Legal Entity
Detroit Health Clinic PLLC
DBA Monarch Lifestyle Medicine
HIPAA Compliance Notice
Last Updated: September 13, 2026
This HIPAA Compliance Notice describes how Detroit Health Clinic PLLC, doing business as Monarch Lifestyle Medicine ("Monarch," "we," "us," or "our"), protects the privacy and security of your Protected Health Information (PHI) in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the HIPAA Privacy Rule, the HIPAA Security Rule, and the HITECH Act. As a HIPAA-covered entity, we are committed to maintaining the confidentiality, integrity, and availability of your health information.
1. Covered Entity Status
Detroit Health Clinic PLLC DBA Monarch Lifestyle Medicine is a HIPAA-covered healthcare provider. We provide healthcare services and transmit health information electronically in connection with transactions for which the U.S. Department of Health and Human Services (HHS) has adopted standards. All references to "Monarch" in this notice refer to Detroit Health Clinic PLLC DBA Monarch Lifestyle Medicine.
2. Protected Health Information (PHI)
Protected Health Information (PHI) is any individually identifiable health information — including demographic data — that relates to your physical or mental health condition, the provision of healthcare to you, or payment for that care. This includes, but is not limited to:
- Name, address, date of birth, and contact information
- Medical history, diagnoses, and treatment plans
- Laboratory results and diagnostic test results
- Prescription and medication records
- Appointment records and clinical notes
- Billing and insurance information linked to your care
3. Administrative Safeguards
We maintain administrative safeguards — the policies and procedures that govern how our workforce manages PHI — including:
- A designated Privacy Officer and Security Officer responsible for HIPAA compliance and oversight
- Workforce training on HIPAA Privacy and Security Rules for all employees and contractors with access to PHI
- Role-based access controls limiting PHI access to the minimum necessary for each staff member's job function
- Business Associate Agreements (BAAs) with all vendors and service providers who handle PHI on our behalf
- Documented sanction policies for workforce members who violate our privacy and security policies
- Regular risk assessments to identify and address vulnerabilities in our handling of PHI
4. Physical Safeguards
We implement physical safeguards to protect the facilities and equipment that store or access PHI:
- Restricted facility access with controlled entry to areas containing PHI
- Secure storage and disposal of physical records containing PHI
- Workstation security policies governing the use and positioning of devices that access PHI
- Device and media controls for the transfer, removal, disposal, and re-use of electronic media containing PHI
5. Technical Safeguards
We deploy technical safeguards to protect electronic PHI (ePHI) from unauthorized access, alteration, or destruction:
- Encryption of ePHI in transit and at rest using industry-standard protocols
- Unique user identification and authenticated access to systems containing ePHI
- Automatic logoff and session timeout for inactive workstations
- Audit logging and monitoring of access to ePHI to detect and respond to unauthorized activity
- Integrity controls to verify that ePHI has not been altered or destroyed in an unauthorized manner
- Secure transmission controls including SSL/TLS encryption for all web-based interactions
6. Permitted Uses and Disclosures
We may use and disclose your PHI for the following purposes without your separate written authorization:
- Treatment: Sharing PHI with physicians, specialists, and other healthcare providers involved in your care
- Payment: Using PHI to bill insurance carriers or process payments for services rendered
- Healthcare Operations: Using PHI for quality assurance, training, and practice management activities
- As required by law: Disclosing PHI when mandated by federal, state, or local law
- Public health and safety: Reporting to public health authorities for disease control, adverse event reporting, or to avert a serious threat to health or safety
Any use or disclosure of PHI not described above requires your written authorization. You may revoke an authorization in writing at any time, except to the extent we have already acted in reliance on it.
7. Minimum Necessary Standard
When using, disclosing, or requesting PHI, we make reasonable efforts to limit the information to the minimum necessary to accomplish the intended purpose. This standard does not apply to disclosures to or requests by a healthcare provider for treatment, or to disclosures made to you or required by law.
8. Your Rights Under HIPAA
Under HIPAA, you have the following rights regarding your PHI:
- Right to access: Request and receive a copy of your medical records and PHI in electronic or paper format
- Right to amend: Request a correction to your PHI if you believe it is inaccurate or incomplete
- Right to an accounting of disclosures: Request a list of certain disclosures of your PHI we have made outside of treatment, payment, and healthcare operations
- Right to request restrictions: Request additional restrictions on how we use or disclose your PHI for treatment, payment, or operations
- Right to confidential communications: Request that we communicate with you about your care through alternative means or at alternative locations
- Right to a paper copy of this notice: Request a printed copy of this HIPAA Compliance Notice at any time
To exercise any of these rights, submit a written request to our Privacy Officer using the contact information provided below. We may charge a reasonable, cost-based fee for copies of your records.
9. Breach Notification
In the event of a breach of unsecured PHI, we will follow the HIPAA Breach Notification Rule. We will notify affected individuals in writing without unreasonable delay and no later than 60 days following discovery of the breach. Notifications will include a description of the breach, the types of information involved, steps individuals can take to protect themselves, what we are doing in response, and contact information for further inquiries. For breaches affecting 500 or more individuals, we will also notify the U.S. Department of Health and Human Services and prominent media outlets serving the affected area.
10. Business Associates
We contract with third-party service providers — including electronic health record vendors, laboratory partners, billing services, and telehealth platforms — who may access PHI while performing services on our behalf. Each of these business associates is required to sign a Business Associate Agreement (BAA) obligating them to safeguard PHI in compliance with HIPAA and to report any breaches to us immediately.
11. Website and Electronic Communications
Our website uses encryption (SSL/TLS) to protect information transmitted between your browser and our servers. However, no method of electronic transmission or storage is completely secure. We do not place sensitive health information — such as diagnoses, treatment details, lab values, or medication names — into cookies, URL parameters, analytics tags, or advertising platforms. Any PHI you submit through our online forms is transmitted securely and stored only within HIPAA-compliant systems. Please avoid including detailed medical information in unsecured email or general contact forms; instead, share clinical details during your secure consultation or patient portal communication.
12. Complaints
If you believe your privacy rights have been violated, you may file a complaint with us and/or with the U.S. Department of Health and Human Services Office for Civil Rights (OCR). We will not retaliate against you for filing a complaint. To file a complaint with us, contact our Privacy Officer using the information below. To file a complaint with the OCR, visit hhs.gov/ocr or call 1-877-696-6775.
13. Changes to This Notice
We reserve the right to update or change this HIPAA Compliance Notice at any time. The current version will always be posted on our website with the effective date noted above. We will provide a revised notice in our waiting area and upon request.
14. Contact Us
If you have questions about this HIPAA Compliance Notice, wish to exercise your rights, or need to file a complaint, please contact our Privacy Officer:
Detroit Health Clinic PLLC
DBA Monarch Lifestyle Medicine — Attn: Privacy Officer
1555 E South Blvd, Suite 340
Rochester Hills, MI 48307
Phone: (248) 592-7112
Email: info@monarchlifestylemed.com
Questions About Your Health Information Privacy?
Our team is available to help with any questions about how we protect your Protected Health Information under HIPAA.
Contact Us