- Right to Request Amendment. You have the right to request that we amend your PHI if you believe it is incorrect or incomplete. We may deny your request under certain circumstances (e.g., if we did not create the information, or if we determine the information is accurate and complete), but we will provide a written explanation of any denial.
- Right to an Accounting of Disclosures. You have the right to receive a list of certain disclosures of your PHI made by SoBe Functional Medicine or our Business Associates during the six (6) years prior to your request (or a shorter period if you specify). This accounting does not include disclosures made for treatment, payment, or health care operations, or certain other exceptions specified by HIPAA.
- Right to Request Restrictions. You have the right to request restrictions on how we use or disclose your PHI for treatment, payment, or health care operations. We are not required to agree to your request, except that we must comply with a request to restrict disclosures to a health plan for services for which you have paid out of pocket in full.
- Right to Confidential Communications. You have the right to request that we communicate with you about your health information in a certain way or at a certain location. For example, you may request that we contact you only at a specific phone number or send correspondence to an alternative address. We will accommodate reasonable requests.
- Right to Receive a Copy of the Notice of Privacy Practices. You have the right to obtain a paper or electronic copy of our current Notice of Privacy Practices at any time upon request.
- Right to Revoke Authorization. If you have provided a written authorization for the use or disclosure of your PHI, you may revoke that authorization at any time by submitting a written revocation to our Privacy Officer. Revocation will not affect any uses or disclosures made in reliance on the authorization prior to its revocation.
- Right to File a Complaint. If you believe your privacy rights have been violated, you have the right to file a complaint with SoBe Functional Medicine by contacting our Privacy Officer. You also have the right to file a complaint directly with the U.S. Department of Health and Human Services (HHS), Office for Civil Rights. Instructions for filing a complaint with HHS are available at: https://www.hhs.gov/hipaa/filing-a-complaint/index.html(opens in new tab)
Non-Retaliation
SoBe Functional Medicine will not retaliate against you in any way for exercising your rights under HIPAA, filing a complaint with the Practice, or filing a complaint with the HHS Office for Civil Rights.
6. Data Security Measures
SoBe Functional Medicine is committed to protecting the confidentiality, integrity, and availability of your information. We maintain comprehensive administrative, physical, and technical safeguards in accordance with the HIPAA Security Rule (45 CFR Part 164, Subpart C) and applicable state law. These safeguards include, but are not limited to:
- Encryption: All electronic PHI (ePHI) is encrypted at rest and in transit using industry-standard encryption protocols (e.g., AES-256 for data at rest; TLS 1.2 or higher for data in transit).
- Access Controls: Role-based access controls ensure that workforce members can access only the minimum necessary PHI required to perform their job functions. Each authorized user is assigned a unique user identification.
- Multi-Factor Authentication (MFA): Multi-factor authentication is required for access to systems containing ePHI, including the patient portal, EHR system, and administrative platforms.
- Security Risk Assessments: Regular and thorough security risk assessments are conducted at least annually to identify potential vulnerabilities and threats to ePHI. Periodic penetration testing and vulnerability scanning are performed.
- Workforce Training: All workforce members receive HIPAA privacy and security training upon hire and at least annually thereafter, including training on phishing awareness, social engineering, and proper handling of PHI.
- Incident Response and Breach Notification: We maintain a written incident response plan to detect, contain, and remediate security incidents. Breach notification procedures are implemented in accordance with Section 7 of this Privacy Policy.
- Physical Safeguards: Physical access to areas where PHI is stored or processed is restricted through locked facilities, access badge systems, visitor logs, and workstation security measures. Paper records containing PHI are stored in locked cabinets.
- Secure Disposal: PHI in any form is securely destroyed when no longer needed, using methods such as cross-cut shredding for paper records, secure electronic wiping, and degaussing for electronic media.
- Business Continuity and Disaster Recovery: We maintain data backup and disaster recovery plans to ensure the availability and integrity of ePHI in the event of a system failure, natural disaster, or other emergency.
- Audit Controls: Automated audit trails record access to ePHI, including user identification, date, time, and nature of the access, enabling monitoring and investigation of potential unauthorized access.
7. Breach Notification
In the event of a breach of unsecured PHI, SoBe Functional Medicine will provide notification in compliance with federal and applicable state law. The specific obligations are as follows:
7.1 Federal: HIPAA Breach Notification Rule (45 CFR §§ 164.400–414)
- Individual Notification: We will notify each affected individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed as a result of a breach, without unreasonable delay and no later than sixty (60) calendar days from the date of discovery of the breach.
- HHS Notification: We will notify the Secretary of Health and Human Services of the breach. If the breach affects 500 or more individuals, notification is provided without unreasonable delay and no later than 60 days from discovery. Breaches affecting fewer than 500 individuals are logged and reported to HHS annually.
- Media Notification: If the breach affects 500 or more residents of a single state or jurisdiction, we will provide notice to prominent media outlets serving that state or jurisdiction.
7.2 Florida: Florida Information Protection Act (FIPA) (§ 501.171, Fla. Stat.)
- We will notify affected Florida residents of a breach of their personal information no later than thirty (30) calendar days after the determination that a breach has occurred, or the reasonable belief that a breach has occurred.
- If the breach affects 500 or more individuals, we will notify the Florida Department of Legal Affairs (Attorney General) within 30 days of the determination of the breach.
- Notice may be provided by mail, email (with prior consent), or substitute notice if the cost of notice would exceed $250,000, more than 500,000 persons must be notified, or the Practice does not have sufficient contact information.
7.3 Georgia: Georgia Personal Identity Protection Act (GPIPA) (O.C.G.A. § 10-1-912)
- We will notify affected Georgia residents of a breach of their personal information in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or measures necessary to determine the scope of the breach and restore system integrity.
- If SoBe Functional Medicine acts as a service provider and maintains data on behalf of a data owner, notification to the data owner must occur within twenty-four (24) hours of the discovery of the breach.
- If the breach affects 10,000 or more Georgia residents, we will also notify all nationwide consumer reporting agencies of the timing, distribution, and content of the notification.
8. Telehealth Privacy
SoBe Functional Medicine offers telehealth services to patients in Florida and Georgia. The privacy and security of your health information during telehealth sessions is of paramount importance. The following measures and practices apply:
- HIPAA-Compliant Platforms: All telehealth sessions are conducted using encrypted, HIPAA-compliant communication platforms. We have executed Business Associate Agreements (BAAs) with all telehealth technology vendors.
- Patient Identity Verification: Your identity is verified at the beginning of each telehealth session using a multi-step verification process, which may include photographic identification, date of birth confirmation, and security questions.
- Informed Consent: Before your first telehealth visit, you will be asked to provide informed consent for the delivery of care via telehealth. This consent will be documented in your medical record and covers the nature of telehealth services, potential risks and benefits, technology requirements, and privacy considerations.
- Private Location Advisory: Patients are advised to participate in telehealth sessions from a private, secure location where conversations cannot be overheard by unauthorized individuals.
- Session Recordings: If audio or video recordings of telehealth sessions are made, they will be made only with your informed consent, stored as part of your medical record, and afforded the same privacy protections as all other PHI.
- State Licensure Compliance: Telehealth services comply with state licensure requirements. The applicable state law governing a telehealth encounter is determined by the physical location of the patient at the time of service. Our providers are licensed in the states where they provide telehealth services.
- Compliance with State Telemedicine Laws: Telehealth services comply with applicable Florida telemedicine statutes and Georgia telemedicine requirements, including informed consent, provider-patient relationship, and prescribing regulations.
9. Cookies, Tracking, and Online Privacy
9.1 Types of Cookies
Our website uses the following categories of cookies:
Cookie Type
Purpose
Examples
Essential Cookies
Required for basic website functionality, such as secure login to the patient portal, session management, and security features.
Session cookies, authentication tokens, CSRF protection
Analytics Cookies
Help us understand how visitors use our website so that we can improve content and user experience. These cookies collect aggregated, anonymized data.
Google Analytics (configured for anonymized data collection), internal analytics tools
Functionality Cookies
Enable enhanced features and personalization, such as remembering your preferences, language, or region.
Language preference, accessibility settings
9.2 Tracking Technologies and HHS Guidance
SoBe Functional Medicine uses online tracking technologies on our website in compliance with HHS guidance on the use of tracking technologies by HIPAA-covered entities, including the December 2022 bulletin and subsequent updates issued in 2023. Specifically:
- No tracking technologies on our website transmit PHI or individually identifiable health information to third-party analytics providers, advertising networks, or social media platforms without a valid HIPAA authorization from the patient.
- Tracking technologies are not deployed on authenticated (logged-in) pages of the patient portal in a manner that would expose PHI to third parties.
- We regularly review our use of tracking technologies to ensure ongoing compliance with HHS guidance and HIPAA requirements.
9.3 Managing Cookie Preferences
You can manage your cookie preferences through your web browser settings. Most browsers allow you to block or delete cookies. Please note that disabling certain cookies may limit your ability to use some features of our website, including the patient portal.
9.4 Do Not Track Signals
Our website does not currently respond to "Do Not Track" (DNT) browser signals, as there is no uniform industry standard for recognizing or honoring DNT signals at this time. We will update this Privacy Policy if a standard for responding to DNT signals is established.
9.5 Third-Party Links
Our website may contain links to third-party websites, resources, or services for your convenience and informational purposes. These third-party websites are not governed by this Privacy Policy, and we are not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any third-party website you visit.
10. State-Specific Disclosures
In addition to our obligations under federal law, SoBe Functional Medicine complies with the following state-specific privacy and data protection requirements.
10.1 Florida-Specific Provisions
- Breach Notification Under FIPA. As detailed in Section 7.2, SoBe Functional Medicine complies with the Florida Information Protection Act (§ 501.171, Fla. Stat.), which requires notification to affected Florida residents within thirty (30) days of a breach determination and notification to the Florida Attorney General if 500 or more individuals are affected.
- Public Health Reporting. In accordance with § 381.0031, Fla. Stat., SoBe Functional Medicine reports diseases and conditions of public health significance to the Florida Department of Health as required by law. These reports may include certain patient information as mandated by the reportable disease list maintained by the Department of Health.
- Mental Health Records. Mental health records receive additional confidentiality protections under the Florida Mental Health Act (Baker Act, Chapter 394, Fla. Stat.). Disclosure of clinical records relating to mental health treatment is subject to stricter consent requirements and limitations beyond those imposed by HIPAA.
- Telemedicine. The delivery of telehealth services to patients physically located in Florida is governed by applicable Florida telemedicine statutes, including requirements for provider licensure, informed consent, establishment of a provider-patient relationship, and prescribing standards.
- Patient Records Confidentiality. Patient records maintained by SoBe Functional Medicine are subject to confidentiality protections under applicable Florida hospital and ambulatory care statutes, which restrict unauthorized access to and disclosure of patient medical information.
10.2 Georgia-Specific Provisions
- Breach Notification Under GPIPA/PIPA. As detailed in Section 7.3, SoBe Functional Medicine complies with the Georgia Personal Identity Protection Act (O.C.G.A. § 10-1-912), which requires notification to affected Georgia residents in the most expedient time possible and without unreasonable delay. Service providers must notify the data owner within twenty-four (24) hours. Consumer reporting agencies must be notified if 10,000 or more residents are affected.
- Georgia Health Records Act. The Georgia Health Records Act (O.C.G.A. § 31-33) governs the confidentiality and disclosure of health records in Georgia. This statute establishes patient rights regarding access to their medical records, the conditions under which records may be disclosed, and the process for requesting copies. SoBe Functional Medicine complies with all applicable provisions of this Act.
- Georgia Computer Systems Protection Act. SoBe Functional Medicine maintains safeguards consistent with the Georgia Computer Systems Protection Act, which prohibits unauthorized access to computer systems, including electronic health records, and provides civil and criminal penalties for violations.
- Special Protections for Sensitive Information. Georgia law provides enhanced confidentiality protections for certain categories of sensitive health information, including:
- HIV-Related Information: Under O.C.G.A. § 24-12-21, disclosure of HIV-related test results and information is subject to stricter consent and authorization requirements than general PHI.
- Mental Health Records: Records related to mental health treatment are subject to additional confidentiality protections and more restrictive consent requirements for disclosure.
- Substance Use Disorder Records: Records related to substance use disorder treatment receive enhanced protections under both Georgia state law and federal regulations (42 CFR Part 2), requiring specific written consent for most disclosures.
- Telemedicine. Georgia telemedicine requirements govern the delivery of telehealth services to patients physically located in Georgia, including provider licensure requirements, informed consent obligations, and standards for establishing a provider-patient relationship via telemedicine.
11. Data Retention
SoBe Functional Medicine retains PHI and medical records in accordance with HIPAA requirements and the applicable state law of the patient's state of residence. The minimum retention periods are as follows:
Jurisdiction
Retention Requirement
Florida
Medical records must be retained for a minimum of five (5) years from the date of last patient contact. Certain records may be subject to a seven (7) year retention period.
Georgia
Medical records must be retained for a minimum of ten (10) years from the date of last treatment.
After the expiration of the applicable retention period, records are securely destroyed in accordance with the disposal methods described in Section 6 of this Privacy Policy. SoBe Functional Medicine will not destroy records in response to a pending or anticipated legal hold, investigation, or litigation.
12. Changes to This Privacy Policy
SoBe Functional Medicine reserves the right to amend or update this Privacy Policy at any time. When we make changes, the following procedures will apply:
- The revised Privacy policy is posted on our website at https://sobefunctionalmedicine.com/privacy-policy/ with an updated "Effective Date" and "Last Revised" date.
- Material changes will be communicated to patients through reasonable means, which may include posting a prominent notice on our website, providing written notification via email or postal mail, or informing patients at their next office visit.
- Patients will be notified of material changes to our privacy practices as required by HIPAA and applicable state law.
- A revised Notice of Privacy Practices (NPP), if applicable, will be made available at the front desk of our office(s) and on our website.
- Continued use of our services or website after the effective date of a revised Privacy Policy constitutes your acknowledgment of the revised terms.
13. Contact Information
If you have questions about this Privacy Policy, wish to exercise any of your rights described herein, or would like to file a complaint, please contact our Privacy Officer:
Contact Detail
Information
Privacy Officer
Arian Burns, Practice Adminstrator
Practice Name
SoBe Functional Medicine
Mailing Address
975 W 41st Street, Suite 308
Miami Beach, FL 33140
Telephone
(786) 474-3573
contactus@sobefunctionalmedicine.com
Website
Sobefunctionalmedicine.com
13.1 Filing a Complaint with SoBe Functional Medicine
If you believe your privacy rights have been violated, you may file a written complaint with our Privacy Officer at the address, phone number, or email listed above. We will promptly investigate all complaints and provide you with a written response. You will not be penalized or retaliated against for filing a complaint.
13.2 Filing a Complaint with the U.S. Department of Health and Human Services
You also have the right to file a complaint directly with the federal government. Complaints may be submitted to:
U.S. Department of Health and Human Services
Office for Civil Rights
Complaint Portal: https://www.hhs.gov/hipaa/filing-a-complaint/index.html(opens in new tab)
There is no deadline for filing a HIPAA complaint with the Office for Civil Rights, although complaints should be submitted within 180 days of the date you knew or should have known about the act or omission that is the basis of the complaint, unless good cause is shown for the delay.