Effective Date: August 8, 2026
Last reviewed: August 8, 2026
This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully.
Hinkapin Health LLC ("Hinkapin Health," "we," "us") works with self-funded employers, third-party administrators, benefits advisors and surgical facilities to coordinate bundled surgical care at published prices. Depending on which service you are receiving, our obligations under the Health Insurance Portability and Accountability Act ("HIPAA") differ. We are stating that plainly here rather than leaving it ambiguous.
| In this role | Here is how your information is handled |
|---|---|
|
As a business associate Most of our employer, TPA and advisor work |
When we perform services for an employer's group health plan or its administrator, we act as that plan's business associate. The plan — not Hinkapin Health — is the covered entity, and the plan's own Notice of Privacy Practices governs your information. We handle your information only as permitted by our written Business Associate Agreement with that plan, and we are directly liable under HIPAA for safeguarding it. To exercise your HIPAA rights over information held in that context, contact your health plan administrator; we will support the plan in responding. |
|
As, or on behalf of, a covered entity Care arranged through Affiliates |
When you receive care at, or we arrange care through, our affiliated surgical facility, that facility is a covered entity under HIPAA and this notice describes how your information is used in that relationship. Sections 3 through 12 below apply to you directly. |
| Under Texas law, in every role | The Texas Medical Records Privacy Act (Texas Health & Safety Code, Chapter 181) defines "covered entity" far more broadly than federal HIPAA does — it reaches essentially any organization that collects, stores, analyzes, uses or transmits protected health information of a Texas resident. We treat ourselves as covered by Chapter 181 in all of our work, regardless of our federal HIPAA classification. Section 8 describes the additional rights that gives you. |
Contact our Privacy Officer using the details in Section 12. If your information sits with your employer's health plan rather than with us, we will tell you that and point you to the right contact rather than leaving you to work it out.
Protected health information ("PHI") is information that identifies you and relates to your physical or mental health, the health care you receive, or the payment for that care. In our work this typically includes your name and contact details, date of birth, the procedure you are scheduled for or considering, the surgeon and facility involved, your insurance or self-pay status, prior authorization and clearance records, and the amounts billed and paid.
It does not include information that has been de-identified in accordance with HIPAA standards — for example, the aggregate savings and volume figures we report to an employer, which contain no information that could reasonably identify any individual.
We may use and disclose your PHI without your written authorization for the following purposes.
To coordinate and manage your surgical care. For example, we share your clinical clearance records with the operating surgeon and the anesthesia team, and we transmit your pre-operative instructions to the facility scheduling your procedure.
To determine what your care costs and to settle it. For example, we assemble the components of a bundled surgical episode — facility, surgeon, anesthesia, pathology, implants — into a single invoice, and we exchange eligibility and claims information with your health plan or its administrator so the episode can be paid correctly.
To run and improve our services. For example, we review outcomes and complication rates across episodes for quality assurance, we verify that participating surgeons and facilities hold current credentials, and we audit invoices against our published prices to confirm you were charged what was quoted.
Where we act as a business associate, we return information to the plan or its administrator as our agreement requires. We do not disclose your individually identifiable health information to your employer as an employer. Information a plan sponsor receives is limited to what HIPAA permits — generally de-identified or summary information — unless you have separately authorized more.
We may contact you by phone, text message or email about scheduling, pre-operative preparation, payment arrangements and follow-up. Tell us at any time if you prefer a different method or location, and see Section 7 on confidential communications.
We use third-party technology providers to operate our forms, client portal, scheduling and communications. Where any of those providers may create, receive, maintain or transmit PHI on our behalf, we require a written Business Associate Agreement obligating them to safeguard your information to the same standard we are held to, and to report any breach to us. We do not sell your information, and we do not permit our vendors to use it for their own purposes.
Federal and state law allow or require us to use or disclose your PHI without your authorization in the following circumstances:
Other than the purposes described above, we will not use or disclose your PHI without your written authorization. Your written authorization is always required for:
You may revoke an authorization in writing at any time. Revocation stops any future use or disclosure under that authorization but does not undo disclosures already made in reliance on it.
You have the following rights regarding the protected health information we maintain about you. To exercise any of them, contact our Privacy Officer in writing using the details in Section 12. If we hold your information as a business associate of your health plan, we will route your request to the plan and support its response.
You may inspect and obtain a copy of the information we hold about you, including an electronic copy where we maintain it electronically. We will respond within 30 days, or within 15 business days where Texas law's shorter deadline for electronic health records applies. We may charge a reasonable, cost-based fee.
If you believe information we hold is incorrect or incomplete, you may ask us to amend it. We may deny the request in certain circumstances, and if we do, we will explain why in writing and tell you how to submit a statement of disagreement.
You may request an accounting of certain disclosures we have made in the six years before your request. Disclosures for treatment, payment and health care operations, and those you authorized, are generally excluded. The first accounting in any 12-month period is free.
You may request restrictions on how we use or disclose your information. We are not required to agree to every request — with one important exception described immediately below.
You have a right under 45 CFR 164.522(a)(1)(vi) to require that information about that care not be disclosed to your health plan for payment or health care operations purposes, and we must honor that request. Because a substantial share of our patients choose our published flat-rate pricing over billing insurance, this right applies frequently in our work. Tell us before your procedure and we will restrict the disclosure.
You may ask us to reach you at an alternative address, phone number or by an alternative method — for example, only at a personal mobile number rather than a work line. We will accommodate reasonable requests and will not ask you to explain why.
You may request a paper copy at any time, even if you agreed to receive it electronically. We will provide one promptly.
We will notify you if a breach occurs that compromises the privacy or security of your information, as required by the HIPAA Breach Notification Rule and applicable Texas law.
If you have given someone medical power of attorney, or if someone is your legal guardian, that person can exercise these rights on your behalf. We will verify their authority before acting.
The Texas Medical Records Privacy Act (Texas Health & Safety Code, Chapter 181), as amended by House Bill 300, gives Texas residents protections beyond federal HIPAA. Where Texas law is more protective than HIPAA, we follow Texas law.
We may change this notice, and the changes will apply to information we already hold as well as information we receive in the future. The current version will always be posted at hinkapinhealth.com/hipaa-notice.html with its effective date shown at the top. We will provide a copy on request.
If you believe your privacy rights have been violated, you may complain to us, to the federal government, or to the State of Texas. We will not retaliate against you in any way for filing a complaint.
Attn: Privacy Officer
Privacy Officer
Hinkapin Health LLC
3865 Childress Ave, Suite C
Mesquite, TX 75150
Email: concierge@hinkapinhealth.com
Phone: (888) 850-0711
Office for Civil Rights, U.S. Department of Health and Human Services
200 Independence Avenue SW, Room 509F, HHH Building, Washington, D.C. 20201
Phone: 1-877-696-6775 · Online:
hhs.gov/hipaa/filing-a-complaint
Office of the Attorney General, Consumer Protection Division
PO Box 12548, Austin, TX 78711-2548
Phone: 1-800-621-0508 · Online:
texasattorneygeneral.gov/consumer-protection
For any question about this notice, to exercise any of the rights described in Section 7, or to request a paper copy, contact our Privacy Officer:
Attn: Privacy Officer
Privacy Officer
Hinkapin Health LLC
3865 Childress Ave, Suite C
Mesquite, TX 75150
Email: concierge@hinkapinhealth.com
Phone: (888) 850-0711
If your information is held by your employer's group health plan and we act only as that plan's business associate, contact your plan administrator to exercise your rights. We will tell you who that is if you are not sure.
Hinkapin Health · HIPAA Notice of Privacy Practices · Effective August 8, 2026
This notice is provided under 45 CFR 164.520 and Texas Health & Safety Code Chapter 181. Related documents: Privacy Policy · Terms of Service · Pricing Disclaimer