Privacy and Communications
Website Privacy and Communication Notice
This page explains how the public website is intended to be used, what it currently collects, and what visitors should avoid sending through non-secure channels.
Intended Website Use
This website is intended to provide general information about the practice, professional background, service areas, and public contact details. It is not designed as a patient portal or a secure method for transmitting protected health information.
Current Website Safeguards
- The website is informational and does not currently provide patient login, intake submission, chat, or online scheduling that collects protected health information.
- The site code currently does not include advertising pixels, session-replay tooling, or third-party analytics scripts.
- Security headers are configured to reduce framing, MIME sniffing, and referrer leakage, and to narrow what the browser may load or expose.
- Outbound links to third-party sites are marked to avoid sending referrer data where possible.
Communication Boundaries
- Do not use LinkedIn, map links, or general website navigation for urgent clinical concerns or private health details.
- Do not send diagnosis details, treatment summaries, insurance numbers, or other protected health information through channels that are not explicitly designated as secure.
- If secure intake, messaging, telehealth, or payment tools are added later, they should be reviewed separately for HIPAA risk, vendor terms, and business-associate requirements before launch.
Third-Party Destinations
Links to LinkedIn, Google Maps, or other third-party properties are provided for convenience only. Once you leave this website, the privacy and security practices of the destination site control.
Operational Review Still Required
| Risk analysis | Maintain a documented HIPAA risk analysis and update it as systems, vendors, or workflows change. |
|---|---|
| Vendors | Review hosting, email, form, telehealth, and payment vendors for HIPAA suitability and business-associate obligations. |
| Policies | Keep administrative, technical, and physical safeguards, workforce procedures, breach response, and retention practices current. |
| Legal review | Review these website notices against actual operations, state law, and intake documents before production reliance. |