FishtownFish wrapped around the rod of AsclepiusMedicine
Philadelphia Primary Care
How It Works
What People Say
Patient reviews across 6 platforms
Articles
Symptoms
What your body is telling you
Treatments
Protocols, prescriptions, therapies
Longevity
Medicine 3.0 strategies
Heart Health & Risk
Protect your heart & vessels
Metabolism
Insulin, blood sugar, weight
Hormones
TRT, thyroid, menopause, andropause
Performance
VO2 max, muscle, sleep, gut
Playbooks
Step-by-step frameworks
About
Meet Dr. Ash
Your Physician
GERO·SPAN
Our Clinical Framework
FAQ
Common Questions
Book a Free Call
Your Privacy
Fishtown Medicine•4 min read

Your Privacy

On This Page
  • 1. Your Rights
  • 2. Our Legal Duties
  • 3. How We May Use & Disclose PHI Without Written Authorization
  • 4. Uses & Disclosures That Never Occur Here
  • 5. Extra Protections for Sensitive Information
  • 6. Safeguarding Your Information
  • 6.1 Website Chat Tool (Not a PHI Channel)
  • 7. Data Retention & Destruction
  • 8. Changes to This Notice
  • 9. Acknowledgement of Receipt
  • 10. Questions, Requests, or Complaints
  • Common Questions
  • What is protected health information (PHI)?
  • How do I request a copy of my Fishtown Medicine medical records?
  • Does Fishtown Medicine ever sell my health data?
  • How do I file a privacy complaint?
  • Is my genetic data stored long-term at Fishtown Medicine?
  • Can I limit which information you share with my insurance plan?
  • How long does Fishtown Medicine keep my medical records?

Get a preventive doctor that knows you.

Consult Dr. Ash
TL;DR · 30-second take

The Fishtown Medicine HIPAA Notice of Privacy Practices explains how we safeguard, use, and disclose your protected health information (PHI). It covers your rights, our legal duties, the limits on data sharing, and how to file a complaint. We never sell PHI or use it for marketing.

FISHTOWN MEDICINE - HIPAA NOTICE OF PRIVACY PRACTICES

We work at the pace of your trust. This Notice of Privacy Practices ("Notice") explains how Fruition Medicine PLLC d/b/a Fishtown Medicine ("Fishtown," "we," "us," "our") safeguards, uses, and discloses your protected health information ("PHI") and describes your rights under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and related state laws. Creating an account, receiving care, or communicating with us confirms you have received and understand this Notice. We work at the pace of your trust.

1. Your Rights

You may…What it meansHow to exercise
Access your recordView, download, or request paper copies, usually within 30 days, in the form/format you request (electronic if readily producible). You may also direct us to send it to anyone you designate.Submit a written request to the Privacy Officer.
Correct your recordAsk us to amend incomplete or inaccurate information.Written request; approval or denial (with reason) within 60 days.
Request confidential communicationsAsk us to contact you at a specific phone, email, or address.Written request; we honor reasonable requests.
Limit PHI we use/shareRequest limits on treatment, payment, or operations disclosures.Written request; we may decline but honor any approved limits except emergencies.
Restrict disclosure to your health plan when you self-payIf you pay in full out-of-pocket for an item or service, we will not share that PHI with your health plan unless required by law.Written request at or before the time of service.
Receive an accounting of disclosuresGet a six-year history of non-routine disclosures.Written request; first list each 12 months is free.
Receive a paper copy of this NoticeAsk at any time, even if you agreed to electronic delivery.Phone, email, portal, or in person.
Appoint a representativeSomeone with medical power of attorney or legal guardianship can act for you.Provide legal documentation.
File a complaintDo so without fear of retaliation.See § 10.

2. Our Legal Duties

We are required by law to:
  • keep your PHI private;
  • provide this Notice explaining our privacy practices;
  • follow the terms of the Notice currently in effect; and
  • notify you if a breach compromises the privacy or security of your PHI.
Material changes trigger immediate updates in our portal, on our website, and (on request) in paper form.

3. How We May Use & Disclose PHI Without Written Authorization

  • Treatment: diagnose, treat, coordinate care, and consult with other clinicians.
  • Payment: submit claims, process billing, collect fees.
  • Healthcare Operations: quality improvement, audits, training, licensing.
  • Business Associates: share PHI with vendors (EHR, billing, cloud services) that sign HIPAA-required BAAs.
  • Public Health & Safety: disease reporting, recalls, abuse/neglect reporting.
  • Health Oversight: regulator inspections and investigations.
  • Legal Proceedings: court orders, subpoenas, warrants.
  • Workers' Compensation: as authorized by law.
  • Research: with IRB approval or a valid privacy-board waiver.
  • Organ/Eye Donation coordination.
  • Serious Threat: avert imminent harm to health or safety.
  • Special Government Functions: military, national security, corrections.
  • Routine Communications: appointment reminders, test results, care coordination, or information about health-related benefits or services that may interest you.
Note on health-plan disclosures: We never share PHI with a health plan unless coverage or payment is required, for example, billing labs, prescriptions, imaging studies, or prior authorizations.

4. Uses & Disclosures That Never Occur Here

We do not:
  • use PHI for marketing communications;
  • sell PHI; or
  • release psychotherapy notes (if we maintain any) without your written authorization.
Any other use or disclosure of PHI not described in this Notice will occur only with your written authorization, which you may revoke at any time (except where already relied upon).

5. Extra Protections for Sensitive Information

We comply with all federal and state laws that give added protection to:
  • HIV-related information
  • Substance-use-disorder records (42 CFR Part 2)
  • Mental-health treatment notes
  • PHI related to lawful reproductive care (per the 2024 HHS reproductive-health rule)
Genetic Information: We never use genetic data for insurance underwriting or discriminatory purposes. Raw genetic data received for clinical interpretation is permanently deleted once processing is complete.

6. Safeguarding Your Information

MeasureWhat we do
EncryptionPHI encrypted in transit and at rest.
Access ControlsRole-based, minimum-necessary permissions.
Audit LogsContinuous monitoring for improper access.
Secure MessagingHIPAA-compliant SMS, video, and portal.
Patient ResponsibilitiesUse strong passwords and secure personal devices.

6.1 Website Chat Tool (Not a PHI Channel)

Our public website includes a third-party chat widget (Intercom) so visitors can ask general questions about how our practice operates — services, pricing, scheduling, neighborhood coverage, and similar non-clinical topics. The website chat is not a HIPAA-covered channel and should not be used to share protected health information. If you need to discuss symptoms, treatment, medications, lab results, or any individually identifiable health information, please use the patient portal, our HIPAA-compliant SMS line, or a scheduled telehealth visit instead. Messages sent through the website chat are routed through Intercom's systems under their own terms and privacy policy and are not stored in your medical record.

7. Data Retention & Destruction

We retain PHI for at least 7 years (or longer if law requires) and then destroy it using HIPAA-compliant methods.

8. Changes to This Notice

We may update this Notice to reflect legal or operational changes. Revised versions take effect when posted to https://fishtownmedicine.com/about/privacy-policy. Material changes are also announced via portal message or email. Continued use of our services constitutes acceptance of the revised Notice.

9. Acknowledgement of Receipt

HIPAA requires that we make a good-faith effort to obtain your written or electronic acknowledgement that you received this Notice. Care is not conditioned on signing; refusal is documented.

10. Questions, Requests, or Complaints

Privacy Officer Fishtown Medicine 2418 E York St, Philadelphia, PA 19125 Phone: (267) 360-7927 Email: compliance@fishtownmedicine.com You may also contact the U.S. Department of Health & Human Services Office for Civil Rights (OCR) Phone: (800) 368-1019 TTY: (800) 537-7697 We will not retaliate against you for filing a complaint. Your trust drives us. Thank you for letting Fishtown Medicine protect your privacy while delivering preventive, personalized care.

Frequently Asked Questions

Common Questions

Protected health information (PHI) is any individually identifiable health information that we create, store, or transmit. PHI includes labs, diagnoses, medications, billing details, and any communication tied to your care.
To request a copy of your Fishtown Medicine medical records, send a written request to the Privacy Officer at compliance@fishtownmedicine.com or through the Ultralight portal. We typically deliver records within 30 days in your requested format.
No. Fishtown Medicine does not sell your health data, does not use PHI for marketing, and does not release psychotherapy notes without your written authorization.
You can file a privacy complaint by contacting our Privacy Officer at compliance@fishtownmedicine.com or by contacting the U.S. Department of Health & Human Services Office for Civil Rights at (800) 368-1019. We will not retaliate for filing a complaint.
No. Raw genetic data sent to Fishtown Medicine for clinical interpretation is permanently deleted once processing is complete. Clinical conclusions stay in your record, but the raw genetic file is not retained.
Yes. If you pay in full out-of-pocket for a specific service, you can request that we not share that PHI with your health plan, unless disclosure is required by law. Submit the request in writing at or before the time of service.
Fishtown Medicine keeps medical records for at least 7 years, or longer if state or federal law requires it. After that, records are destroyed using HIPAA-compliant methods.

---

Medical Disclaimer: This resource provides administrative and legal context for educational purposes. The right privacy and care decisions depend on your unique situation. Contact our Privacy Officer or Dr. Ash with questions specific to your records.

Still have a question?

He answers personally. Usually within a few hours.

Related Intelligence

Longevity Strategies | Fishtown Medicine

Longevity Strategies | Fishtown Medicine

Strategies to extend your healthspan and optimize lifespan in Philadelphia.

Read Deep Dive
Metabolic Health

Metabolic Health

Why you feel tired at 3 PM, and how to fix it.

Read Deep Dive
Gender Affirming Care Philadelphia: LGBTQ+ Affirming Standards

Gender Affirming Care Philadelphia: LGBTQ+ Affirming Standards

Expert gender-affirming primary care in Philadelphia. Our clinical standards for transgender, non-binary, and gender-expansive patients in Fishtown and 19125.

Read Deep Dive

Talk it through with Dr. Ash.

If anything you read here raised a question, this is a free 20-minute Warm Invitation Call. Pick a time and we’ll work through it together.

HSA/FSA eligible
No initiation or cancellation fees
No copays

Loading scheduler...

Having trouble with the scheduler? Book directly on Dr. Ash’s calendar

FishtownFish wrapped around the rod of AsclepiusMedicine
Philadelphia Primary Care
2418 E York St, Philadelphia, PA 19125Home visits in Greater Philadelphia

Serving Fishtown · Art Museum · Bella Vista · Callowhill · Center City · Center City West · Chestnut Hill · East Kensington · Fairmount · Fitler Square · Graduate Hospital · Logan Square · Manayunk · Northern Liberties · Old City · Olde Richmond · Poplar · Port Richmond · Queen Village · Rittenhouse · Roxborough · Society Hill · Southwark

Explore by topic

Women’s Health
  • Perimenopause
  • Menopause 3.0
  • PCOS
  • Fertility
Men’s Health
  • TRT Therapy
  • TRT Safety
  • TRT vs Enclomiphene
  • Low Libido
Metabolic
  • Medical Weight Loss
  • Ozempic vs Metformin
  • Fasting Protocols
  • Visceral Fat
Cardiovascular
  • apoB & Heart Health
  • apoB vs LDL
  • Lp(a) Cholesterol
  • ED & Heart Risk
Longevity + Performance
  • Healthspan vs Lifespan
  • Biological Age
  • VO2 Max
  • Zone 2 Training
Supplements
  • Magnesium
  • Creatine
  • Omega-3
  • Foundational Stack

Content is for educational purposes only and does not constitute medical advice.

TermsPrivacyScope of PracticeClinical Independence