top of page

Privacy Policy & HIPAA Notice

​Effective Date August 28, 2026
Last Updated August 28, 2026

This Privacy Policy describes how we collect, use, safeguard, and disclose personal and medical information when we represent individuals seeking Social Security Disability Insurance (SSDI) or Supplemental Security Income (SSI) benefits

1. Statutory Context & HIPAA Compliance Framework

Under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations (45 C.F.R. Parts 160 and 164), non-provider entities such as legal representatives and advocates are generally not classified as direct "Covered Entities." However, because representing Social Security Disability claimants requires collecting, reviewing, and transmitting Protected Health Information (PHI):

We adhere strictly to HIPAA Privacy, Security, and Breach Notification standards to protect the confidentiality of all medical records, diagnostic test results, mental health records, and treatment histories obtained on your behalf.

When operating under a Business Associate Agreement (BAA) with covered health care providers or third-party vendors, we fulfill all statutory obligations imposed on Business Associates under the HIPAA Omnibus Rule.

Federal Privacy Laws: Information disclosed to the Social Security Administration (SSA) or state Disability Determination Services (DDS) is additionally protected under the Privacy Act of 1974 (5 U.S.C. § 552a) and Section 1106 of the Social Security Act.

 

2. Information We Collect

To evaluate, file, and appeal your Social Security Disability claim, we collect personal and health data from you, your medical providers, and government agencies.

A.  Protected Health Information (PHI)

Complete medical records, outpatient/inpatient treatment notes, and physician evaluations.

Diagnostic imaging, lab results, operating notes, and pharmacy records.

Psychological evaluations, therapy notes, and psychiatric intake assessments.Functional Capacity Evaluations (FCEs), treating source statements, and vocational reports.

B.  Personally Identifiable Information (PII) & Financial Data

Social Security Numbers (SSNs), dates of birth, tax filings (W-2s, 1099s), and work history.

Bank account details (for fee arrangements and direct deposit setup).

Contact details (mailing address, email addresses, phone numbers).

C.  Digital Data (Website & Intake Portals)

IP addresses, browser types, session activity, and secure web portal login.

 

3. How We Use Your Information

We process and use your PHI and PII strictly for purposes directly related to your disability claim:

  • Claim Preparation & Adjudication -- Gathering evidence to prove your physical or mental impairments meet SSA rules.

  • Representation Before the SSA -- Submitting forms, briefs, and medical records to SSA Field Offices, State DDS Offices, Administrative Law Judges (ALJs), the Appeals Council, or Federal District Courts.

  • Medical Record Procurement -- Releasing formal authorization requests (e.g., Form SSA-827 or practice-specific HIPAA releases) to hospitals, clinics, and physicians.

  • Administrative & Practice Operations -- Case tracking, accounting, quality control, and client communications.

 

4. Disclosures of Information

We do not sell, rent, or trade your personal or medical information. We disclose PHI and personal data only as permitted by HIPAA, federal law, and your authorization:

  • To Government Agencies -- The Social Security Administration (SSA), Disability Determination Services (DDS), and the Office of Hearing Operations (OHO) for claim adjudication.

  • To Healthcare Providers -- Requesting updated medical evidence or sending treating source questionnaires.

  • To HIPAA-Compliant Vendors (Business Associates) -- Secure cloud storage providers, electronic fax services, record retrieval services, and legal software systems. All vendors are bound by written Business Associate Agreements (BAAs) requiring equal or greater safeguards.

  • As Required by Law -- Pursuant to court orders, subpoenas, or mandatory child/elder abuse reporting requirements.

 

5. HIPAA Security Rule Safeguards

We maintain administrative, physical, and technical safeguards designed to protect electronic PHI (ePHI) from unauthorized access, use, or disclosure:

  • Technical Controls -- End-to-end encryption for data in transit (TLS/SSL) and at rest (AES-256); secure client portals; multi-factor authentication (MFA); and strict role-based access restrictions.Administrative Controls: Mandatory staff HIPAA and privacy training; routine internal security audits; and strict password and access-revocation policies.

  • Physical Controls -- Locked file cabinets for hard-copy case files; secure paper shredding protocols; and restricted access to physical offices.

 

6. Your Rights Regarding Your PHI

Under our privacy policies and applicable health privacy laws, you retain the following rights:

1.  Right to Inspect and Copy -- You may request access to or copies of your representation case file and medical records maintained in our system.

2.  Right to Revoke Authorization -- You may revoke your HIPAA authorization allowing us to obtain medical records at any time in writing, except to the extent action has already been taken based on that authorization.

3.  Right to Request Restrictions -- You may request restrictions on how we use or share certain PHI, though we reserve the right to decline if doing so prevents us from adequately representing your claim before the SSA.

4.  Right to Accounting of Disclosures -- You may request a log of non-routine disclosures of your PHI made by our office outside of standard legal representation activities.

5.  Right to Notification of Breach -- In the event of an unauthorized acquisition, access, use, or disclosure of unencrypted PHI, we will notify you promptly in compliance with the HIPAA Breach Notification Rule.

 

7.   Data Retention and Destruction

We retain your case files, personal data, and medical records for as long as necessary to fulfill the legal representation, comply with state bar/advocate record retention rules, and satisfy administrative recordkeeping requirements. Upon expiration of the retention period, physical records are cross-cut shredded and digital files are permanently erased using secure data sanitization standards.

 

8. Third-Party Websites & Communications

  • Texting & Unencrypted Email -- Standard SMS and standard email are not completely secure. By providing your email address or mobile number, you acknowledge these risks. We provide a secure online portal for transferring sensitive PHI.

  • Third-Party Links -- Our website may contain links to external sites (e.g., SSA.gov). We are not responsible for the privacy practices of external third-party sites.

 

9. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy to reflect changes in legal requirements, internal practice operations, or technology. Any changes will be posted on our website with an updated "Last Updated" date.

 

10. Privacy Officer & Contact Information

If you have questions about this Privacy Policy, wish to exercise your rights, or believe your privacy rights have been violated, please contact our designated Privacy Officer.

 

Randi E. Lappin

Focus Disability Advocates, Inc.

P.O. Box 3130, Sewanee, TN 37375

(423) 225-4439

randilappin@focusdisabilityadvocates.com

 

If you believe your HIPAA rights have been violated, you also have the right to file a complaint with the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services.

bottom of page