Notice of Privacy Practices
Effective date: August 21, 2026 · Last updated: August 21, 2026 · 45 CFR § 164.520
This Notice applies to each independent licensed healthcare professional or professional medical entity that provides care to you through the NoTimeRx platform and adopts or provides this Notice (each, a “Provider Practice”). The Provider Practice responsible for your care may be identified in your patient portal, telehealth consent, prescription, visit summary, or other encounter documentation. This Notice describes the privacy practices of the applicable Provider Practice and the privacy practices that Biotica Consulting LLC d/b/a NoTimeRx follows when acting for that Provider Practice.
In this Notice, “we,” “us,” and “our” mean the Provider Practice and, only when performing authorized services for the Provider Practice, NoTimeRx and other Business Associates. This wording does not make NoTimeRx a healthcare provider, a medical practice, or a covered entity solely because it operates the platform.
1. Who This Notice Applies To
This Notice applies to the Provider Practice, its licensed clinicians, employees, trainees, contractors, and other workforce members who are permitted to use or disclose Protected Health Information (“PHI”) on its behalf. It applies to care delivered by the Provider Practice through the NoTimeRx website, patient portal, intake process, secure messaging features, telephone or video services, and related telehealth workflows in the United States.
NoTimeRx’s MSO and Business Associate role
NoTimeRx is operated by Biotica Consulting LLC d/b/a NoTimeRx. NoTimeRx is a non-clinical management services organization (“MSO”), technology platform, and administrative services provider. NoTimeRx may create, receive, maintain, transmit, or otherwise process PHI for the Provider Practice under a written Business Associate Agreement (“BAA”) and applicable law.
NoTimeRx may provide non-clinical services such as platform hosting, intake technology, identity verification support, scheduling, patient communications, payment administration, customer support, security operations, provider credentialing support, e-prescribing connectivity, and coordination with pharmacies, laboratories, and other service providers.
NoTimeRx does not practice medicine, diagnose, prescribe, determine medical necessity, select treatment, direct a clinician’s professional judgment, or control the content of a Provider’s clinical decision.
Independent pharmacies, laboratories, clinics, healthcare facilities, and other healthcare providers may be separate covered entities and may provide their own Notices of Privacy Practices. Their notices govern their independent uses and disclosures of information.
2. Information Covered by This Notice
PHI is individually identifiable health information created, received, maintained, or transmitted by or for the Provider Practice in any form, including electronic, paper, oral, photographic, video, or other form. Depending on your care, PHI may include:
- Your name, date of birth, contact information, physical location, shipping address, and identity-verification information.
- Your health history, symptoms, allergies, medications, supplements, diagnoses, treatment requests, pregnancy-related information, and contraindications.
- Questionnaire responses, photographs, documents, laboratory information, messages, visit notes, prescriptions, refill requests, and treatment plans.
- Payment, billing, insurance, HSA or FSA, pharmacy, fulfillment, and delivery information related to healthcare services.
- Technical, security, and audit information associated with access to or operation of the patient portal when that information is maintained on behalf of the Provider Practice.
This Notice does not necessarily apply to information that is not PHI, such as properly de-identified information or certain general website, ecommerce, employment, or marketing information that is not created, received, maintained, or transmitted by NoTimeRx on behalf of a HIPAA covered entity. Non-PHI information is governed by the NoTimeRx Privacy Policy and other applicable federal and state privacy laws.
3. Our Legal Duties and Privacy Commitments
The Provider Practice is required by law to:
- Maintain the privacy and security of your PHI.
- Provide you with this Notice of its legal duties and privacy practices.
- Follow the terms of the Notice currently in effect.
- Notify affected individuals following a breach of unsecured PHI when notification is required by law.
- Provide you with a way to exercise the privacy rights described in this Notice.
Our MSO privacy and security commitments
When NoTimeRx acts as a Business Associate, it commits to use and disclose PHI only as permitted by the applicable BAA, the Provider Practice’s instructions, and law. NoTimeRx’s privacy and security program is designed to:
- Limit access to PHI to authorized workforce members and service providers with a legitimate, job-related need.
- Apply role-based access and minimum-necessary principles where required, including separating non-clinical administrative functions from clinical decision-making.
- Prohibit workforce members from browsing, using, or disclosing patient information out of curiosity or for an unauthorized purpose.
- Require confidentiality, privacy, and security training and take appropriate action when policies are violated.
- Maintain reasonable and appropriate administrative, technical, and physical safeguards based on risk and applicable legal requirements.
- Evaluate vendors that handle PHI and enter into BAAs with subcontractors when HIPAA requires one.
- Maintain incident-response, investigation, mitigation, documentation, and breach-reporting processes.
- Assist the Provider Practice with patient-rights requests, audits, records access, amendments, restrictions, and accountings as required by the BAA and law.
- Return or destroy PHI at the end of a service relationship when feasible, or continue protecting it and limit further use when return or destruction is not feasible.
- Not sell PHI and not use PHI for unrelated third-party advertising without a valid written authorization when one is required.
4. How We May Use and Disclose PHI for Treatment, Payment, and Healthcare Operations
Treatment
The Provider Practice may use and disclose PHI to evaluate you, communicate with you, coordinate care, prescribe or manage medication, order or review testing, obtain consultation, make referrals, and communicate with other professionals involved in your treatment.
Example: Your Provider may review your intake responses and photographs, discuss relevant information with another treating clinician, and transmit a prescription and necessary clinical information to a licensed pharmacy.
Payment
We may use and disclose PHI to charge for services, process payments, determine eligibility or benefits, obtain reimbursement, coordinate HSA or FSA transactions, manage refunds, respond to payment disputes, or perform related billing and collection activities as permitted by law.
Example: We may provide information about a covered service to a health plan, payment processor, HSA or FSA administrator, or other payer so the service can be paid.
Healthcare Operations
We may use and disclose PHI for activities necessary to operate and improve the Provider Practice and the services furnished on its behalf. These activities may include quality assessment, patient safety, care coordination, provider credentialing, compliance, auditing, training, legal review, fraud and abuse prevention, security monitoring, customer support, business planning, and internal analytics related to healthcare operations.
Example: The Provider Practice may review a sample of records to evaluate documentation quality, while NoTimeRx may analyze authorized platform events to investigate a security issue or improve an intake workflow on the Provider Practice’s behalf.
5. Other Uses and Disclosures Permitted or Required Without Your Written Authorization
HIPAA and other laws permit or require certain uses and disclosures without your written authorization. We will meet applicable legal conditions and, where required, limit the information disclosed.
Required by law and regulatory compliance
We may use or disclose PHI when federal, state, or local law requires it. We may disclose PHI to the U.S. Department of Health and Human Services when it requests information to investigate or determine compliance with federal privacy law.
Public health and safety
We may disclose PHI for legally authorized public-health activities, including preventing or controlling disease, reporting adverse events or product problems, assisting with recalls, reporting births or deaths where required, and preventing or reducing a serious and imminent threat to health or safety.
Abuse, neglect, or domestic violence
We may report suspected abuse, neglect, or domestic violence to an authorized government agency when the law permits or requires the disclosure and applicable conditions are met.
Health oversight
We may disclose PHI to health oversight agencies for authorized audits, investigations, inspections, licensure or disciplinary matters, accreditation, or other activities necessary for oversight of the healthcare system and government programs.
Judicial, administrative, and law-enforcement matters
We may disclose PHI in response to a valid court or administrative order, subpoena, discovery request, or other lawful process only when the applicable legal requirements are satisfied. We may make limited disclosures for authorized law-enforcement purposes, such as identifying a suspect or missing person, reporting certain injuries or crimes, responding to a lawful request, or protecting against a serious threat.
Workers’ compensation and government functions
We may disclose PHI as authorized for workers’ compensation programs, military and veterans’ activities, national security, intelligence, protective services, correctional institutions, and other specialized government functions.
Coroners, medical examiners, funeral directors, and organ donation
We may disclose PHI to coroners, medical examiners, funeral directors, and organ procurement organizations as permitted by law.
Business Associates
The Provider Practice may disclose PHI to Business Associates that perform services on its behalf, including NoTimeRx and qualifying vendors that provide hosting, security, communications, payment, legal, accounting, data processing, e-prescribing, and other services involving PHI. Business Associates must protect PHI under written agreements and applicable law.
6. Situations in Which You Have a Choice
Unless you object, or unless professional judgment or law permits otherwise, we may share PHI directly relevant to your care or payment with a family member, close friend, caregiver, or another person involved in your care. We may also use or disclose limited information for disaster-relief or notification purposes.
If you are present and able to make decisions, we will ordinarily ask your permission, give you an opportunity to object, or reasonably infer that you do not object. If you are unavailable or incapacitated, a Provider may use professional judgment to determine whether a limited disclosure is in your best interest.
You may tell us not to share information with a particular person, subject to emergency, safety, legal, and other applicable exceptions.
7. Uses and Disclosures That Generally Require Your Written Authorization
We will obtain a valid written authorization before using or disclosing PHI when HIPAA or another applicable law requires one, including for:
- Most uses and disclosures of psychotherapy notes.
- Marketing communications that require authorization under HIPAA.
- The sale of PHI. We do not sell PHI.
- Other uses or disclosures not described in this Notice and not otherwise permitted or required by law.
You may revoke an authorization in writing at any time, except to the extent that action has already been taken in reliance on it or another legal exception applies. We will not condition treatment, payment, enrollment, or eligibility on an authorization except where law specifically permits that condition.
The Provider Practice and NoTimeRx do not currently use PHI for fundraising. If a Provider Practice later uses PHI for a fundraising communication as permitted by law, the communication will provide a clear way to opt out, and treatment or payment will not be conditioned on your choice.
Information that has been properly de-identified under applicable law is not PHI. De-identified information may be used or disclosed for lawful operational purposes, including service improvement and analytics, provided it is not represented as identifiable patient information.
8. Your HIPAA Rights
Access and obtain a copy
You may ask to inspect or receive an electronic or paper copy of PHI in a designated record set, subject to limited legal exceptions. We will generally act on a valid request within 30 days. We may charge a reasonable, cost-based fee where permitted and will tell you about any fee in advance when required.
Request an amendment
You may ask to amend PHI that you believe is inaccurate or incomplete. We may deny the request in circumstances permitted by law, but we will provide a written explanation and information about your right to submit a statement of disagreement. We will generally act on a valid request within 60 days, subject to any permitted extension.
Request confidential communications
You may ask us to contact you in a specific way or at a different location. We will accommodate reasonable requests and may ask you to specify how payment, if any, will be handled.
Request restrictions
You may ask us to limit certain uses or disclosures for treatment, payment, or healthcare operations, or disclosures to persons involved in your care. We are not generally required to agree, but if we agree, we will follow the restriction except in an emergency or as otherwise permitted by law.
If you pay out of pocket in full for a healthcare item or service, you may ask us not to disclose information about that item or service to your health plan for payment or healthcare operations. We will agree unless a law requires the disclosure.
Receive an accounting of disclosures
You may request a list of certain disclosures of your PHI made during the six years before your request. The accounting will not include disclosures excluded by law, such as many disclosures for treatment, payment, or healthcare operations. One accounting in a 12-month period is generally free; a reasonable, cost-based fee may apply to an additional request after advance notice.
Receive a copy of this Notice
You may request a paper copy of this Notice at any time, even if you agreed to receive it electronically. A current electronic copy will also be available through the NoTimeRx website or patient portal.
Choose a personal representative
A person with legal authority to act for you, such as a guardian, healthcare agent, or other legally recognized personal representative, may exercise your rights. We may verify the person’s identity and authority before acting.
How to exercise your rights
Submit a request through the patient portal or contact the Privacy Office listed below. We may require a written request, identity verification, and enough information to locate the relevant records. NoTimeRx may receive and route your request on behalf of the Provider Practice, but the Provider Practice remains responsible for the clinical record and final response unless duties have been lawfully delegated.
9. Substance Use Disorder Records Protected by 42 CFR Part 2
To the extent the Provider Practice or NoTimeRx receives or maintains substance use disorder patient records protected by 42 U.S.C. § 290dd-2 and 42 CFR Part 2, those records receive additional protections.
Part 2 records, or testimony describing the content of those records, will not be used or disclosed in a civil, criminal, administrative, or legislative investigation or proceeding against you unless authorized by your written consent or by a court order entered in accordance with Part 2 and accompanied by a subpoena or other legal requirement compelling disclosure, as applicable.
If Part 2 records are proposed for fundraising communications for the benefit of a covered entity, you will first be given a clear and conspicuous opportunity to elect not to receive those communications. We do not currently use Part 2 records for fundraising.
10. Telehealth, Pharmacy, Laboratory, and Fulfillment Coordination
Telehealth care may involve the exchange of PHI among the Provider Practice, NoTimeRx, pharmacies, laboratories, other treating providers, and authorized service providers. The Provider Practice may disclose information to a pharmacy for e-prescribing, medication-history review, drug-interaction review, dispensing, counseling, refill processing, and related treatment or payment activities.
The Provider Practice may disclose information to a laboratory or other healthcare provider to order, perform, interpret, or coordinate testing and treatment. NoTimeRx may transmit or route information for these purposes as a Business Associate without making the underlying clinical decision.
Limited information may be provided to shipping carriers, couriers, fulfillment vendors, or other conduits as needed to deliver an order or communication. We seek to limit delivery information to what is reasonably necessary and use discreet packaging where operationally available. A separate pharmacy, laboratory, clinic, or vendor may be responsible for its own privacy practices and security.
11. Security Program and Access Controls
We maintain a privacy and security program designed to protect PHI against reasonably anticipated threats, hazards, unauthorized access, impermissible uses or disclosures, and accidental loss. Depending on the risk, technology, and applicable legal requirements, safeguards may include:
- Identity and access management, authentication controls, role-based permissions, and periodic access review.
- Audit logging, security monitoring, alerting, incident investigation, and documentation.
- Encryption or other protective controls for PHI in transit and at rest where reasonable and appropriate.
- Secure development, vulnerability management, patching, backups, recovery planning, and business-continuity measures.
- Workforce training, confidentiality obligations, sanctions, vendor due diligence, and subcontractor oversight.
- Secure retention, disposal, return, and destruction practices appropriate to the media and legal requirements.
No security program can eliminate every risk. We do not promise that unauthorized access, loss, or misuse can never occur. We commit to investigate suspected incidents, mitigate harmful effects to the extent practicable, document required actions, and provide or support legally required notifications.
12. Record Retention, Return, and Destruction
The Provider Practice retains medical records for the periods required by applicable federal and state law, professional standards, contractual obligations, and legitimate legal or operational needs. NoTimeRx may maintain copies or components of records on behalf of the Provider Practice under the BAA and applicable retention schedules.
A request to delete an account or consumer profile does not necessarily require deletion of a medical record that the Provider Practice is legally required or permitted to retain. When NoTimeRx’s Business Associate relationship ends, NoTimeRx will return or destroy PHI when feasible as required by the BAA. If return or destruction is not feasible, NoTimeRx will continue to protect the PHI and limit further use or disclosure to the purpose that makes return or destruction infeasible.
13. Breach and Security-Incident Notification
If unsecured PHI is acquired, accessed, used, or disclosed in a manner not permitted by law, the Provider Practice will evaluate the incident under applicable breach-notification standards. When individual notice is required, it will be provided without unreasonable delay and no later than 60 days after discovery, or sooner when a more protective state law applies.
NoTimeRx will report breaches and security incidents to the Provider Practice as required by law and the BAA, cooperate with investigation and mitigation, and support required notices. NoTimeRx may send a notice directly if it is legally responsible for the notice or has been expressly delegated that responsibility.
Where required, notice will also be provided to the U.S. Department of Health and Human Services and, for certain breaches affecting more than 500 residents of a state or jurisdiction, to prominent media outlets.
14. More Protective State Laws, Minors, and Sensitive Information
We provide services across the United States, and state law may provide privacy protections that are more stringent than HIPAA. Where a more protective federal or state law applies, we will follow that law. Additional rules may apply to mental-health records, substance-use-disorder records, HIV or STI information, genetic information, reproductive-health information, domestic-violence information, minor-consented care, and other sensitive information.
A parent, guardian, or other representative may ordinarily exercise rights for a minor or dependent person, but state law may give the individual independent confidentiality rights in certain circumstances. The Provider Practice may provide state-specific notices or addenda when required.
15. Changes to This Notice
We reserve the right to change the terms of this Notice and to make the revised Notice effective for all PHI maintained by the Provider Practice, including PHI created or received before the change, to the extent permitted by law.
When the Notice is materially revised, the “Last updated” and effective dates will be changed, and the revised Notice will be made available on the NoTimeRx website, in the patient portal, upon request, and through any additional method required by law. You may request a paper copy at any time.
16. Complaints and Non-Retaliation
If you believe your privacy rights have been violated, you may file a complaint with the Provider Practice through the Privacy Office listed below. You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights.
U.S. Department of Health and Human Services, Office for Civil Rights
200 Independence Avenue, S.W.
Washington, D.C. 20201
Telephone: 1-877-696-6775
Online: HHS OCR complaint portal
We will not retaliate against you, deny care, reduce the quality of care, or adversely affect your access to services because you filed a good-faith privacy complaint or exercised a legal right.
17. Contact the Privacy Office
Privacy Officer for the Provider Practice
c/o Biotica Consulting LLC d/b/a NoTimeRx
1404 Oak Tree Rd
Ste 4 #282
Iselin, NJ 08830
USA
Email: privacy@notimerx.com
18. Acknowledgment of Receipt
You may be asked to acknowledge that you received or were offered this Notice. Your acknowledgment does not authorize any use or disclosure of PHI, does not waive any privacy right, and does not prevent you from filing a complaint.