Notice Of Privacy Practices

Tristan Cooper MD PLLC, DBA NextDayDoctor Medical Group  ·  Version 2.6

Notice of Privacy Practices

Tristan Cooper MD PLLC, DBA NextDayDoctor Medical Group

Effective Date: August 26, 2026


THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

This Notice of Privacy Practices ("Notice") describes the privacy practices of Tristan Cooper MD PLLC, DBA NextDayDoctor Medical Group (the "Practice," "we," "us," or "our"). The Practice is the health care provider and HIPAA Covered Entity responsible for your clinical care and medical records. This Notice applies to Protected Health Information ("PHI") created, received, maintained, or transmitted by or for the Practice.

The Practice uses non-clinical administrative and technology support to deliver its services. NDD MSO LLC, DBA NextDayDoctor, is the Practice's direct Business Associate for management, administrative, billing, and technology services under written agreements. Strongwork LLC supports the technology through a written subcontractor Business Associate Agreement with NDD MSO LLC. Other service providers that create, receive, maintain, or transmit PHI must be covered by an applicable written Business Associate Agreement before receiving PHI. These companies support the Practice but do not control clinical judgment, diagnose, prescribe, or provide medical care.

We are required by law to:

  • Maintain the privacy and security of your PHI;
  • Give you this Notice of our legal duties and privacy practices;
  • Notify affected individuals following a breach of unsecured PHI when notification is required; and
  • Follow the terms of the Notice currently in effect.

We reserve the right to change this Notice and make the revised practices effective for all PHI we maintain, including PHI created or received before the revision. We will not implement a material change before the effective date of a revised Notice unless law requires otherwise. The current Notice will be posted on our website and made available on request. When required or reasonably appropriate, registered users will also receive notice by email and through an in-app notice.


1. Key Terms

Protected Health Information ("PHI") is individually identifiable health information created or received by the Practice or a Business Associate that relates to your health, health care, or payment for health care and is protected by HIPAA.

Designated Record Set means the records maintained by or for the Practice that are used, in whole or in part, to make decisions about you. Depending on your care, this may include intake information, consultation notes, finalized clinical documentation, prescription records, visit summaries, retained telehealth transcripts, and clinical messages.

Business Associate means a person or entity that performs certain functions for the Practice involving PHI under a written Business Associate Agreement. A subcontractor Business Associate performs such a function for another Business Associate and is subject to corresponding HIPAA safeguards.

Part 2 Records means substance use disorder patient records protected by 42 U.S.C. 290dd-2 and 42 C.F.R. Part 2.


2. How We May Use and Disclose PHI

Treatment

We may use and disclose PHI to provide, coordinate, or manage your care. For example, we may share relevant information with a treating clinician, pharmacy, laboratory, or specialist involved in your care.

Payment

The Practice currently provides services on a cash-pay basis and does not submit claims to health insurers. We may use PHI to obtain payment, maintain billing records, issue refunds, respond to charge questions, and administer payment-related operations. A payment processor receives the payment-card, transaction, and fraud-prevention information needed to process an authorized charge; the Practice does not provide clinical information to the payment processor for that function. The processor's handling of financial information may also be governed by its own privacy notice and applicable financial-privacy law.

When a prescription is sent electronically, the prescription message may include an identifier for an optional cash-discount program so the pharmacy can determine whether a discounted cash price is available. The program is not health insurance, does not affect clinical decision-making, and is not a condition of treatment. You may ask the pharmacy not to use it and may use another discount program or available cash price. Entities supporting electronic prescribing may receive reduced transaction charges when the identifier is included.

Health Care Operations

We may use and disclose PHI for lawful health care operations, including quality assessment and improvement, patient support, care coordination, credentialing, training, compliance, audits, security, fraud prevention, business planning, and evaluating clinician or service performance.

The Practice and its Business Associates may create information that is de-identified under HIPAA. Once properly de-identified, the information is no longer PHI. Under our agreements, de-identified information may be used for internal operations, security, quality assessment, and service improvement. The Practice does not sell de-identified information, and does not license, commercialize, or disclose it to an outside third party except with the patient's authorization, under a separate written authorization signed by the Practice, or as required by law.

A narrow exception applies to specialized service providers whose standard terms the Practice and its Business Associates are not able to negotiate — for example, the network that routes electronic prescriptions to pharmacies. Where such a service is necessary to your care and no alternative is reasonably available on different terms, that provider's own agreement may permit it to create and use de-identified information derived from the transactions it processes, including for the provider's own commercial purposes. The Practice permits this only under a separate written authorization, only for the specific service named in that authorization, and only after the reasons for accepting those terms have been recorded in writing. Information handled in this way must still meet the HIPAA de-identification standard, and neither the Practice nor its Business Associates permit re-identification. You may ask the Privacy Officer which services currently operate under such an authorization.

Business Associates and Other Service Providers

We may disclose PHI to Business Associates that perform authorized services for the Practice, including management and administrative support, secure hosting and storage, communications, telehealth, transcription, AI-assisted services, electronic prescribing, records administration, and security. Each Business Associate and subcontractor that handles PHI must protect it and use or disclose it only as permitted by its written agreement and applicable law.

AI-Assisted Features

The Practice uses AI-assisted services in staff-facing and patient-facing workflows. Staff-facing tools may assist with transcription, preparation of draft clinical documentation, information organization, and care coordination. Patient-facing tools may organize information you provide during booking or intake for a clinician's review, provide general health information, or assist with navigation and support.

Patient-facing AI features do not diagnose, prescribe, or make clinical decisions. General information produced by an AI-assisted feature is informational only and is not a substitute for professional medical advice. A licensed clinician remains responsible for clinical decisions and reviews and approves clinical documentation before it becomes part of the medical record.

When an AI-assisted service processes PHI, it does so through a service covered by an applicable written Business Associate Agreement. PHI is not used to train third-party AI models. Records maintained in the Practice's Designated Record Set remain subject to applicable access and amendment rights regardless of whether an AI-assisted tool helped prepare them.

Before materially changing the nature or scope of AI-assisted processing of PHI, or deploying a materially new category of patient-facing AI feature that processes PHI, the Practice will revise this Notice and provide any additional notice or obtain any consent required by applicable law.

Real-Time Video Visit Transcription

Video visits are transcribed in real time as a required feature of the Practice's video telehealth service. Audio is processed during the visit to generate a text transcript for clinical documentation, but raw audio is not retained after transcription. A visual indicator shows participants that transcription is active. The treating clinician reviews and finalizes any AI-assisted draft note before it enters the medical record. A retained transcript is part of the Designated Record Set and is subject to applicable access and amendment rights.

The Practice provides notice and obtains any consent required for transcription through the applicable telehealth consent and encounter workflow. If the Practice later uses transcription for another materially different category of encounter, it will update its notices and consent workflow as required before that use begins.

People Involved in Your Care or Payment for Care

With your agreement or when permitted by law, we may share relevant PHI with a family member, friend, personal representative, or other person involved in your care or payment for care. If you are unavailable or incapacitated, we may use professional judgment to decide whether a disclosure is in your best interests.

Other Uses and Disclosures Permitted or Required by Law

We may use or disclose PHI without your authorization when HIPAA and other applicable law permit or require it, including for:

  • Public-health activities and required disease or injury reporting;
  • Reports concerning abuse, neglect, or domestic violence;
  • Health-oversight activities, licensing, audits, and investigations;
  • Judicial or administrative proceedings when legal requirements are satisfied;
  • Certain law-enforcement purposes;
  • Coroners, medical examiners, and funeral directors;
  • Organ, eye, or tissue donation;
  • Research approved or permitted under applicable privacy requirements;
  • Prevention or reduction of a serious and imminent threat to health or safety;
  • Certain military, veterans, national-security, correctional, or workers' compensation purposes;
  • Disclosures to the U.S. Department of Health and Human Services to investigate HIPAA compliance; and
  • A lawful transfer, merger, or succession involving the Practice, subject to continuing privacy obligations and applicable notice requirements.

These descriptions do not override a more protective federal or state law. Where another law materially limits a use or disclosure that HIPAA would otherwise permit, we follow the more protective law.

Uses and Disclosures Requiring Written Authorization

Most uses and disclosures of psychotherapy notes, uses and disclosures for marketing, and disclosures that constitute a sale of PHI require your written authorization, subject to exceptions in applicable law. Other uses and disclosures not described in this Notice will be made only with your written authorization. You may revoke an authorization in writing at any time, except to the extent we have already acted in reliance on it. We will not condition treatment on an authorization except where law permits.

We do not use PHI for fundraising. If that practice changes, we will revise this Notice before the change and provide a clear way to opt out of fundraising communications.

Information lawfully disclosed under HIPAA may be redisclosed by a recipient and may no longer be protected by HIPAA. Other laws or contractual duties may still protect it. Special protections for Part 2 Records are described in Section 5.


3. Your Rights Regarding PHI

To exercise a right described below, contact the Privacy Officer using Section 7. We may ask you to make the request in writing and verify your identity or authority. We will respond within the time required by applicable law.

Access and Copies

You may inspect or obtain a copy of PHI in the Practice's Designated Record Set. If the information is maintained electronically, you may request an electronic copy in a readily producible form and format. You may also direct us in writing to send a copy to another person when legal requirements are met. We ordinarily respond within 30 days and may use one additional 30-day extension when permitted, with written notice of the reason and expected completion date.

We may charge only a reasonable, cost-based fee permitted by law. We may deny access in limited circumstances. When a denial is reviewable, we will explain how to request review by a licensed health care professional who did not participate in the original decision.

Amendment

You may ask us to amend PHI in the Designated Record Set if you believe it is incorrect or incomplete. Your written request must explain the reason. We ordinarily act within 60 days and may use one additional 30-day extension when permitted, with written notice. We may deny a request in circumstances allowed by law, including when the information was not created by us, is not part of the applicable records, is not available for inspection, or is accurate and complete. If denied, you may submit a statement of disagreement as permitted by law.

Accounting of Disclosures

You may request an accounting of certain disclosures made during the six years before your request. The accounting generally does not include disclosures for treatment, payment, or health care operations or disclosures made under your written authorization. Your first accounting in a 12-month period is free; we may charge a reasonable, cost-based fee for an additional accounting after telling you the cost and giving you an opportunity to withdraw or modify the request.

Restrictions

You may ask us to restrict certain uses or disclosures for treatment, payment, or health care operations. We are not required to agree to most requested restrictions. If we agree, we will comply except as permitted by law, including when information is needed for emergency treatment.

If you pay a health care item or service in full out of pocket and ask us not to disclose PHI about that item or service to a health plan for payment or health care operations, we must agree unless the disclosure is required by law. Because the Practice is cash-pay, this right may apply broadly, but you must still make the request.

You may request a restriction on discretionary AI-assisted processing by contacting the Privacy Officer. We will consider the request but are not required to agree if the processing is part of treatment, is required by law, or is integral to the secure delivery or documentation of the service. We will not state that we have accepted a restriction unless we can reliably implement it through the applicable Business Associate chain.

Confidential Communications

You may ask us to contact you about PHI by an alternative reasonable means or at an alternative reasonable location. Tell us the method or location you want us to use.

Paper Copy

You may request a paper copy of this Notice at any time, even if you previously received or agreed to receive it electronically.

Personal Representatives and Minor Patients

A personal representative may exercise rights for another person to the extent authorized by applicable law. Parent or guardian access to a minor's records depends on the law governing the care and the circumstances in which the minor consented. Some laws give minors independent privacy rights for particular services and may limit parent or guardian access. Contact the Privacy Officer with questions about a particular request.


4. Breach Notification

If a breach of unsecured PHI occurs, the Practice will provide notification without unreasonable delay and no later than 60 calendar days after discovery when HIPAA requires individual notice. A shorter deadline or additional notice may apply under state or other federal law.

Business Associates and subcontractors must report potential breaches and security incidents through the contractual chain so the Practice can investigate, make the required legal determinations, mitigate harm, and provide any required notice. An individual notice will describe, to the extent known, what happened, the information involved, steps you can take, what is being done in response, and how to ask questions. The Practice will also notify regulators and, where required, the media or the public in the manner and time required by law.


5. Specially Protected Information and State Law

Substance Use Disorder Records

When 42 C.F.R. Part 2 applies, we follow its additional protections. Part 2 Records received from a Part 2 program, and testimony describing their contents, may not be used or disclosed in a civil, criminal, administrative, or legislative proceeding against you unless you give written consent or a qualifying court order is issued after the required notice and opportunity to be heard. A court order authorizing a use or disclosure must be accompanied by a subpoena or other legal requirement compelling disclosure before the record is used or disclosed.

Uses and disclosures of Part 2 Records for treatment, payment, health care operations, legal proceedings, and other purposes remain subject to Part 2 and any other more protective law. If the Practice creates or maintains records as a Part 2 program, any additional Part 2 notice, consent, breach, or fundraising requirement also applies. The Practice does not currently use Part 2 Records for fundraising.

Other More Protective Laws

Federal or state law may provide added protection for mental-health information, HIV or other communicable-disease information, genetic information, reproductive-health information, records concerning minors, and other sensitive information. We follow a more protective law when it applies.

State consumer-health and comprehensive privacy laws may separately apply to health-related information that is not PHI. The NextDayDoctor Privacy Policy describes those practices and available consumer rights. If this Notice and the Privacy Policy address the same PHI, this Notice controls for the Practice's HIPAA obligations.

Record Retention

The Practice has adopted a minimum ten-year clinical-record retention period measured from the later of the last encounter to which a record relates or the Practice's receipt or production of the record. A longer period controls when required by the patient's jurisdiction, record category, age, a claim, investigation, payor requirement, preservation notice, or legal hold. Under Nevada law, health care records generally must be retained for at least five years after receipt or production and may not be destroyed while the person who is the subject of the record is under age 23. Records are securely disposed of only after all applicable periods and holds expire.

HIPAA separately requires retention of specified compliance documentation for six years from creation or the date last in effect, whichever is later. That HIPAA rule is not a general medical-record retention period.


6. Telehealth Privacy

PHI is transmitted electronically during telehealth services. We use reasonable administrative, technical, and physical safeguards designed to protect PHI during transmission and storage, but no system can guarantee absolute security.

Your surroundings and device also affect privacy. Use a private location and a device and network you trust when possible. Other people with access to a shared device, email account, telephone number, or network may be able to see appointment or account information. Tell the clinician if another person is present during a visit.

Privacy and record-access laws may depend on your physical location when care is delivered. The Practice follows applicable law in each jurisdiction where it provides care and applies a more protective rule when required.


7. Questions, Requests, and Complaints

For questions about this Notice, to exercise a privacy right, or to file a complaint with the Practice, contact:

Privacy Officer, NextDayDoctor Medical Group
Tristan Cooper MD PLLC, DBA NextDayDoctor Medical Group
c/o NextDayDoctor
9205 West Russell Road, Suite 240
Las Vegas, Nevada 89148
Phone: (619) 639-8329 (ask for the Privacy Officer)
Email: privacy@nextdaydoctor.com

You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights:

Office for Civil Rights
U.S. Department of Health and Human Services
200 Independence Avenue, S.W.
Washington, D.C. 20201
Toll-free: 1-877-696-6775
Website: https://www.hhs.gov/ocr/privacy/hipaa/complaints/

We will not retaliate against you, deny care, or change the quality of your care because you asked a privacy question, exercised a privacy right, or filed a complaint.


8. Availability and Acknowledgment

We will provide this Notice no later than the first service delivery, including an electronic service, except that in an emergency we may provide it as soon as reasonably practicable afterward. If the Practice maintains a physical care location, the Notice will also be available there and posted as required by law.

Except in an emergency, we will make a good-faith effort to obtain your written or electronic acknowledgment that you received this Notice. The acknowledgment confirms receipt only; it is not consent to uses or disclosures beyond those permitted by law. Refusing or being unable to sign the acknowledgment does not waive your privacy rights and, by itself, will not prevent treatment. We may document our effort and the reason an acknowledgment was not obtained.

The current Notice is available on our website and in paper form on request.

Loading...
Loading...
Name