HIPAA Notice of Privacy Practices
Last updated: July 2026
This notice describes how medical information about you could be used and disclosed, and how you can access that information. Under the Health Insurance Portability and Accountability Act (HIPAA), Vital Bloom would be required to protect the privacy of your protected health information (PHI).
Our commitment
In production, Vital Bloom would maintain the privacy and security of your PHI, provide this notice of our legal duties and privacy practices, and follow the terms of the notice currently in effect.
How your information may be used
Your PHI may be used for treatment (coordinating your care), payment (billing and insurance), and healthcare operations. Any other use or disclosure would require your written authorization, except where permitted or required by law.
Secure video visits
Telehealth visits would be conducted over HIPAA-compliant platforms (Zoom for Healthcare or Microsoft Teams) under signed Business Associate Agreements. Scheduling through Meetkeep would likewise be governed by a BAA and appropriate safeguards.
Your rights
You would have the right to inspect and copy your PHI, request amendments, request an accounting of disclosures, request restrictions, request confidential communications, and receive a paper copy of this notice. You may also file a complaint without fear of retaliation.
Safeguards required for production
A real-world launch requires administrative, physical, and technical safeguards; encryption in transit and at rest; workforce training; breach-notification procedures; and executed BAAs with all vendors that touch PHI. This prototype implements none of these and stores no real health information.