Notice of Privacy Practices
Effective Date: May 8, 2026
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
Secure Draw Mobile Inc. ("Secure Draw Mobile") is committed to protecting the privacy of your identifiable health information. This information is known as "protected health information" or "PHI." Examples of documents that may contain your PHI include laboratory test orders, test results, and invoices.
Our Responsibilities
Secure Draw Mobile is required by law to maintain the privacy of your PHI. We are also required to provide you with this Notice of our legal duties and privacy practices upon request. It describes our legal duties, privacy practices, and your patient rights as determined by the Health Insurance Portability and Accountability Act of 1996 (HIPAA). We are required to follow the terms of this Notice currently in effect. We are required to notify affected individuals in the event of a breach involving PHI that is unsecured. PHI is stored electronically and is subject to electronic disclosure.
How We May Use or Disclose Your Health Information
We use your PHI for treatment, payment, or healthcare operations purposes and for other purposes permitted or required by law. Not every use or disclosure is listed in this Notice, but all of our uses or disclosures of your PHI will fall into one of the categories listed below.
We need your authorization to use or disclose your PHI for any purpose not covered by one of the categories below. With limited exceptions, we will not use or disclose psychotherapy notes, use or disclose your PHI for marketing purposes, or sell your PHI unless you have signed an authorization. You may revoke any authorization you sign at any time. If you revoke your authorization, we will no longer use or disclose your PHI except to the extent we have already taken action based on your authorization.
We may use and disclose your PHI for the following purposes:
Treatment
Secure Draw Mobile provides mobile phlebotomy services for physicians and other healthcare professionals, and we use your PHI in the specimen collection process. We disclose your PHI to authorized healthcare professionals who order tests or need access to your test results for treatment purposes. We may use and disclose PHI to contact you about our services, such as to remind you of an appointment, confirm your scheduled visit, or notify you of the status of your specimen collection. Examples of other treatment-related purposes include disclosure to a pathologist or laboratory partner to help process or interpret your test results, or use of your PHI to contact you to schedule another collection if necessary.
Payment
Secure Draw Mobile may use and disclose your PHI for purposes of billing and payment. For example, we may disclose your PHI to health plans or other payers to determine whether you are enrolled with the payer or eligible for health benefits, or to obtain payment for our services. If you are insured under another person's health insurance policy (for example, parent, spouse, domestic partner, or a former spouse), we may also send invoices to the subscriber whose policy covers your health services.
Healthcare Operations
Secure Draw Mobile may use and disclose your PHI for activities necessary to support our healthcare operations. This includes functions such as performing quality checks on our specimen collection process, internal audits, arranging for legal services, or developing reference standards for our services. It also includes, for example, the sale, transfer, merger, or consolidation of all or part of Secure Draw Mobile with another covered entity, or an entity that following such activity will become a covered entity, and due diligence related to the transaction(s).
Business Associates
We may provide your PHI to other companies or individuals that need it to provide services to us. These other entities, known as "business associates," are required to maintain the privacy and security of PHI. For example, our business associates may use your PHI to conduct billing, collections, courier, lab processing, or record storage services on our behalf.
Individuals Involved in Your Care
We may disclose relevant PHI to a family member, friend, caregiver, or other individual involved in your healthcare or payment for your healthcare, if you tell us that this is acceptable to you or you do not object; or if in our professional judgment, we believe that you do not object.
As Required by Law
We may use and disclose your PHI as required by law.
Law Enforcement Activities and Legal Proceedings
We may use and disclose your PHI if necessary to prevent or lessen a serious threat to your health and safety or that of another person. We may also provide PHI to law enforcement officials, for example, in response to a warrant, investigative demand, or similar legal process, or for officials to identify or locate a suspect, fugitive, material witness, or missing person. We may disclose your PHI as required to comply with a court or administrative order. We may disclose your PHI in response to a subpoena, discovery request, or other legal process in the course of a judicial or administrative proceeding, but only if efforts have been made to tell you about the request or to obtain an order of protection for the requested information.
Research
We may use or disclose PHI for research projects, such as studying how to diagnose or treat particular diseases. These research projects must go through a special process that protects the confidentiality of your medical information. We may also use or disclose PHI about deceased patients to researchers if certain requirements are met.
De-identified Information
We may use your PHI to create "de-identified" information, which means that we remove information that can be used to identify you. There are specific rules under the law about what type of information needs to be removed before information is considered de-identified. Once information has been de-identified as required by law, it is no longer PHI, and we may use it for any lawful purpose.
Other Uses and Disclosures
As permitted by HIPAA, we may disclose your PHI to:
-
Social Services Agencies
-
Public Health Authorities
-
The Food and Drug Administration
-
Health Oversight Agencies
-
Military Command Authorities
-
National Security and Intelligence Organizations
-
Correctional Institutions
-
Organ and Tissue Donation Organizations
-
Coroners, Medical Examiners, and Funeral Directors
-
Workers Compensation Agents
We may also disclose PHI to those assisting in disaster relief efforts so that family or friends can be notified about your condition, status, and location.
Incidental Uses and Disclosures
Sometimes, your PHI may be used or disclosed in the course of our primary uses and disclosures, such as for treatment, payment, or healthcare operations. For example, our phlebotomist may use your name when confirming your scheduled visit at the door of your home or office, or in a telephone conversation with your healthcare provider. We are permitted to make such incidental uses and disclosures as long as we take reasonable steps to minimize them and have appropriate safeguards in place to protect them.
Note Regarding State Law
For all of the above purposes, when state law is more restrictive than federal law, we are required to follow the more restrictive state law.
Your Patient Rights
You have the right to access your PHI. You may:
-
Contact our Customer Service team at (877) 254-6399 to request your records; or
-
Submit a written or email request to our Customer Service team to obtain your PHI (requests must be signed and include enough demographic and other information necessary for us to authenticate you and identify your records).
If your request for test information is denied, you may request that the denial be reviewed.
Amend Health Information
You may request amendments (changes) to your PHI by making a written request. However, we may deny the request in some cases (such as if we determine the PHI is accurate). If we deny your request to change your PHI, we will provide you with a written explanation of the reason for the denial and let you know about further actions you may take.
Accounting of Disclosures
You have the right to receive a list of certain disclosures of your PHI made by Secure Draw Mobile in the past six years from the date of your written request. Under the law, this does not include disclosures made for treatment, payment, or healthcare operations or certain other purposes.
Request Restrictions
You may request that we agree to restrictions on certain uses and disclosures of your PHI. We are not required to agree to your request, except for requests to limit disclosures to your health plan for purposes of payment or healthcare operations when you have paid us for the item or service covered by the request out-of-pocket and in full and when the uses or disclosures are not required by law.
Request Confidential Communications
You have the right to request that we send your health information by alternative means or to an alternative address, and we will accommodate reasonable requests.
Copy of this Notice
You have the right to obtain a paper copy of this Notice upon request.
How to Exercise Your Rights
You may write or send an email to us with your specific request. Please refer to the Contact Information below. Secure Draw Mobile will consider your request and provide you a response.
Complaints / Questions / Contact Information
If you believe your privacy rights have been violated, you have the right to file a complaint with us. You also have the right to file a complaint with the Secretary of the U.S. Department of Health and Human Services, Office for Civil Rights. Secure Draw Mobile will not retaliate against any individual for filing a complaint.
To file a complaint with us, or should you have any questions about this Notice, send an email to us at Support@securedrawmobile.com, or write to us at the following address:
Secure Draw Mobile Inc. Attention: Privacy Officer 2450 Colorado Ave, Suite 100E Santa Monica, CA 90404
You may also contact our Customer Service Department at (877) 254-6399.
We reserve the right to amend the terms of this Notice to reflect changes in our privacy practices, and to make the new terms and practices applicable to all PHI that we maintain about you, including PHI created or received prior to the effective date of the Notice revision. Our Notice is displayed on our website, and a copy is available upon request.
Non-Discrimination Notice
We comply with applicable Federal civil rights laws and do not discriminate on the basis of race, color, national origin, age, disability, or sex. Secure Draw Mobile does not exclude people or treat them differently because of race, color, national origin, age, disability, or sex.
Secure Draw Mobile provides language services free of charge to people whose primary language is not English, including qualified interpreters.
Secure Draw Mobile provides aids and services free of charge to people with disabilities to communicate effectively with us, including:
-
Auxiliary aids and services
-
Written information in other formats (audio, accessible electronic formats, other formats)
If you need these services, contact (877) 254-6399.
If you believe that Secure Draw Mobile has failed to provide these services or discriminated in another way on the basis of race, color, national origin, age, disability, or sex, you can file a grievance with:
Secure Draw Mobile Inc. Civil Rights Coordinator 2450 Colorado Ave, Suite 100E Santa Monica, CA 90404 Phone: (877) 254-6399 Email: Support@securedrawmobile.com
You can file a grievance in person, by mail, or by email. If you need help filing a grievance, the Civil Rights Coordinator is available to help you.
You can also file a civil rights complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, electronically through the Office for Civil Rights Complaint Portal, available at https://ocrportal.hhs.gov/ocr/portal/lobby.jsf, or by mail or phone at:
U.S. Department of Health and Human Services 200 Independence Avenue, SW Room 509F, HHH Building Washington, D.C. 20201 (800) 368-1019 (800) 537-7697 (TDD)
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is a law intended to enhance privacy rights and consumer protection for residents of the state of California. The CCPA and CPRA apply to certain business entities that do business in California.
For details about the types of Personal Information we collect about you, the sources of that information, how we use the information (including our business or commercial purposes for collecting or selling Personal Information), the parties with whom we share Personal Information, and the specific pieces of Personal Information we have collected about you, please refer to our Privacy Policy at https://www.securedrawmobile.com/privacy-policy.
The following rights apply to all California residents (excluding legal entities such as companies):
-
The Right to Know: The right to receive ("access") a copy of your Personal Information.
-
The Right to Correct: The right to request correction of inaccurate Personal Information.
-
The Right to Delete: The right to request deletion of your Personal Information.
-
The Right to opt Out of Sharing: The right to opt out of certain disclosures ("sharing") of your Personal Information.
-
The Right to Limit Use of Sensitive Personal Information: The right to limit the use or disclosure of your sensitive Personal Information.
We collect sensitive Personal Information when (i) we collect your IP address when you visit a website related to your health information, or (ii) you are an employee or contractor of Secure Draw Mobile Inc. You can limit the use or disclosure of your sensitive Personal Information described in (i) by interacting with the cookie banner that appears on our website, or by using the "Your Privacy Choices" link in the footer of our website. With regard to (ii), we do not use your sensitive Personal Information for any purpose that is subject to limitation. In addition, we may collect sensitive Personal Information as part of protected health information. Please note that such sensitive Personal Information is subject to our HIPAA Notice of Privacy Practices and not subject to the CCPA/CPRA.
These rights will not apply if Secure Draw Mobile Inc. does not collect any Personal Information about you, or if all of the information we collect is exempt from the statute (for example, the CCPA and CPRA do not protect information that is already protected by certain other privacy laws such as HIPAA, and do not protect information that is already publicly available).
How to Make a Request Under CCPA/CPRA
To exercise any of your rights under the CCPA or CPRA, please contact us at:
-
Email: Support@securedrawmobile.com
-
Phone: (877) 254-6399
-
Mail: Secure Draw Mobile Inc., 2450 Colorado Ave, Suite 100E, Santa Monica, CA 90404
We will respond within the timeframes required by law. We may need to verify your identity before processing your request.
"Shine the Light" Law
Under California Civil Code Section 1798.83, California residents with whom we have an established business relationship are entitled to request and receive, free of charge, once per calendar year, information about the Personal Information we shared, if any, with other businesses for their own direct marketing uses during the prior year. To make such a request, contact us at Support@securedrawmobile.com.
Effective Date: May 8, 2026 Last Updated: May 8, 2026
