NOTICE OF PRIVACY PRACTICES (HIPAA)
Effective Date: January 2026
Your Information. Your Rights. Our Responsibilities.
This Notice describes how medical information about you may be used and disclosed and how you can access this information. Please review it carefully.
Who We Are
EnteroTrack Labs dba EnteroTrack operates a CLIA-certified laboratory that performs diagnostic testing, including the Esophageal String Test® (EST), for use by healthcare providers.
For purposes of the Health Insurance Portability and Accountability Act, EnteroTrack Labs operates as a Covered Entity when providing laboratory testing services.
Protected Health Information (PHI)
We collect, use, and maintain “Protected Health Information” (PHI), which includes identifiable health information such as:
- Test orders and results (including EoEScore® and related biomarkers)
- Clinical and demographic information provided by healthcare providers
- Billing and insurance information
- Specimen-related data derived from laboratory analysis
Your Rights
When it comes to your health information, you have certain rights:
Get a copy of your medical record
- You can ask to see or get an electronic or paper copy of your medical record and other health information we have about you.
- We will provide a copy or summary within 30 days of your request.
- We may charge a reasonable, cost-based fee.
Ask Us to Correct Your Medical Record
- You can request correction of information you believe is incorrect or incomplete.
- We may deny your request, but we will explain why in writing within 60 days.
Request Confidential Communications
- You can ask us to contact you in a specific way, (e.g., different address or phone).
- We will accommodate all reasonable requests.
Ask Us to Limit What We Use or Share
- You may request limits on PHI used for treatment, payment, or operations.
- We are not required to agree, but if we do, we will honor the restriction except in emergencies.
- If you pay out-of-pocket in full, you may request that we not share that information with your insurer, and we will comply unless required by law.
Get a List of Disclosures
- You may request an accounting of disclosures for up to 6 years prior.
- One report per year is free; additional requests may incur a fee.
Choose Someone to Act for You
- If you have a legal representative, (e.g., medical power of attorney), they may exercise your rights.
Get a Copy of This Notice
- You may request a paper copy at any time.
File a Complaint
- You may file a complaint without fear of retaliation.
Your Choices
You have choices in how we share certain information.
You may instruct us to:
- Share information with family, friends, or others involved in your care
- Share information in disaster relief situations
We will NOT share Without your written permission:
- PHI for marketing purposes
- PHI for sale
- Most psychotherapy notes (if applicable)
Fundraising
We do not use your PHI for fundraising purposes.
How We Use and Disclose Your PHI
We use and disclose PHI in accordance with HIPAA and limit disclosures to the minimum necessary.
1. Treatment
We use and share PHI with healthcare providers to support diagnosis, monitoring, and treatment decisions.
2. Payment
We use and share PHI to obtain reimbursement from insurers, Medicare, or other payers.
3. Healthcare Operations
We use PHI for:
- Laboratory quality assurance and validation
- Internal performance monitoring
- Compliance and regulatory reporting
- Business management and administrative functions
We also disclose results to the ordering healthcare provider and, where applicable, to payers.
Other Uses and Disclosures
We may use or disclose PHI without your authorization when required or permitted by law:
Public Health and Safety
- Prevent disease
- Report adverse events
- Address threats to health or safety
Research
We may use or disclose PHI for research when approved by an Institutional Review Board (IRB) or as otherwise permitted by law.
Legal and Regulatory Compliance
- Comply with federal and state laws
- Respond to court orders or subpoenas
- Cooperate with health oversight agencies
Specialized Government Functions
- Law enforcement
- Workers’ compensation
- National security
Deceased Individuals
- Medical examiners or funeral directors.
Substance Use Disorder Records
To the extent we maintain substance use disorder records subject to 42 CFR Part 2, we will not disclose such information for legal proceedings without your written consent or a court order.
Data Sharing and Business Associates
We may share PHI with service providers, (e.g., billing vendors, IT providers, logistics providers), IT providers, and logistics providers, who perform services on our behalf. These parties are contractually required to safeguard PHI in accordance with HIPAA.
Website and Non-Secure Communications
Information submitted through general website forms, email, or other non-secure channels may not be protected under HIPAA. Do not submit sensitive health information through these channels unless explicitly directed to a secure system.
Our Responsibilities
We are required by law to:
- Maintain the privacy and security of your PHI
- Notify you without unreasonable delay if a breach occurs
- Follow the terms of this Notice
- Provide you with a copy of this Notice
We will not use or share your PHI other than as described here unless you provide written authorization.
Changes to This Notice
We may change this Notice at any time. Any revised Notice will apply to all PHI we maintain and will be available on our website and upon request.
Contact Information
Privacy Officer
EnteroTrack Labs
12635 E. Montview Blvd., STE 215LC
Aurora, CO 80045
Email: info@enterotrack.com
Complaints
You may file a complaint with us or with:
U.S. Department of Health and Human Services, Office for Civil Rights
200 Independence Avenue, S.W.
Washington, D.C. 20201
Phone: 1-877-696-6775
Website: https://www.hhs.gov/hipaa/filing-a-complaint/index.html
We will not retaliate against you for filing a complaint.
State Law
Where state law provides greater privacy protections than federal law, we will comply with those requirements.