Privacy Policy
[LAST UPDATED DATE]
1. Who we are
Practice: [FULL LEGAL NAME OF PRACTICE]
Address: [REGISTERED ADDRESS]
Contact: [EMAIL] · [PHONE]
Privacy Officer: [NAME AND CONTACT DETAILS]
2. Information we collect
Booking data: name, email address, phone number, selected treatment and appointment time.
Health information you provide in the medical history form. This is Protected Health Information (PHI) under HIPAA.
Technical data: IP address, browser type and visit timestamps, logged for security purposes.
3. How we use and disclose PHI
We use PHI for treatment, payment and health care operations, as permitted by the HIPAA Privacy Rule (45 CFR §164.506).
We do not sell your information. We do not use PHI for marketing without your written authorization.
[IF APPLICABLE: describe any disclosures required by state law]
4. Your rights
You have the right to access, request an amendment to, and receive an accounting of disclosures of your PHI, and to request restrictions on its use (45 CFR §164.520-528).
You may file a complaint with us at [EMAIL], or with the U.S. Department of Health and Human Services, Office for Civil Rights. We will not retaliate against you for filing a complaint.
[IF SERVING CALIFORNIA RESIDENTS: add CCPA/CPRA disclosures]
5. Retention
Medical records are retained for [RETENTION PERIOD] in accordance with [STATE] law.
Booking and contact data is retained for [RETENTION PERIOD].
6. Safeguards
Data is transmitted over encrypted (HTTPS/TLS) connections and protected by access controls and audit logging, consistent with the HIPAA Security Rule.
Business Associate Agreements are in place with our service providers as required by 45 CFR §164.308(b).