Privacy Policy

Notice of Privacy Practices

Ernest Normington, MD Lewisburg Plastic Surgery
This notice describes how medical information about you may be used and disclosed and how to get access to this information. Please review this notice carefully. If you have any questions regarding this notice, you may contact us at:

Ernest Normington, MD
Lewisburg Plastic Surgery
Attention: Privacy Officer
135 Walter Drive
Lewisburg, PA 17837

Phone: (570) 524-7777
Fax: (570) 523-9165


Ernest Normington, MD/ Lewisburg Plastic Surgery, is required by the federal privacy rule to maintain the privacy of your health information that is protected by the rule, and to provide you with notice of their legal duties and privacy practices with respect to your protected health care information. We are required to abide by the terms of the notice currently in effect.

Generally speaking, your protected health information is any information that relates to your past, present or future physical or mental health or condition, the provision of health care to you, or payment for health care provided to you, and individually identifies you or reasonably can be used to identify you.

Your medical and billing records at our practice are examples of information that usually will be regarded as protected health information.


A. Treatment, Payment, and Health Care Operations

This section describes how we may use and disclose your protected health information for treatment, payment, and health care operations purposes. The descriptions include examples. Not every possible use or disclosure for treatment, payment, and health care operations purposes will be listed.

1. Treatment

We may use and disclose your protected health information for our treatment purposes as well as the treatment purposes of other health care providers. Treatment includes the provision, coordination, or management of health care services to you by one or more health care providers. Some examples of treatment uses and disclosures include:
To maintain consistent quality of care, practice physicians and other staff involved in your care may review your medical record and share and discuss your medical information with each other.

We may share and discuss your medical information with another physician, hospital, laboratory, home health agency or other health care facility to which we have referred you for care.

We may call patients by their name in the waiting room when it is time for them to go to an examination room.

We may contact you to provide appointment reminders either via mail or by telephone. This may include leaving appointment information on your answering machine.

2. Payment

We may use and disclose your protected health information for our payment purposes as well as the payment purposes of other health care providers and health plan. Payment uses and disclosures include activities conducted to obtain payment for the care provided to you or so that you can obtain reimbursement for that care. Some examples of payment uses and disclosures include:

Sharing information with your health insurer to determine whether you are eligible for coverage or whether proposed treatment is a covered service.

Submission of a claim form to your health insurer.

Providing information and documentation to your health insurer to support the medical necessity of a health service.

Mailing your bills in envelopes with our return address on the envelope.

Allowing your health insurer access to your medical record for a medical necessity or quality review audit.

Providing information to a collection agency or our attorney for purposes of securing payment of a delinquent account.

3. Health Care Operations

We may use and disclose your protected health information for our health care operation purposes as well as certain health care operation purposes of other health care providers and health plans. Some examples of health care operation purposes include:

Quality assessment

Population based activities relating to improving health or reducing health care costs.

Reviewing the competence, qualifications, or performance of health care professionals.

Accreditation, certification, licensing, and credentialing activities.

Conducting other medical review, legal services, and auditing functions.


We may use and disclose your protected health information for other purposes. This section generally describes those purposes by category. Each category includes one or more examples. Not every use or disclosure in a category will be listed. Some examples fall into more than one category - not just the category under which they are listed:

1. Individuals Involved in Care or Payment for Care

We may disclose your protected health information to someone involved in your care or payment for your care, such as a spouse, a family member, or close friend. For example: If you have surgery, we may discuss your physical limitations with a family member assisting in your post-operative care.

2. Notification Purpose

We may use and disclose your protected health information to notify or to assist in the notification of a family member, a personal representative, or another person responsible for your care, regarding a location, general condition, or death. For example: If you are hospitalized, we may notify a family member of the hospital and your general condition.

3. Required by Law

We must disclose protected health information when required by federal, state, or local law. For example: We may disclose protected health information to comply with mandatory reporting requirements involving births and deaths, child abuse, disease prevention and control, vaccine-related injuries, medical device-related deaths and serious injuries, gunshot and other injuries by a deadly weapon or criminal act, driving impairments, and blood alcohol testing.

4. Other Public Health Activities

We must disclose certain protected health information for public health activities, including:

Public health reporting of communicable diseases

Child abuse and neglect reports

FDA-related reports and disclosures

Public health warnings to third parties at risk of a communicable disease or condition.

OSHA requirements for workplace surveillance and injury reports.

5. Victims of Abuse, Neglect or Domestic Violence

We must disclose certain protected health information for purposes of reporting abuse, neglect or domestic violence in addition to child abuse. An example would be reports of elder abuse to the Department of Aging or abuse of a nursing home patient to the Department of Public Welfare.

6. Health Oversight Activities

We may use and disclose protected health information for purposes of health oversight activities authorized by law. These activities could include audits, inspections, investigations, licensure actions, and legal proceedings. For example, we may comply with a Drug Enforcement Agency inspection of patient records.

7. Judicial and Administrative Proceedings

In connection with a lawsuit or a dispute, we may disclose health information about you in response to a court or administrative order. We may also disclose medical information about you in response to a subpoena, discovery request, or other lawful process by someone else involved in the dispute, but only if we are assured that efforts have been made to inform you about the request or to obtain an order protecting the information requested. We may use and disclose health information in defending or asserting a lawsuit involving your treatment at the Practice.

8. Law Enforcement Purposes

We may disclose health information if asked to do so by a law enforcement official:

In response to a court order, subpoena, warrant, summons or similar process

To identify or locate a suspect, fugitive, material witness, or missing person

About the victim of a crime if, under certain limited circumstances, we are unable to obtain the person's agreement

About a death we believe may be the result of criminal conduct

About criminal conduct at the Practice

In emergency circumstances to report a crime; the location of the crime or victims; or the identity, description or location of the person who committed the crime.

9. Coroners and Medical Examiners

We must disclose certain protected health information for purposes of providing information to a coroner or medical examiner for the purpose of identifying a deceased patient, determining a cause of death, or facilitating their performance of other duties required by law.

10. Funeral Directors

We must disclose certain protected health information for purposes of providing information to funeral directors as necessary to carry out their duties.

11. Organ and Tissue Donation

For purposes of facilitating organ, eye and tissue donation and transplantation, we may use protected health information and disclose protected health information to entities engaged in the procurement, banking, or transplantation of cadaveric organs, eyes, or tissue.

12. Threat to Public Safety

We may use and disclose protected health information for purposes involving a threat to public safety, including protection of a third party from harm and identification and apprehension of a criminal. Any disclosure, however, would only be to someone able to help prevent that threat. For example, in certain circumstances, we are required by law to disclose information to protect someone from imminent serious harm.

13. Specialized Government Functions

We may use and disclose protected health information for purposes involving specialized government functions including:

Military and veterans activities.

National security and intelligence.

Protective services for the President and others.

Medical suitability determination for the Department of State.

Correctional institutions and other law enforcement custodial situations. If you are an inmate of a correctional institution or under the custody of a law enforcement official, we may disclose health information about you to the correctional institution or law enforcement official. This disclosure would be necessary (1) for the institution to provide you with health care; (2) to protect your health and safety or the health and safety of others; (3) for the safety and security of the correctional institutions.

14. Workers' Compensation and Similar Programs

We may use and disclose protected health information as authorized by and to the extent necessary to comply with laws relating to workers' compensation or similar programs, established by law, that provide benefits for work-related injuries or illness without regard to fault. For example, this would include submitting a claim for payment to your employer's workers' compensation carrier if we treat you for a work injury.

15. Business Associates

A business associate such as a billing company, an accountant firm, or a law firm sometimes performs certain functions of this practice. We may disclose protected health information to our business associates and allow them to create and receive protected health information on our behalf. We require these associates to agree that they will protect the privacy of your health information in the same manner that we do.

16. Research and de-identified information

We may use protected health information about you in the process of de-identifying the information. For example: Under certain circumstances, we may use and disclose health information about you for research purposes.

For example, a research project may involve comparing the health and recovery of all patients who receive one medication to those who receive another, for the same condition.

All research projects are subject to a special approval process. This process evaluates a proposed research project and its use of health information, trying to balance the research needs with patients' needs for privacy of their health information. Before we use or disclose health information for research, the project will have been approved through this research approval process.

17. Incidental Disclosures

We may disclose protected health information as by-product of an otherwise permitted use or disclosure. For example, other patients may overhear your name being paged in the waiting room.

18. Uses and Disclosures with Authorization

For all other purposes, which do not fall under a category listed under sections III.A and III.B, we will obtain your written authorization to use and disclose your protected health information. Your authorization can be revoked at any time except to the extent that we have relied on the authorization.


A. Further Restriction on Use and Disclosure

You have the right to request a restriction or limitation on the health information we use or disclose about you for treatment, payment or health care operations. We are not required to agree to your request. If we do agree, we will comply with your request unless the information is needed to provide you with emergency treatment. To request restrictions, you must make your request in writing to the privacy officer. In your request, you must tell us (1) what information you want to limit; (2) whether you want to limit our use, disclosure or both; and (3) to whom you want the limits to apply, for example, disclosure to your spouse.

You also have the right to request that we restrict use and disclosure of your health information to notify, or assist in notifying a family member, personal representative, or another person responsible for your care, your location and general condition. Without such restrictions, we may disclose health information about you to a friend or family member who is involved in your health care.

B. Confidential Communication

You have a right to request that we communicate your protected health information to you by a certain means or at a certain location. For example, you may request that we only contact you by mail or at work. We are not required to agree to confidential communications that are unreasonable.
To make a request for confidential communications, you must submit a written request to our privacy officer. The request must tell us how or where you want to be contacted. In addition, if another Individual or entity is responsible for payment, the request must explain how payment will be handled.

C. Accounting of Disclosures

You have a right to obtain, upon request, an "accounting" of certain disclosures of your protected health information by this practice or a business associate acting on behalf of us. This is a list of the disclosures of your health information we have made other than disclosures made to you, authorized by you, or made for the purposes of treatment, payment or our operations.

To request this list or accounting of disclosures, you must submit your request in writing to the Privacy Officer. Your request must state a time period, which may not be longer than six (6) years and may not include dates before April 14, 2003. Your request should indicate in what form you want the list. The first list you request within a (12) twelve-month period will be free. For additional lists, we may charge you for the cost of providing the list. We will notify you of the cost involved and you may choose to withdraw or modify your request at that time before any costs are incurred.

D. Inspection and Copying

You have a right to inspect and obtain a copy of your protected health information that we maintain in a designated record set. This right is subject to limitations and we may impose a charge for the labor and supplies involved in providing copies.
To exercise this right of access, you must submit a written request to our privacy officer. The request must (a) describe the health information to which access is requested, (b) describe how you want to access the information, such as inspection, pick-up a copy, or mailing of a copy. (c) specify any requested form or format, such as paper copy or an electronic means, and (d) include the mailing address, if applicable.

E. Right to Amendment

If you feel that health information we have about you is incorrect or incomplete, you may ask us to amend the information. You have the right to request an amendment for as long as the information is kept by or for the practice.
To request an amendment, your request must be made in writing and submitted to the privacy officer. Your request must specify each change you want and a reason must be provided in support of each requested change. We may deny your request for an amendment if it is not in writing or does not include a reason to support the request. In addition, we may deny your request if you ask us to amend information that:

Was not created by us, unless the person or entity that created the information is no longer available to make the amendment

Is not part of the health information kept by or for us

Is not part of the information which you would be permitted to inspect and copy

Is accurate and complete

F. Paper Copy of Privacy Notice

You have a right to receive, upon request, a paper copy of our Notice of Privacy Practices. This may be obtained by requesting it at the front desk.


We reserve the right to change this notice at any time. We further reserve the right to make any change effective for all protected health information that we maintain at the time of the change - including information that we created or received prior to the effective date of the change.
We will post a copy of our current notice in the waiting room. Patients may review the privacy notice during daily operational hours.


If you believe that we have violated your privacy rights, you may submit a complaint to our privacy officer or the Secretary of Health and Human Services. To file a complaint with the practice, submit the complaint in writing to our privacy officer. You will not be penalized for the filing of the complaint.


This notice is not intended to create contractual or other rights independent of those created in the federal privacy rule.


Your trust is our greatest asset. We make every reasonable effort to ensure that information held by Lewisburg Plastic Surgery’s website is confidential and secure. We disclose our information-security practices to you as clearly and fully as possible. This is how we handle information we learn about you from your visit to our web site. Please check back to this policy frequently because we may modify it at any time without notice. The use of Lewisburg Plastic Surgery’s web site is governed by the Terms and Conditions of Use. If you do not agree to the terms of our privacy policy or the Terms and Conditions of Use, please do not use this web site.


Personal information submitted by you to the Lewisburg Plastic Surgery web site, or collected by Lewisburg Plastic Surgery (LPS) as a result of your visit to our web site, will be considered private and held in confidence. We will take reasonable steps to protect your personal data from misuse, unauthorized access and alteration. In addition, we will not sell, rent, trade or give away personal information to any third party for use in selling products or services without your consent.

The Lewisburg Plastic Surgery web site contains links to other sites. Lewisburg Plastic Surgery does not endorse, approve, certify, or control these other web sites, and we do not guarantee the accuracy, completeness, efficacy, or timeliness of the information contained on these sites. Lewisburg Plastic Surgery is not responsible for the privacy practices or content of such web sites. Any information you provide to one of these other web sites will be governed by the privacy policy of that web site. We therefore strongly recommend that you refer to each web site's privacy policy before giving out any personal information on their site.


Lewisburg Plastic Surgery may collect such personal information as your name, address, date of birth, phone number, e-mail address and resume information.
Lewisburg Plastic Surgery may use the collected personal information for the purpose of providing personalized services, for class registrations, for communicating separately with you (e.g., answering questions which you have submitted to us), for reviewing in connection with current job openings, and for our internal mailing list. This personal information is not shared with any third party outside of Lewisburg Plastic Surgery other than our web site hosting and maintenance subcontractors.


Lewisburg Plastic Surgery primarily collects information through the question submission forms offered on our site. We use cookie technology to track user trends and patterns to better understand our user base and improve the quality of our services. A cookie is a small data file that web sites may write to your hard drive when you visit them. A cookie file can contain information such as a user ID that the site uses to track the pages you have visited. But the only personal information a cookie can contain is information you supply yourself. A cookie cannot read data off your hard disk or read cookie files created by other sites. A cookie can tell us, "This is the same computer that visited Lewisburg Plastic Surgery two days ago," but it cannot tell us, "This person is Joe Smith" or even, "This person lives in the United States." You can reset your browser to refuse all cookies or to indicate when a cookie is being sent. Be aware, however, that some parts of the Lewisburg Plastic Surgery site may not function properly if you refuse cookies.


Our site and/or services are not directed at children, and we make every reasonable effort to ensure that we do not accept personal information from persons under 13 years of age. The only information collected about children is that which is supplied by their parent or guardian for the purpose of obtaining treatment or information regarding treatment.


We offer the use of a secure server. The Secure Socket Layer (SSL) encrypts information that you input before it is sent to us in appropriate areas. We also take steps to protect the data we collect from unauthorized access or use.


We do not rent or sell email addresses to third parties for unsolicited communications.


By using this web site, you agree that you will not utilize any email addresses available to you through this web site to transmit unsolicited messages.


If you have any other questions or concerns regarding this privacy statement, or any other aspect of our web site, please contact us at [email protected]