
Your critical compliance resources all in one place.

Eddie Revuelta. PT, DPT, OCS
Director of Training and Compliance
I'm GBPT's Corporate Compliance Officer.
Compliance is good patient care and part of everyone's job.
Below is an easy-to-use form to keep me informed of all patient complaints, incidents, medical record request delays, and subpoenas and court orders.
Let me know how I can help and what questions you have. Thanks for all you do!
Eddie
Phone (209) 872-3975 (mobile) E-mail [email protected]
All The Tools You Need to Stay Compliant & Handle Incidents
We are here to help people. Keeping their information confidential is part of good patient care.
Confidentiality, cybersecurity, and compliance are HIPAA and state law requirements.
Patients have a right to confidentiality.
Patients have a right to their records.
Patients must be notified if their information is breached.
Everyone at GBPT must be trained and follow the rules.
These are the policies of GBPT and part of everyone's job.

English Notice of Privacy Practices
A Notice of Privacy Practices is the HIPAA document that spells out to patients what their rights are, and how we can use their information without their permission.
- It must be given to every new patient.
- It must be posted prominently for patients to see.
- It must be given to anyone who asks for it.
- It is posted on our website.
- Please destroy any old versions and use this version.

Spanish Notice of Privacy Practices
A Notice of Privacy Practices is the HIPAA document that spells out to patients what their rights are, and how we can use their information without their permission.
- It must be given to every new patient.
- It must be posted prominently for patients to see.
- It must be given to anyone who asks for it.
- It is posted on our website.
- Please destroy any old versions and use this version.

Providing and Charging for Medical Records
Patients have a right to their medical records. GBPT is allowed to charge for records based on HIPAA and state laws.
- From the time a patient makes a request we have 30 days to provide their records.
- Records requests must be tracked. Anything that may delay providing records must be immediately reported to our Corporate Compliance Officer.
- Subpoenas and court orders must immediately be forwarded to our Corporate Compliance Officer.

HIPAA Training
All new employees are required to take HIPAA training within 14 days of starting their employment.
Current employees require an annual refresher.

HIPAA Awareness
Our Corporate Compliance Officer will be sending reminder emails to keep HIPAA top-of-mind after training.
Click below to download signs and talking points for staff meetings.

Complaints & Incidents
All complaints and incidents must be documented and immediately reported to our Corporate Compliance Officer.
Failing to report an incident may result in termination.
Use the form below to report complaints and incidents. Call Eddie Revuelta with questions.

Walk-Through Checklist
Each location is required to submit a completed walk-through checklist each calendar quarter to ensure your facility stays compliant.
This easy-to-use checklist will only take a few minute to complete.

Vendors
All vendors that come in contact with patient information or the systems that process it are Business Associates and must comply with HIPAA and state laws.
All GBPT Business Associates require corporate approval.

Whistleblower Complaints
Anyone who believes they have witnessed compliance violations, sexual harassment, fraud, waste, or abuse, or other situations that should be investigated may anonymously call our Whistleblower Hotline at _____________ or file a report.
Compliance Reporting
IMMEDIATELY report complaints, incidents, medical record request delays, subpoenas and court orders.