Privacy Policy

1. PURPOSE

The purpose of this procedure is to comply with the Administrative Safeguards of HIPAA Privacy, to secure and maintain the confidentiality of Protected Health Information, maintain sensitive organizational information at Poriferous, LLC. and prevent and detect inappropriate and illegal uses and disclosures. This procedure also includes the protections put in place by Poriferous, LLC. in regards to information collected where HIPAA does not apply.

This procedure applies to all Poriferous employees, contractors, temporary personnel, and third parties who create, receive, maintain, transmit, access, store, or otherwise process PHI, personal information, or other sensitive data on behalf of Poriferous, LLC.

2. POLICY

Poriferous, LLC. shall be responsible for implementation of the administrative requirements under the Federal HIPAA Privacy Rule.  In addition, Poriferous, LLC. is also responsible for protecting personal information, device information, and usage data provided and/or collected through communications and use of the Poriferous website.

3. DEFINITIONS

3.1 HIPAA: Health Insurance Portability and Accountability Act

3.1.1 Individually Identifiable Health Information (IIHI):  Under Section 160.103 of HIPAA, IIHI is defined as information that is a subset of health information, including demographic information collected from an individual, and:

  • Is received by Poriferous, LLC.
  • Relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual.
  • That identifies the individual.
  • With respect to which there is a reasonable basis to believe the information can be used to identify the individual.
  • IIHI includes identifiers of the patient, relatives, employers, or household members such as the following (§164.514):
    1. Names.
    2. Geographic subdivisions smaller than a State, including street address, city, county, precinct, zip code (except for the initial 3 digits of a zip code if, according to the current publicly available data from the Bureaus of the Census all zip codes with the same 3 initial digits contains more than 20,000 people).
    3. All elements of dates (except year) directly related to an individual, including birth date, admission date, discharge date, date of death, all ages over 89 and all elements of dates indicative of such age, except that such ages and elements may be aggregated into a single category of age 90 or older.
    4. Telephone numbers.
    5. Fax numbers.
    6. Email addresses.
    7. Social security numbers.
    8. Medical record numbers.
    9. Health plan beneficiary numbers.
    10. Account numbers.
    11. Certificate/license numbers.
    12. Vehicle identifiers and serial numbers, including license plate numbers.
    13. Device identifiers and serial numbers.
    14. Biometric identifiers, including finger and voice prints.
    15. Full face photographic images and any comparable images.
    16. Any other unique identifying number, characteristic, or code.

3.2 Protected Health Information (PHI): Under Section 164.501 of HIPAA, PHI means IIHI that is transmitted and maintained in electronic media or in any other form or medium.

3.3 Treatment:  The provision, coordination, or management of health care and related services, including the coordination or management of health care by a health care provider with a third party; consultation between health care providers relating to a patient; or the referral of a patient for health care from one health care provider to another (§164.501).

3.4 Provider: Under Section 160.103 of HIPAA, a provider of medical or health services (as defined in section 1861(u) of the Act, 42 U.S.C. 1395x(u) and 1861(s) of the Act, 42 U.S.C. 1395x(s)) and any other person or organization who furnishes, bills, or is paid for health care in the normal course of business.

4. HIPAA PRIVACY POLICY

4.1 Poriferous, LLC. is committed to complying with the HIPAA Privacy Rule and maintaining the confidentiality of patients’ PHI through appropriate, authorized access, uses, and disclosures.

4.2 Poriferous, LLC. receives, stores, accesses, transmits, and maintains PHI in a manner designed to preserve its confidentiality, integrity, and availability.

4.3 Confidentiality policies and procedures are reinforced throughout Poriferous, LLC. and followed by all employees and business associates.

4.4 The Regulatory Department oversees the HIPAA Privacy program.

4.5 The Regulatory Department is responsible for the following functions which support compliance with the HIPAA Privacy Rule, patient confidentiality, access laws and Poriferous, LLC. policies and procedures pertaining to them:

  • Maintain working knowledge of legislative and regulatory initiatives. Interpret and translate requirements for implementation.
  • Establish and maintain written policies and procedures that place appropriate administrative, technical, and physical safeguards to protect the privacy of PHI from intentional or unintentional uses and disclosures.
    1. Update policies and procedures as necessary and appropriate, and in compliance with Poriferous, LLC. privacy practices, to comply with changes in the law.
    2. Maintain policies and procedures (including any changes made) in written or electronic form for six years from the date of its creation or the date when it last was in effect, whichever is later.
    3. Make all reasonable efforts to limit incidental uses and disclosures.
    4. Provide training, for anyone coming into contact with PHI, on the established policies and procedures as necessary and appropriate to carry out their job functions and document the training provided.
    5. Maintain a program encouraging employees and patients to report complaints concerning compliance of the law and Poriferous, LLC. privacy policies and procedures to privacy@poriferous.com.
    6. Promptly and properly investigate and address reported violations, taking steps to prevent recurrence.
    7. Document all complaints and follow up documentation [§164.530(d)(2)].
    8. Assure there will be no intimidation, threats, coercion, discrimination against, or any other retaliatory action as a consequence to anyone who makes reports or participates in an investigation of violations in good faith [§164.530(g)].
    9. Mitigate, to the extent practicable, any harmful effect that is known to Poriferous, LLC. of a use or disclosure of PHI in violation of its policies and procedures or the requirements of the law by an employee or its business associate [§164.530(f)].
    10. Consistently enforce the law and internal policies and procedures through appropriate disciplinary mechanisms [§164.530(e)].
    11. Document and file all actions taken against employees who failed to comply with the policies and procedures [§164.530(e)(2)].
    12. Monitor, audit, and reinforce compliance with the law and Poriferous, LLC. policies and procedures.
    13. Cooperate with the Office of Civil Rights, other legal entities, and organization officers in any compliance reviews or investigations.
    14. Ensure that there are no attempts to require individuals to waive their legal rights as a condition of the provision of treatment or payment [§164.530(h)].

4.6 Patient data collected through www.poriferous.com is done so through the use of secure file transfer solutions configured to meet applicable HIPAA security and privacy requirements. Security measures for these sites include physical access control, network access control, encryption in transit using TLS and encryption at rest using AES-256 or equivalent industry-standard encryption, data retention limits, internal and external user authentication, and credential authorization.

4.7 Once data is received, an authorized Poriferous, LLC employee will download the files directly to the secure, physical server located at the Poriferous Headquarters. The file transfer solution is protected through unique user credentials and requires multi-factor authentication to access files. Data stored on the server may only be accessed by authorized personnel using unique user credentials, and the data is stored here for a period of 2 years. In use, the data is processed using internal software, located on the same secure server. Following the 2 year storage period, the data is archived to an alternate private and secured server, also housed at the Poriferous headquarters, which has greater limits to personnel access. PHI is retained in accordance with applicable federal and state legal requirements, customer contractual obligations, record retention policies, and business needs.

4.7.1 Access to PHI is limited to workforce members requiring such access to perform their job duties and is granted in accordance with the HIPAA Minimum Necessary Standard. User access to PHI is role-based and reviewed periodically to ensure that access remains appropriate to assigned job responsibilities. User access is promptly modified or terminated when employment, contractual relationships, or job responsibilities change.

4.8 The internal server is protected with a physical firewall which is monitored 24/7 by a third-party cybersecurity group. In addition, Poriferous, LLC. maintains third-party endpoint protection and holds a cybersecurity insurance policy. In-house servers are protected from electrical failure through the use of battery back-ups, which allow for safe shut-down, and from natural disaster through physical data back-ups stored in secure, fire- and water-proof locations.

4.9 Poriferous, LLC. investigates any suspected unauthorized access, use, or disclosure of PHI and provides notifications as required by applicable HIPAA Breach Notification Rule requirements.

5. GENERAL PRIVACY POLICY

5.1 Poriferous collects personal information voluntarily provided by users, including names, company names, addresses, telephone numbers, email addresses, and the contents of communications. Poriferous may also automatically collect certain device and technical information, including IP addresses, browser types and versions, operating systems, and website usage information such as pages visited, links clicked, and dates and times of access. Poriferous may use cookies, analytics tools, and similar technologies to improve website functionality, analyze website usage, and enhance user experience.

5.2 The general information collected is used to:

  • Respond to inquiries, requests, and customer service needs.
  • Provide, operate, maintain, and improve products and services.
  • Send transactional and account related communications, including by SMS when consent is provided.
  • Process orders and fulfill requests for information regarding surgical implant products.
  • Personalize and improve website experience.
  • Detect, prevent, and address technical issues, fraud, or unauthorized activity.
  • Comply with any applicable laws, regulations, and legal obligations.

5.3 When an individual provides a mobile telephone number and affirmatively opts-in, the individual expressly consents to receive recurring SMS and text messages from Poriferous at the number provided, including messages that may be sent using automated technology. Consent is not a condition of purchasing goods or services. A person may choose not to opt-in without affecting their ability to do business with Poriferous.

5.3.1 Messages may include order and account updates, appointment or follow up reminders, product information, customer support responses, and related notifications.

5.3.2 Message frequency varies based on interaction with Poriferous. Messages may be sent in response to a request and as periodic information updates.

5.3.3 Message and data rates may apply. Such charges are determined by the recipient’s mobile carrier and are the responsibility of the recipient. The recipient shall contact their wireless provider for details regarding their messaging and data plan.

5.3.4 SMS messages may be cancelled at any time by replying “STOP” to any message sent by Poriferous. Poriferous will send a confirmation message and cease to send SMS messages to that number. If another opt-in request is received, messages will be sent to that number again.

5.3.5 At any time, a recipient may reply “HELP” to a message, call 770-683-3855, or email sales@poriferous.com to receive assistance.

5.3.6 Carriers are not liable for delayed or undelivered messages.

5.3.7 No mobile information, SMS opt-in data, or text messaging consent information will be shared with third parties or affiliates for marketing or promotional purposes. Information may be shared with service providers and subcontractors that perform functions on behalf of Poriferous, such as customer service, messaging delivery, hosting, or technical support, solely to the extent necessary to provide those services. SMS opt-in data and consent records will not be sold or shared with third parties for their independent marketing purposes.

5.4 Poriferous does not sell personal information. Information may be shared in the limited circumstances described below:

  • With trusted vendors who perform services on behalf of Poriferous, such as hosting, messaging delivery, analytics, and customer support, who are obligated to protect personal information.
  • When required to comply with applicable law, regulation, legal process, or enforceable governmental request.
  • To protect the rights, property, or safety of Poriferous LLC, its customers, or others, and to detect or prevent fraud or security issues.
  • In connection with a merger, acquisition, financing, or sale of assets, subject to the protections of this policy.

For additional information regarding SMS communications and mobile information sharing practices, see Section 5.3.7.

5.4.1 Personal information shall be retained only for as long as reasonably necessary to fulfill the purposes described in this policy, comply with legal obligations, resolve disputes, and enforce agreements, unless a longer retention period is required or permitted by law.

5.5 While Poriferous implements reasonable administrative, technical, and physical safeguards designed to protect personal information, no method of transmitting or storing information electronically is completely secure. Accordingly, Poriferous cannot guarantee absolute security. It is the responsibility of the user to ensure personal account credentials remain confidential.

5.6 Dependent upon applicable jurisdiction and law, users may have the following rights regarding their personal information:

  • Access their personal information.
  • Request correction of inaccurate or incomplete information.
  • Request deletion of their personal information, subject to legal exceptions.
  • Opt-out of marketing communications, including by replying “STOP” to SMS messages.
  • Withdraw consent where processing is based on consent.

A user must contact Poriferous to exercise any of these rights, and Poriferous shall respond to the request as required by applicable law. Certain states may provide additional privacy rights. Poriferous shall honor such rights where applicable under state law.

5.7 The website and services provided by Poriferous are intended for healthcare professionals and other adults and are not directed to children under the age of 13. In accordance with the Children’s Online Privacy Protection Act (COPPA), Poriferous does not knowingly collect personal information from children under 13. If Poriferous becomes aware that personal information has been collected from a child under the age of 13 without appropriate authorization, Poriferous shall take reasonable steps to delete such information promptly.

5.8 This policy may be updated to reflect changes in practices, technology, legal requirements, or other factors. When changes are made, they shall be recorded in the change control table at the end of this document. Users are encouraged to review this policy periodically, as continued use of services following changes constitutes acceptance of the updated policy.

5.9 If a user has questions or concerns regarding this policy or relevant data practices, they may contact Poriferous directly at 770-683-3855 or sales@poriferous.com.

6. DOCUMENTATION

6.1 All documentation related to and/or required by HIPAA, including but not limited to compliance enforcement activities such as training, policies and procedures, complaint investigations, designated record sets, etc. are maintained for six years from the date of creation, or the date it was last in effect, whichever is later [§164.530(j)].  Documentation may be maintained in written or electronic form [§164.530(j)(1)(ii)] and shall be protected from unauthorized alteration, destruction, or loss.

Last updated: 9/1/26, Revision B

Translate »