
Confidentiality Policy
VitalSigns House Calls Inc.
Effective Date: June 17, 2026
This Confidentiality Policy governs the obligations of VitalSigns House Calls Inc. and its entire
workforce — including employees, independent contractors, volunteers, students, and affiliated
providers — with respect to all confidential, sensitive, and proprietary information encountered in
the course of clinical and administrative operations. Compliance with this policy is a condition of
employment and continued engagement.
1. Scope and Applicability
This policy applies to all VitalSigns workforce members, including full-time and part-time employees,
independent contractors, students, interns, and volunteers. It covers all forms of confidential
information regardless of medium — written, electronic, verbal, or visual — and encompasses patient
information, business information, and third-party information encountered in the performance of
duties.
2. Categories of Confidential Information
Confidential information includes, but is not limited to:
• Protected Health Information (PHI): Any individually identifiable health information as defined
under HIPAA, including diagnoses, treatment records, insurance data, and demographic identifiers.
• Patient Financial Information: Billing records, insurance identifiers, payment history, and account
information.
• Business and Operational Information: Proprietary clinical protocols, business strategies,
financial projections, payer contract terms, vendor agreements, and trade secrets.
• Personnel Information: Employee records, compensation data, performance reviews, disciplinary
actions, and personal contact information.
• Technology and System Information: EHR credentials, network passwords, system configurations,
and IT security procedures.
• Third-Party Information: Confidential information received from business associates, referral
partners, and other healthcare entities under confidentiality agreements.
3. Workforce Obligations
All workforce members must:
• Access confidential information only to the extent necessary to perform assigned job functions
(minimum necessary standard).
• Not disclose, share, copy, or transmit confidential information to unauthorized individuals inside
or outside the organization.
• Secure confidential documents and devices — including locking workstations, securing physical
records, and not leaving PHI visible in patient homes.
• Report any suspected or actual unauthorized disclosure, breach, or inappropriate access to the
Privacy Officer within 24 hours of discovery.
• Complete annual HIPAA and confidentiality training as required.
• Sign and abide by a Confidentiality Acknowledgment Agreement upon hire and annually
thereafter.
• Return or destroy all confidential materials upon termination of employment or engagement.
4. Minimum Necessary Standard
Workforce members shall access, use, and disclose only the minimum amount of PHI and confidential
information necessary to accomplish the intended purpose. Role-based access controls are
implemented within the CureMD EHR system to enforce this standard. Workforce members must not
access patient records for individuals not under their direct care responsibility.
5. Electronic Communication Standards
• PHI must not be transmitted via personal email, unsecured text message, or social media
platforms.
• All electronic transmission of PHI must use encrypted, HIPAA-compliant channels approved by
VitalSigns.
• Patient photographs, videos, or identifying information must never be posted on personal or
professional social media.
• Portable devices (laptops, tablets, phones) containing PHI must be encrypted and
password-protected.
• Remote access to VitalSigns systems must be conducted through approved secure connections
(VPN or encrypted portal).
6. Social Media Policy
Workforce members must never post, comment on, or share any patient information, clinical
encounters, or identifiable patient scenarios on personal or professional social media, including but
not limited to Facebook, Instagram, TikTok, X (formerly Twitter), LinkedIn, and Snapchat. This
prohibition applies even when no patient name is used, if the information could reasonably identify
the patient. Violations may result in immediate termination and referral to regulatory authorities.
7. Physical Security of Records
Paper records and printed PHI must be stored in locked cabinets or secured areas when not in use.
Documents containing PHI must not be left in plain sight in patient homes, vehicles, or public spaces.
Disposal of PHI-containing documents must be done via secure shredding methods. Workforce
members are responsible for safeguarding any patient-identifiable materials in their possession
during field operations.
8. Confidentiality After Separation
Confidentiality obligations survive termination of employment or engagement with VitalSigns. Former
workforce members remain bound by this policy indefinitely with respect to PHI, and for a period of
three (3) years with respect to business confidential information, unless a longer period is specified in
an individual written agreement.
9. Breach Reporting
Any actual or suspected breach of confidentiality — including unauthorized access, inadvertent
disclosure, lost or stolen devices, or misdirected communications — must be reported to the Privacy
Officer within 24 hours of discovery. Workforce members will not face retaliation for good-faith
reporting. Willful concealment of a breach is subject to disciplinary action and potential civil or
criminal liability.
10. Sanctions for Non-Compliance
Violations of this Confidentiality Policy are subject to progressive disciplinary action up to and
including immediate termination of employment or contract, referral for professional licensing review,
and civil or criminal referral as appropriate under HIPAA and applicable Alabama state law. Financial
penalties under HIPAA can reach up to $1.9 million per violation category per year. Individual
workforce members may face personal liability for willful violations.
11. Training and Acknowledgment
All workforce members are required to: (a) complete initial HIPAA and confidentiality training upon
hire; (b) complete annual refresher training; and (c) sign a Confidentiality Acknowledgment Form
confirming their understanding of and commitment to this policy. Signed acknowledgments are
retained in personnel files as required by HIPAA documentation standards.
12. Policy Questions and Reporting
Privacy Officer — VitalSigns House Calls Inc. Mobile, Alabama
Email: privacy@vitalsignshousecalls.com To report a confidentiality concern or suspected breach, contact
the Privacy Officer immediately.