HIPAA and Your Health Information

Last updated: September 3, 2026

The short version. This website does not collect protected health information, so there is nothing here for HIPAA to attach to. HIPAA matters to MDside in two other places: when an affiliated practice treats a patient, and when MDside acts as a business associate of a client that is a covered entity. This page explains both, and where a patient goes to exercise HIPAA rights — which is the treating practice, not this site.

This page is an explanation of how health information is handled across MDside’s services. It is not a Notice of Privacy Practices. A Notice of Privacy Practices is issued by a covered entity to its own patients, and the practice that treats you issues yours.

This website collects no protected health information

mdside.com is a business-to-business informational site. No form on it submits patient data to us; the only interactive element is a scheduling tool for booking a business call. If you are a patient looking for your records, your test results or your treatment history, this is not where they are — contact the practice that treated you. How the Site handles ordinary business information is set out in our Privacy Policy.

Please do not send patient information to us by email or in a booking note. It is not a secure channel.

Where health information actually lives

Setting Who is responsible Where to ask
This website MDside — but no health information is collected here. Privacy Policy
A patient treated by an affiliated practice That practice, as a HIPAA covered entity. The practice, under its own Notice of Privacy Practices.
A clinic or brand that engages MDside The client covered entity, with MDside as a business associate where applicable. Your business associate agreement.

When MDside acts as a business associate

Where a client is a covered entity and our work involves access to protected health information on its behalf, we do that under a written business associate agreement before any information changes hands. Under that agreement we:

  • use and disclose protected health information only as the agreement and HIPAA permit;
  • apply administrative, physical and technical safeguards to it;
  • bind any subcontractor who touches it to the same obligations;
  • make information available so the covered entity can meet a patient’s access, amendment and accounting requests;
  • report to the covered entity any use or disclosure not permitted by the agreement, and any breach of unsecured protected health information, without unreasonable delay;
  • return or destroy the information when the engagement ends, where that is feasible.

If you are a client and need a business associate agreement in place, ask — we will not begin work that touches protected health information without one.

When an affiliated practice is the covered entity

Clinicians in the MDside network practise through MDside PC and other licensed professional entities — a professional corporation is owned by licensed physicians precisely so that clinical responsibility sits with clinicians. When one of those entities evaluates or treats a patient, it is the covered entity for that encounter. It issues its own Notice of Privacy Practices, keeps the medical record, and is where the patient exercises HIPAA rights. MDside LLC, the management services organization, does not practise medicine and does not make clinical decisions.

A patient’s rights under HIPAA

  • Access. To inspect and get a copy of your record, usually within 30 days.
  • Amendment. To ask for a correction, and to have a statement of disagreement recorded if the request is refused.
  • Accounting of disclosures. To get a list of certain disclosures made.
  • Restriction. To ask that uses or disclosures be limited — and, where you pay in full out of pocket, to require that the treatment not be disclosed to a health plan.
  • Confidential communications. To ask to be contacted a particular way or at a particular address.
  • Paper copy. To receive a paper copy of the Notice of Privacy Practices, even if you agreed to an electronic one.
  • Breach notification. To be told if your unsecured protected health information is breached.

Direct any of these to the practice that treated you. If you are not sure which entity that was, contact us and we will tell you where to write.

Complaints

If you believe health information has been mishandled, raise it with the treating practice first, or with us at [email protected]. You may also complain to the U.S. Department of Health and Human Services, Office for Civil Rights, at hhs.gov/ocr/complaints. You will not be retaliated against for making a complaint.

Related

Contact us

MDside PC
401 East Jackson Street, Suite 2340, Tampa, FL 33602, United States
Email: [email protected]
Phone: +1 800 579 6971