Notice of Privacy Practices
Effective Date: March 5, 2026 | Last Updated: March 5, 2026
1. About This Page and Your Provider's Notice
Krasyn LLC ("Krasyn") operates the Krasyn electronic medical records platform used by your healthcare provider. Under HIPAA, your healthcare provider is the "covered entity" responsible for maintaining the privacy of your Protected Health Information ("PHI") and for providing you with their Notice of Privacy Practices, which is the authoritative description of how your health information may be used and disclosed. Krasyn is a "business associate": we process your health information only on your provider's behalf, under a Business Associate Agreement that requires us to maintain the privacy and security of your PHI, to notify your provider following a breach of unsecured PHI, and to use and disclose PHI only as that agreement and HIPAA permit. This page explains how Krasyn safeguards your information in that role; it supplements, and does not replace, your provider's own notice.
2. How Your Provider May Use and Disclose Your Health Information
Your healthcare provider, using the Krasyn platform, may use and disclose your PHI for the following purposes without your written authorization. Krasyn processes this information only as directed by your provider under the Business Associate Agreement:
Treatment
Your health information may be used and disclosed to provide, coordinate, or manage your healthcare. For example, your provider may share information with a specialist to whom you have been referred.
Payment
Your health information may be used and disclosed to obtain payment for services provided to you. For example, information may be shared with your insurance company to process claims.
Healthcare Operations
Your health information may be used for activities necessary to operate the practice, including quality assessment, staff training, compliance programs, and business planning.
As Required by Law
Your provider (and Krasyn, where the law applies to us directly as a business associate) will disclose your health information when required by federal, state, or local law, including for public health activities, health oversight, judicial proceedings, law enforcement purposes, and to avert a serious threat to health or safety.
3. Uses and Disclosures Requiring Your Written Authorization
Your written authorization to your provider is required for the following uses and disclosures:
- Marketing communications involving PHI
- Sale of your health information
- Most uses of psychotherapy notes (if applicable)
- Any other use or disclosure not described in this notice
You may revoke your authorization in writing at any time, except to the extent that action has already been taken in reliance on the authorization.
4. Your Rights Regarding Your Health Information
Under HIPAA you have the rights below. You exercise these rights through your healthcare provider (the covered entity that maintains your records); Krasyn supports your provider in fulfilling each of them through the platform.
Right to Access
You have the right to inspect and obtain a copy of your health information maintained in a "designated record set," which includes medical and billing records. Submit your request in writing to your provider. Your provider will provide a copy in the format you request if it is readily producible, or in a mutually agreeable alternative format, and may charge a reasonable, cost-based fee.
Right to Amend
You have the right to request an amendment to your health information if you believe it is incorrect or incomplete. Your request to your provider must be in writing and must provide a reason for the amendment. Your provider may deny the request under certain circumstances and will provide a written explanation if denied.
Right to an Accounting of Disclosures
You have the right to request from your provider a list of disclosures of your health information made for purposes other than treatment, payment, healthcare operations, and certain other exceptions. Krasyn's audit trail helps your provider produce this accounting. The first accounting within a 12-month period is free; additional requests may be subject to a reasonable fee.
Right to Request Restrictions
You have the right to ask your provider to restrict how your health information is used or disclosed for treatment, payment, or healthcare operations. Your provider is not required to agree to your request, except that they must agree to restrict disclosures to a health plan if you paid for the service in full out of pocket.
Right to Confidential Communications
You have the right to request that your provider communicate with you about your health information by alternative means or at alternative locations. Reasonable requests will be accommodated.
Right to a Paper Copy
You have the right to receive a paper copy of your provider's Notice of Privacy Practices upon request, even if you agreed to receive it electronically.
Right to Be Notified of a Breach
You have the right to be notified if there is a breach of your unsecured PHI. Krasyn notifies your provider of any breach involving the platform, and your provider notifies you as required by law.
5. Krasyn's Responsibilities as a Business Associate
- We are required by HIPAA and our Business Associate Agreement to maintain the privacy and security of your PHI
- We will promptly notify your provider if a breach occurs that may have compromised the privacy or security of your information, so your provider can notify you as required by law
- We will not use or disclose your information for marketing or fundraising purposes
- We will not sell your information
- We use and disclose PHI only as permitted by the Business Associate Agreement and HIPAA
- We will not retaliate against you for filing a complaint
6. How the Krasyn Platform Protects Your Information
As the technology platform processing your health information on behalf of your healthcare provider, Krasyn implements the following protections:
- Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Access controls: Only authorized users with a legitimate need can access your records
- Audit trail: Every access to and modification of your records is logged and cannot be altered
- Organization isolation: Your data is kept separate from other organizations' data
- Automatic session timeout: Sessions expire after 15 minutes of inactivity to prevent unauthorized access
- No data selling: Your health information is never sold or used for advertising
7. Changes to This Page
We reserve the right to change this page and make the revised version effective for health information we already process as well as any information we process in the future. The current version will be posted on this page with the effective date. Your provider is responsible for notifying you of changes to their own Notice of Privacy Practices.
8. Complaints
If you believe your privacy rights have been violated, you may file a complaint with:
- Your healthcare provider's Privacy Officer (contact your provider directly)
- Krasyn LLC: compliance@krasyn.com
- U.S. Department of Health and Human Services Office for Civil Rights:
200 Independence Avenue, S.W., Washington, D.C. 20201
Phone: 1-877-696-6775
Website: hhs.gov/hipaa/filing-a-complaint
You will not be penalized or retaliated against for filing a complaint.
9. Contact Information
For questions about this notice or to exercise your privacy rights:
- Privacy Officer: privacy@krasyn.com
- Compliance: compliance@krasyn.com
Krasyn LLC
2489 N Side Saddle Lane
Post Falls, ID, United States