AOS Enterprise

Joint Notice of Privacy Practices

Effective Date: August 2, 2026

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

This Joint Notice of Privacy Practices (the “Notice”) describes the privacy practices of the AOS organized health care arrangement described below (the “AOS OHCA,” “we,” “us,” or “our”). It applies to protected health information (“PHI”) created or received by a participating entity as part of its participation in the AOS OHCA.

PHI is information about you, including demographic information, that identifies you or could reasonably be used to identify you and that relates to your past, present, or future physical or mental health or condition, the provision of health care to you, or payment for that care.

1. Who This Notice Applies To

This Notice applies to the following covered health care providers and service-delivery sites that participate in the AOS OHCA (collectively, the “Participants”):

  • AOS Miami, PLLC
    2801 NE 213th St, Ste 1206
    Aventura, FL 33180
  • Alfi Oral Surgery, PA
    6624 Fannin St, Ste 1710
    Houston, TX 77030
  • Airway Outpatient Surgical Center, LLC
    1200 Binz St, Ste 1000
    Houston, TX 77004

This Notice also applies, as appropriate, to the workforce members of each Participant; members of its medical, dental, allied-health, and professional staffs; trainees and students; and other persons who provide services at a covered service-delivery site under the Participant’s control.

It covers services furnished through in-person, ambulatory, facility-based, mobile, and telehealth settings, including oral and maxillofacial surgery, orthodontics, ambulatory surgery, sleep and airway medicine, otolaryngology, facial plastic and cosmetic surgery, psychiatry, psychology, nutrition, myofunctional therapy, dental hygiene, and other present or future medical, dental, behavioral-health, and allied-health specialties operated by a Participant.

The Participants are separate legal entities and are independently responsible for their own acts and omissions. Participation in the AOS OHCA does not create a partnership, joint venture, agency, or employment relationship among Participants and does not make one Participant responsible for the clinical judgment, professional services, or liabilities of another.

2. Our Responsibilities

We have a responsibility to:

  • Maintain the privacy and security of your PHI as required by applicable law.
  • Provide you with notice of our legal duties and privacy practices concerning your PHI.
  • Follow the terms of this Notice currently in effect.
  • Apply appropriate administrative, physical, and technical safeguards to PHI, including PHI maintained or transmitted electronically.
  • Notify affected individuals following a breach of unsecured PHI when required by law.

We will not use or disclose your PHI except as described in this Notice, as permitted or required by law, or as authorized by you in writing. Where another applicable law provides greater protection, we will follow the more protective law.

3. Your Rights

Access to Your Health Information

You may inspect and obtain a copy of PHI in a designated record set that we maintain about you, subject to limited exceptions. You may request paper or electronic copies and, when the requested form and format are readily producible, receive the information in that form and format.

You may also direct us in a signed written request to transmit an electronic copy to another person or entity when the request clearly identifies the recipient and where to send the copy. We generally will act on your request within 15 days and may charge only a reasonable, cost-based fee permitted by law.

You may have convenient access to some information through a patient portal. Portal availability does not limit your right to request access to PHI maintained elsewhere in the designated record set.

Amendment

If you believe PHI in a designated record set is incorrect or incomplete, you may request an amendment in writing and explain the reason for the request. We generally will respond within 60 days.

Accounting of Disclosures

You may request a written accounting of certain disclosures of your PHI made during the six years before your request. Certain disclosures, including many disclosures for treatment, payment, or health care operations, are excluded by law.

Restrictions

You may ask us in writing to restrict certain uses or disclosures for treatment, payment, or health care operations, or disclosures to persons involved in your care or payment for your care.

If you, or another person other than a health plan on your behalf, pay in full for a health care item or service, you may ask us not to disclose PHI about that item or service to your health plan for payment or health care operations. We must agree unless the disclosure is required by law.

Confidential Communications

You may ask us to communicate with you about PHI by reasonable alternative means or at an alternative location, such as a different mailing address, telephone number, or email address.

Paper Copy of This Notice

You may obtain a paper copy of this Notice at any time, including if you agreed to receive it electronically.

Personal Representatives

A person with legal authority to act for you may exercise your privacy rights and make choices about your PHI, subject to applicable law. We may verify that person’s identity and authority before acting.

Breach Notification

You have the right to receive notice following a breach of your unsecured PHI when notification is required by law.

4. Your Choices

When permitted by law and consistent with your preferences, we may share relevant PHI with a family member, close personal friend, or another person you identify who is involved in your care or payment for your care.

If you are present and able to decide, we will ordinarily ask you or give you an opportunity to object. If you cannot tell us your preference, we may use professional judgment to make a disclosure that is in your best interests.

Tell us if you have a preference about appointment reminders, messages, or the persons with whom we may discuss your care. We will honor your instructions when required by law and otherwise will make reasonable efforts to accommodate them.

5. How We Use and Disclose Information

HIPAA permits us to use and disclose PHI for treatment, payment, and health care operations without obtaining a HIPAA authorization. These permissions do not eliminate any more protective consent or authorization requirement imposed by applicable law.

Treatment

We may use and disclose PHI to provide, coordinate, or manage your health care and related services; consult with, refer to, or obtain services from other health care professionals; prescribe and manage medications; perform diagnostic testing and treatment planning; and coordinate care across Participants and outside providers.

Payment

We may use and disclose PHI to bill and collect payment from you, a health plan, or another payer; determine eligibility or coverage; obtain prior authorization; coordinate benefits; conduct utilization review; support medical-necessity determinations; manage claims, appeals, collections, and refunds; and perform other payment activities.

Health Care Operations

Unless otherwise restricted by applicable law, we may use and disclose PHI for health care operations and joint health care operations, including quality assessment and improvement, patient safety, care coordination, credentialing, peer review, licensing, accreditation, training, compliance, auditing, legal and risk-management functions, customer service, business planning, data analytics, information-system administration, and related activities.

Business Associates and Technology Service Providers

We may disclose PHI to business associates that perform services for or on behalf of a Participant or the AOS OHCA, such as cloud hosting, electronic health record support, billing, revenue cycle, secure communications, transcription, clinical documentation, diagnostic analysis, treatment-planning support, data analytics, cybersecurity, legal, accounting, and records-management services.

6. Other Uses and Disclosures Permitted or Required by Law

Subject to applicable conditions and any more protective law, we may use or disclose PHI without your written authorization for purposes including:

  1. Compliance with federal, state, or local law and reporting obligations.
  2. Authorized public-health activities.
  3. Governmental or protective-services activities permitted or required by law.
  4. Audits, investigations, inspections, licensure, accreditation, and disciplinary proceedings.
  5. Court orders, subpoenas, judicial proceedings, and other lawful process.
  6. Limited law-enforcement purposes authorized by law.
  7. Preventing or lessening a serious and imminent threat.
  8. Coroners, medical examiners, and funeral directors.
  9. Organ and tissue donation.
  10. Workers’ compensation and similar programs.
  11. Military, veterans, national-security, protective-service, and correctional activities authorized by law.
  12. Research permitted by applicable law.
  13. Disaster-relief activities.
  14. Certain disclosures concerning deceased individuals.
  15. School immunization records where permitted by law.
  16. Certain administrative, legal, due-diligence, and compliance activities.
  17. Use and disclosure of appropriately de-identified information and limited data sets.

7. Uses and Disclosures Requiring Authorization

We will obtain your written authorization before using or disclosing PHI when HIPAA or another applicable law requires authorization. This generally includes most uses and disclosures of psychotherapy notes, uses and disclosures for marketing that require authorization, disclosures that constitute a sale of PHI under HIPAA, and uses or disclosures not otherwise described in this Notice or permitted by law.

An authorization is a separate document from this Notice and from an acknowledgment of receipt. You may revoke an authorization in writing at any time, except to the extent we have already acted in reliance on it or another law limits revocation.

We may contact you about treatment alternatives, care-management services, health-related products or services, appointment availability, or benefits and services that may be of interest when the communication is permitted without a marketing authorization.

PHI disclosed under HIPAA may be redisclosed by a recipient and may no longer be protected by HIPAA unless another law restricts redisclosure or the recipient is independently subject to HIPAA or a contractual duty.

8. Specially Protected Information

Substance Use Disorder Records

To the extent we create, receive, or maintain records protected by 42 U.S.C. § 290dd-2 and 42 C.F.R. Part 2, additional protections apply. Such records and testimony describing their contents will be used or disclosed only as permitted by Part 2 and other applicable law.

Psychotherapy Notes and Mental or Behavioral Health Information

Most uses and disclosures of psychotherapy notes require your written authorization, subject to limited exceptions permitted by law. Mental and behavioral health information may also be subject to more protective state or federal confidentiality requirements.

Genetic, HIV, Communicable-Disease, and Other Sensitive Information

Genetic information, HIV/AIDS information, communicable-disease information, sexual-health information, records concerning minors, and other categories of sensitive information may receive additional protection under applicable law.

9. Electronic Systems, Communications, and Technology

Electronic Health Records, Cloud Systems, Portals, and Digital Intake

Participants may create, receive, maintain, and transmit PHI through electronic health records, practice-management platforms, cloud-hosted systems, patient portals, electronic prescribing systems, digital imaging and diagnostic platforms, electronic signature services, online scheduling, and digital intake forms.

Email, SMS/Text, Telephone, and Portal Messages

We may use the contact information you provide to communicate about appointments, referrals, prescriptions, care instructions, billing, insurance, records requests, and other treatment, payment, or operational matters.

Standard email and text messaging may present privacy and security risks. You may request reasonable confidential communications or tell us that you do not want certain channels used.

Telehealth and Remote Services

We may provide or support services through telehealth or other remote technologies. PHI may be exchanged through video, audio, chat, remote-monitoring, scheduling, and portal technologies used for treatment and related activities.

AI-Assisted Documentation and Administrative Technologies

Where permitted by law, we may use technology that employs artificial intelligence, machine learning, speech recognition, or similar functionality to assist with clinical documentation, transcription, coding support, scheduling, patient communications, quality review, data organization, or other treatment, payment, and health care operations.

Some documentation tools may capture audio of a clinical encounter to generate a draft note or transcript. Before using such a tool, we will provide any notice and obtain any consent required by applicable federal or state law.

Electronic Signatures

We may use electronic signatures and electronic acknowledgments for clinical, administrative, financial, privacy, and consent documents as permitted by law.

10. Health Information Exchange

A Participant may participate in one or more health information exchanges, interoperability networks, electronic prescribing networks, or record-locator services that permit authorized health care providers and other participants to exchange health information electronically for treatment, payment, health care operations, and other purposes permitted by law.

Where applicable, you may have a right to opt in to, opt out of, or restrict certain exchange activity. Contact the Privacy Officer for information about the HIEs used by the Participant treating you and the choices available to you.

11. Organized Health Care Arrangement

An organized health care arrangement is a HIPAA-recognized arrangement through which legally separate covered entities that participate in joint health care activities may share PHI for those joint activities and may issue a single joint notice of privacy practices.

The AOS Participants have formed the AOS OHCA to support coordinated, integrated courses of care and shared health care functions under the AOS/AOSC brand.

As necessary and permitted by HIPAA and other applicable law, Participants may use and disclose PHI to one another for treatment, payment, and health care operations relating to the AOS OHCA, including joint health care operations.

The AOS OHCA does not merge the Participants, make all records part of a single legal medical record, or guarantee that all Participants can immediately access all information. Access and exchange depend on clinical need, role-based permissions, technical availability, and applicable law.

12. State Law and Other Privacy Protections

We operate in multiple states. Where state or other federal law provides greater privacy protection, grants additional rights, or imposes stricter consent, authorization, disclosure, retention, or notice requirements than HIPAA, we will comply with the applicable law.

This may include laws governing mental and behavioral health, substance-use-disorder treatment, HIV/AIDS and communicable diseases, genetic information, reproductive and sexual health, minors’ records, dental records, biometric information, recording of communications, and telehealth.

This Notice does not create a uniform right to use or disclose information when a more protective law applies.

13. Complaints, Questions, and Privacy Officer

If you believe your privacy rights have been violated, disagree with a decision concerning your PHI, have a question about this Notice, or wish to exercise a right, contact:

AOS Enterprise Privacy Officer
Zachary Higham
Chief Legal and Compliance Officer and Enterprise Privacy Officer

2801 NE 213th St, Ste 1206
Aventura, FL 33180

Telephone: 305-701-3901

Email: [email protected]

You may also file a complaint with the Secretary of the U.S. Department of Health and Human Services, Office for Civil Rights, by writing to 200 Independence Avenue, S.W., Washington, D.C. 20201; calling 1-877-696-6775; or visiting the HHS Office for Civil Rights website.

We will not retaliate against you for filing a complaint or exercising a privacy right.

14. Changes to This Notice

We reserve the right to change the terms of this Notice and our privacy practices and to make a revised Notice effective for all PHI we maintain, including PHI created or received before the effective date of the revised Notice.

We will promptly revise this Notice when required by law or when there is a material change to the uses or disclosures, your rights, our legal duties, or other privacy practices described here.

The current Notice will be available upon request, at each covered service-delivery site, and electronically at aoscenter.com/notice-of-privacy-practices.

15. Acknowledgment of Receipt

Your acknowledgment of this Notice acknowledges receipt only.

It is not a consent to treatment, a HIPAA authorization, a general medical-record release, a consent to recording, or a consent to marketing or electronic communications.

A Participant may separately request written or electronic acknowledgment that you received or were offered this Notice.