Notice of Privacy Practice

This Notice of Privacy Practices ("NOPP") describes how medical information about you may be used and disclosed, and how you can access this information. Please read it carefully.

siParadigm LLC ("siParadigm") and its subsidiaries and sites, are committed to complying with and addressing data protection requirements under all laws that apply to our business, including but not limited to the Health Insurance Portability and Accountability Act (HIPAA). This NOPP explains how siParadigm handles your personal data and protected health information (PHI) in connection with the provision of clinical laboratory testing services.

Please note that depending on each specific arrangement, siParadigm may be considered to be either Data Controllers or Data Processors for purposes of General Data Protection Regulations (GDPR).

  • siParadigm is required by law to protect the privacy of your personal data and PHI and may need to notify data protection authorities, affected individuals or those Data Controllers instructing it following a breach of unsecured protected health information.
  • As a Data Controller, siParadigm is also required to provide you with a copy of this NOPP, and to follow its terms then in effect, except that siParadigm reserves the right to change its privacy practices and the corresponding policies and procedures and, where permitted by applicable law, to make these changes effective regarding PHI created or received prior to the effective date of such changes. To this effect, should siParadigm make changes to this NOPP, a revised NOPP will be posted on our website.
  • siParadigm may need to materially change its policies and procedures as necessary to comply with changes in the law and for other valid reasons, in which case it will promptly revise its policies and this NOPP and distribute the revised NOPP in the manner described below.
  • You have the right to obtain a paper copy of the NOPP upon request.

Types of Data Processed:

  • Personal data that siParadigm may process includes the following types of data:
    • Name,
    • Date of birth,
    • Address,
    • E-mail address,
    • Telephone numbers,
    • Insurance status,
    • Gender,
    • Marital status, and
    • Unique numbers that could identify you such as government or private insurance numbers, social security numbers, drivers license or national ID numbers.
  • PHI including but not limited to:
    • Names and addresses of your healthcare providers,
    • Information about your credit card or other forms of payment used to pay for our services,
    • Dates of service,
    • Laboratory test results, diagnosis,
    • Information about your family or ethnicity (only to the extent required to enable us to provide you with accurate results or diagnostics), genetic or biometric data, and
    • For reference, PHI includes laboratory test orders, laboratory test results and invoices and billing data relating to the healthcare services siParadigm provides.

Purpose of Data Processing, Legal Basis, and Disclosures:

  • siParadigm may collect, use, process, disclose and maintain your personal data and PHI for the following purposes:
  • For Treatment, Benefits and Services: As a service provider, siParadigm may disclose your PHI to doctors, nurses, and other health care personnel who are involved in providing your health care, and in the course of providing services, siParadigm may use your PHI to determine care management options. For example, your PHI will be shared among your doctor(s) and healthcare professionals.
  • siParadigm may also make your PHI available to providers by make it accessible through a provider portal, a password protected area that makes it possible to share your laboratory results electronically. Be aware that if your physician allows us to transfer your laboratory and pathology reports to his or her electronic health record (EHR) in his or her office, once they have been transferred anyone taking care of you at that office may be able to access your laboratory and pathology results directly.
  • For Payment: siParadigm may use/disclose your personal data and PHI in order to bill and collect payment for your health care services and/or release portions of your PHI to a private insurer to get paid for services that siParadigm delivered to you. For example, siParadigm may share your PHI with your health insurance plan so it will pay for your services.
  • For Health Care Operations: siParadigm may use/disclose your PHI in the course of operating our clinical laboratory. For example, siParadigm may use your PHI for certain administrative, financial, legal, and quality improvement purposes, such as to conduct quality assessments, internal audits, general administrative and business planning activities and other activities necessary to support our healthcare operations.
  • Business Associates. siParadigm may disclose the minimum amount of your personal data and PHI necessary to contractors, agents and other business associates who need the information to help us with billing or other business activities related to the services siParadigm provides. For example, siParadigm may share personal data and PHI with a billing company that helps us obtain payment from your insurer, an attorney or with a quality assurance consultant in order to obtain their advice regarding our operations. If siParadigm discloses your personal data or PHI to a business associate, siParadigm will have a written contract with them that requires the business associate and any of its subcontractors to take reasonable steps to protect the privacy of your personal data and PHI as required by law and/or contract. Business associates and their subcontractors are considered to be data processors and, as such, are directly bound by law and/or contract to protect your information. With that said, you must keep in mind that some of these business associates may be located outside the United States or the European Union and, consequently, in countries that may not necessarily provide the same level of data protection as in your country of residence. If you are a European resident and would like to request copies of a specific business associate agreement relating to your personal data under GDPR, please contact our Privacy Office at the number and address mentioned above in this NOPP.
  • When Required by Law: siParadigm may collect, use, maintain, process or disclose your personal data and PHI as required by law to do so. For instance, under the United States' Clinical Laboratory Improvement Amendments of 1988 (CLIA), siParadigm is required to obtain and maintain for designated periods of time personal data and specimens belonging to patients for whom siParadigm is providing laboratory testing services. Therefore, while you may refuse to provide siParadigm with your personal data, siParadigm is unable to test any specimen of yours without the personal data elements which siParadigm is required to obtain under CLIA. Please note that the CLIA-mandated retention periods can range from two (2) years for test requisitions and authorizations to ten (10) years for pathology test reports and histopathology slides. For more information on the specific CLIA-mandated retention periods please check 42 CFR§493.1105, as amended from time to time. In addition, siParadigm maintains patient and customer information in connection with pending litigation, legal processes, legal claims, compliance, regulatory matters and investigations as necessary. If you are providing us with the data of third parties (such as contact information of next of kin or information about your healthcare provider), you must ensure that you notify the relevant third party before sharing their personal information with us by showing them this NOPP, explaining that their personal data will be processed in accordance with this NOPP, and obtaining their consent, where appropriate.
  • For Public Health Activities: siParadigm may disclose PHI when siParadigm is required to collect information about disease or injury, or to report vital statistics to the public health authority. siParadigm is also required to release some PHI about you to your employer if your employer hires us to perform a pre-employment test or siParadigm discovers that you have a disease that your employer must know about in order to comply with employment laws.
  • Judicial and Administrative Proceedings: siParadigm may disclose your personal data and PHI in response to valid court orders, court-ordered warrants, and judicial summonses and subpoenas, grand jury subpoenas and administrative requests. siParadigm may also disclose your PHI in response to discovery requests, or other legal processes and legal requests, but only if efforts have been made, either by the requesting party or us, to first tell you about the request or to obtain an order protecting the information requested.
  • For Health Oversight Activities: siParadigm may disclose PHI to an agency responsible for monitoring the health care system for such purposes as reporting or investigation of unusual incidents and inspecting our facility. These government agencies monitor government benefit programs such as Medicare and Medicaid, as siParadigm complies with government regulatory programs and civil rights laws.
  • To Avert Threat to Health or Safety: In order to avoid a serious threat to health or safety, siParadigm may disclose personal data or PHI as necessary to law enforcement or other persons who can reasonably prevent or lessen the threat of harm.
  • Workers' Compensation: siParadigm may disclose your personal data and PHI for workers' compensation or similar programs that provide benefits for work-related injuries, as authorized by and to the extent necessary to comply with laws regarding workers' compensation or similar programs providing benefits for work-related injuries or illness.
  • Coroners, Medical Examiners and Funeral Directors: Where allowed by applicable law, siParadigm may disclose PHI relating to an individual's death to coroners, medical examiners or funeral directors, and to organ procurement organizations relating to organ, eye, or tissue donations or transplants (Note: Information belonging to patients who are deceased more than 50 years is not considered PHI.)
  • To Family, Friends or Others Involved in Your Care: If you do not expressly object, siParadigm may share your PHI with your family members, friends and others if this information is directly related to their involvement in your care, or payment for your care. In some cases, siParadigm may need to share your information with a disaster relief organization that will help us notify these persons.
  • Completely De-identified or Partially De-Identified Information: siParadigm may use and disclose your health information if siParadigm have removed any information that could identify you. Where permitted by applicable law, siParadigm may also use and disclose health information about you for research, public health and specific healthcare operations if most of your identifiers are removed and the person who will receive the information signs an agreement to protect the privacy of the information as required by federal and applicable law. In that case any direct identifiers would be removed, but your age, sex, date of birth, dates of service would not be removed.
  • For Internal Assessments and Healthcare Operations Communications: siParadigm may use your personal data to help us understand which products, services and offers are relevant to you, to improve our products and services and generally to communicate news or matters involving quality of care that may be relevant to you. Keep in mind that this use is solely for internal purposes and that siParadigm will not sell any of your personal data to any third party. If you do not wish to receive these communications, you can inform us of your decision by providing notice to the Privacy Office at the address set forth in this NOPP and siParadigm will not engage in such activity.
  • Other Permitted Disclosures: Regardless of any other provisions in this NOPP, siParadigm may disclose or otherwise process your personal data in the context of any sale or transaction involving all or a portion of our business, or as may be required or permitted by law or required for the purposes of any regulatory audit to which siParadigm may be subject from time to time.
  • siParadigm will use your personal data, including PHI, only for the purposes for which siParadigm collects it, unless siParadigm reasonably considers that it needs to use it for another reason that is compatible with the original purpose. If siParadigm needs to use your personal data for another purpose, siParadigm will explain the legal basis siParadigm relies on. Our legal basis to use, process, maintain and disclose your personal data and PHI includes:
    • Your consent (which may subsequently be withdrawn at any time by contacting the Privacy Office at the address listed in this NOPP),
    • Legitimate business needs, which include but are not limited to ensuring that siParadigm provides accurate results and that siParadigm has the right information on file to communicate with you at any time, obtaining payment for our services, and ensuring that siParadigm complies with our quality assurance policies,
    • Creation or performance of contractual obligations (e.g. communicating laboratory results to you or your provider) and,
    • Compliance with legal requirements (e.g. complying with a court order or a legal mandate).
  • Requirement for Written Authorization: siParadigm will only make other uses and disclosures of your PHI that are not described in this NOPP, and not otherwise required or allowed by law, with your written authorization. For example, siParadigm will not sell your PHI or use or disclose your PHI for marketing purposes without your written authorization. If you provide us with written authorization, you may revoke that written authorization at any time, except to the extent that siParadigm has already collected, maintained, used, processed or disclosed the same in accordance with the provisions set forth above. You must revoke your authorization in writing.
  • Special Protections for HIV, Alcohol and Substance Abuse, Mental Health and Genetic Information: siParadigm will comply with all special federal and state privacy protections that apply to HIV-related information, alcohol and substance abuse treatment information, mental health information, and genetic information.

Retention Periods:

  • siParadigm will only retain your personal data and PHI for so long as reasonably necessary for the purposes set out above or as required by applicable laws.

Participants:

  • Any siParadigm employee
  • Any business associates of siParadigm (as described below) and their subcontractors.
  • These employees and business associates may share protected health information (PHI) with each other, only as necessary to carry out the treatment, payment, and healthcare operations described in this NOPP.
  • Personal Representative: If siParadigm confirms that a person has the authority under law to make decisions for you relating to your healthcare ("personal representative"), siParadigm will allow your personal representative to make choices with respect to your PHI.

Data Security:

  • siParadigm maintains reasonable security measures to safeguard personal data from loss, interference, misuse, unauthorized access, disclosure, alteration or destruction. siParadigm also maintains reasonable procedures to help ensure that such data is reliable for its intended use and is accurate, complete and current.

Use of Cookies:

  • From time to time siParadigm uses cookies and similar technology in our websites and e-mail communications for legitimate business purposes such as collecting statistics, helping optimize site functionality and security, to determine the effectiveness of our communications with customers and, generally, to help us better understand how siParadigm can improve its services.
  • Cookies are small files that are placed on your computer by websites that you visit or certain emails you open. These include "preference cookies", "security cookies" or "process cookies". Cookies are widely used in electronic communications around the world. Upon accessing our website, you provided us with your consent to the placement of cookies in your computer. Bear in mind that you have the ability to configure your internet browser at any time to block cookies from a specific domain or from all domains. Please take the time to familiarize yourself with your internet browser so that you may configure your privacy settings as you deem appropriate.

Your Rights to Access and Control Your Personal Data and PHI:

  • To Request Restrictions on Uses/Disclosures: You have the right to ask that siParadigm limits how we use or disclose your personal data and PHI. siParadigm will consider your request, but are not legally bound to agree to the restriction. To this effect, you will need to contact our Privacy Office and provide us with your written and duly authenticated instructions, which siParadigm will keep on file. To the extent that siParadigm does agree to any restrictions on our use/disclosure of your PHI, siParadigm will put the agreement in writing and abide by it to the extent permitted by law. siParadigm is required, however, to honor your written request if you direct us not to share specific PHI with your insurance company relating to a service you pay for personally. It is your responsibility to inform other providers who may receive copies of such information that they may not share this information with your insurer.
  • To Choose How siParadigm Contacts You: You have the right to ask that siParadigm sends you information at an alternative address or by an alternative means. siParadigm must agree to your request as long as it is reasonably easy for us to do so and siParadigm may not ask the reason for the request.
  • To Inspect and Copy Your PHI: You have the right to inspect and obtain a copy of any of your PHI in either electronic or paper form for as long as siParadigm maintains this information in our records. siParadigm will provide the records in the specific form and format that you request if it is readily producible in such form or format. To obtain a copy of your PHI, please submit your request in writing. Depending upon where you live, siParadigm may charge a fee as permitted by law for the costs of copying, mailing or other supplies necessary to fulfill your request. siParadigm generally requires payment before or at the time siParadigm provides the copies and will let you know the amount due in advance. Under certain very limited circumstances, siParadigm may deny your request to inspect or obtain a copy of your information. If siParadigm does, siParadigm will provide a written statement that explains the reasons for the denial and a description of your right to have that decision reviewed. In such cases where you have the right to have your denial reviewed, siParadigm will describe the review process to you in writing. In the event that your request for access to your PHI is denied for any reason, siParadigm will describe to you in writing how you can file a complaint with siParadigm or with the Secretary of the United States Department of Health and Human Services' Office of Civil Rights (OCR).
  • To Request Amendment of Your Personal Data or PHI: If you believe that the personal data or PHI in our system is incorrect or incomplete, you may ask us to amend the information for as long as the information is kept in our records. If you wish to amend your personal data or PHI please request an amendment in writing including why you think siParadigm should make the amendment. siParadigm will respond to requests within 30 days and all other requests within 60 days, barring exceptional circumstances. If siParadigm needs additional time to respond, siParadigm will notify you in writing within 60 days to explain the reason for the delay and tell you when you can expect to have a final answer to your request. If siParadigm denies part or all of your request, siParadigm will provide you with a written notice explaining our reasons for doing so and how you can appeal the decision.
  • To Receive an Accounting of Disclosures: You have a right to submit a request in writing asking for information about our disclosures of your personal data or PHI, except for disclosures made:
    • For treatment, payment, and operations;
    • To you or your personal representative;
    • At your written request;
    • For national security purposes;
    • To family, friends and other persons involved in your care;
    • To correctional institutions or law enforcement officers;
    • Incidental to permissible uses and disclosures of your PHI (for example, when information is overheard by another person passing by);
    • For research or public health using limited portions of your health information that do not directly identify you; and
    • That occurred prior to the compliance date of this requirement.
    siParadigm will respond to your written request for such a list within 60 days of receiving it. Your request can relate to disclosures going as far back as six years. There may be a charge for more than one such list each year.
  • To Port Your Personal Data or PHI: You have the right to obtain and reuse your personal data and PHI for your own purposes across different services. Accordingly, to the extent technically feasible, you have the right to request us to move, copy or transfer your personal data and PHI to the data controller of your choice in a safe and secure way. All portability requests shall be addressed in writing to the Privacy Office at the address listed in this NOPP.
  • To Request the Erasure of Your Personal Data or PHI: If you are a resident of the European Union, you have the right to request that your personal data and PHI be erased from our systems. Bear in mind that siParadigm is a U.S.-based diagnostic laboratory and, as such, siParadigm is required under CLIA, state laboratory laws and other laboratory accreditation requirements to maintain our patients' PHI for designated periods of time from its receipt/generation, all of which affects our ability to accommodate your request. Once that mandatory timeframe expires siParadigm will have the ability to delete your personal data or PHI from our systems if you so desire. To this effect, please send your written request to the Privacy Office at the address listed in this NOPP.

How to Complain About Our Privacy Practices

  • If you believe your privacy rights have been violated, you may file a complaint with duly or the federal agency that enforces HIPAA by submitting your complaint as described below:

siParadigm LLC
ATTN: Privacy and Security Officer, HIPAA Privacy Office
25 Riverside Dr, Ste 2
Pine Brook, NJ 07058
Phone: (888) 599-5227
Email: compliance@siparadigm.com

- OR -

Office of Civil Rights, U.S. Department of Health and Human Services
200 Independence Avenue, S.W.
Washington, D.C. 20201
Telephone: (800) 368-1019
www.hhs.gov/ocr/hipaa

  • Please address any written request (such as requests for a copy of this NOPP, access to your record, to restrict a disclosure to a payer, etc.) to:

siParadigm LLC
ATTN: Privacy and Security Officer, HIPAA Privacy Office
25 Riverside Dr, Ste 2
Pine Brook, NJ 07058
Phone: (888) 599-5227
Email: compliance@siparadigm.com

Last Updated: May 6, 2026

Discover more.

A Model Experience

With core values rooted in service and integrity, our leadership team sets the bar high.

We consistently strive to set the model for exactly how a reference laboratory should engage with both physicians and patients.

Accredited and Certified

siParadigm is accredited by CLIA (Clinical Laboratory Improvement Amendments) and certified by CAP (College of American Pathologists).

We also hold select state licensure where required.