Privacy Policy
Last Updated: 14 August 2026
Part 1: Website Privacy Policy
LS Smiles ('we,' 'us,' or 'our') operates https://www.lssmiles.com/ and provides dental and oral healthcare services ('Services'). This Privacy Policy explains how we collect, use, disclose, and protect information about patients, responsible parties, and website visitors.
By accessing our Website, scheduling an appointment, or receiving care at our practice, you acknowledge that you have read and understood this Privacy Policy.
We are committed to protecting patient confidentiality and maintaining compliance with applicable federal and state law, including but not limited to:
- The Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations
- The Health Information Technology for Economic and Clinical Health Act (HITECH)
- Federal Trade Commission (FTC) Fair Information Practice Principles
- Applicable state privacy, dental recordkeeping, and breach notification laws
- Consumer protection laws where applicable to our location and patient base
Section 2 - Definitions
The following terms are used throughout this Policy. Where context requires, words in the singular include the plural and vice versa.
- 'Patient' means any individual receiving or seeking dental treatment or services from our practice.
- 'Responsible Party' means the individual who is financially or legally responsible for a patient's care, including but not limited to a parent, legal guardian, or spouse.
- 'Protected Health Information' or 'PHI' means individually identifiable health information as defined under HIPAA, including but not limited to treatment history, diagnoses, insurance details, and payment information.
- 'Personal Information' or 'PI' means data that identifies, relates to, or could reasonably be linked, directly or indirectly, to an individual, including but not limited to names, addresses, phone numbers, email addresses, and device identifiers.
- 'De-Identified Data' means information from which all individual identifiers have been removed such that it cannot reasonably be used to identify an individual, consistent with HIPAA Safe Harbor standards. De-identified data does not constitute PHI and is not subject to HIPAA's restrictions.
- 'Aggregate Data' means statistical or analytical information compiled from multiple individuals that does not identify any individual patient.
- 'Trusted Third Party' means a contracted service provider engaged by us to perform specific functions on our behalf. Such providers may have limited access to certain data only to the extent necessary to perform their contracted function. All Trusted Third Parties are required to handle data in accordance with applicable law and their contractual obligations to us.
- 'Call Tracking and Analytics' means a technology function through which calls to our practice and form submissions made through our website may be collected, recorded, and analyzed for quality assurance and marketing performance purposes.
- 'Website' means our official practice website, patient-facing web pages, online scheduling systems, and any web-based service operated or managed by or on behalf of us.
Section 3 - Information We May Collect
We may collect information from patients, responsible parties, and visitors to our Website in order to provide dental care, process payments, comply with legal obligations, and improve our Services. The categories of information we may collect include but are not limited to the following:
3.1 Patient and Responsible Party Information
We may collect information necessary for diagnosis, treatment, billing, and follow-up, including but not limited to: full name, date of birth, gender, and contact details; dental and medical history, treatment plans, and imaging records; insurance details and billing information; payment methods; emergency contact details; and referral information from or to other healthcare providers. By providing your phone number, you consent to receive appointment reminders and practice-related communications by SMS text message, in addition to email. You may opt out of SMS communications at any time as described in Section 4.5.
3.2 Automatically Collected Website Information
When you visit our Website or use our online services, we and our Trusted Third Parties may automatically collect certain technical and usage information, including but not limited to:
- IP address, browser type, operating system, and device identifiers
- Referring and exit pages, timestamps, and session duration
- Website usage patterns and page interaction data
- Data collected through cookies and similar tracking technologies
- Data collected through advertising measurement tools used to evaluate the effectiveness of our marketing campaigns
3.3 Website Contact and Form Submissions
Our Website uses tools to help measure and improve the quality of our services. Calls to our practice and form submissions made through our Website may be recorded and accessed by Trusted Third Parties engaged by us for quality assurance and marketing performance purposes. Such recordings and submissions may be used to improve our services and assess the effectiveness of our marketing.
3.4 Information You Provide Voluntarily
Patients and visitors may voluntarily provide information through online appointment request forms, contact forms, feedback surveys, or direct communication with our staff by phone, email, or other means.
Section 4 - How We May Use Your Information
We may use information collected from patients, responsible parties, and website visitors for the purposes described below. Our use of information is guided by the principle of minimum necessity - we use only the information reasonably required for the stated purpose.
4.1 Primary Uses - Core Healthcare Functions
We may use your information for purposes including but not limited to: providing, coordinating, and managing dental care; appointment scheduling, confirmation, and reminders; billing, insurance processing, and payment collection; maintaining dental and medical records as required by law; and coordinating care with other healthcare providers, dental laboratories, and specialists involved in your treatment.
4.2 Marketing, Analytics, and Service Improvement
We may use website interaction data and similar information in anonymized and aggregated form to measure the effectiveness of our marketing, understand how visitors use our Website, and improve the services we offer. Trusted Third Parties engaged by us may also use such data on our behalf for reporting, benchmarking, and optimization purposes.
4.3 Legally Required Uses
We may be required by law to use or disclose information without your consent in certain circumstances, including but not limited to: public health reporting obligations; responding to court orders, subpoenas, or lawful requests from law enforcement; complying with dental board or regulatory oversight requirements; and insurance audit obligations.
4.4 Restrictions on Use
We do not sell, rent, or trade personal or health information. We do not use PHI for marketing purposes without your prior written authorization. We adhere to HIPAA's minimum necessary standard - we use only the information required for each stated purpose.
4.5 SMS / Text Message Communications
By providing your phone number and opting into SMS communications from us, you agree to receive text messages related to appointment reminders, scheduling updates, office notifications, billing alerts, and other practice-related communications. Message frequency varies based on your appointments and account activity. You may cancel SMS messages at any time by replying STOP to any message you receive from us. We will send a confirmation message once you have been unsubscribed, after which no further SMS messages will be sent. To re-subscribe, contact us directly or opt in again as you did the first time. If you experience issues with our messaging program or need assistance, reply HELP to any message, or contact us directly using the details in Section 14. Carriers are not liable for delayed or undelivered messages. Message and data rates may apply for messages sent to you from us and to us from you. If you have questions about your text or data plan, please contact your wireless provider.
Section 5 - Information Sharing and Disclosure
We disclose information only as described in this Policy, as required by law, or with your authorization. All disclosures are made in accordance with HIPAA's minimum necessary standard. We do not sell patient data.
5.1 Disclosures for Dental Care and Operations
We may disclose information to third parties involved in your care or the operation of our practice, including but not limited to: treating providers and specialists; dental laboratories; pharmacies; insurance companies; billing service providers; and practice management technology vendors. Such disclosures are made only to the extent necessary for the relevant purpose.
5.2 Trusted Third-Party Service Providers
We may engage Trusted Third Parties to perform certain functions on our behalf. These functions may include but are not limited to: website hosting and management; appointment scheduling; payment processing; data analytics and marketing performance measurement; call quality assurance; and related administrative or operational services. Trusted Third Parties may access certain information only to the extent necessary to perform the specific services for which they have been engaged. They are contractually prohibited from using such information for their own independent purposes.
5.3 Call Recording and Website Submissions
Calls to our practice and form submissions made through our Website may be recorded or collected. These recordings and submissions may be accessed by Trusted Third Parties engaged by us for quality assurance and marketing performance purposes. They are not used for advertising targeting, are not used to identify individual patients for marketing purposes, and any Protected Health Information contained within them is handled in accordance with HIPAA.
5.4 Legal and Regulatory Disclosures
We may disclose information when required by applicable law, including but not limited to: court orders and subpoenas; valid law enforcement requests; regulatory oversight by dental boards or health departments; and mandatory public health reporting obligations.
5.5 De-Identified and Aggregate Data
We may use or share de-identified data or Aggregate Data for purposes including but not limited to practice management analytics, treatment outcome reporting, and marketing performance statistics. Such data cannot reasonably be used to identify any individual patient and does not constitute PHI.
Section 6 - Cookies and Tracking Technologies
Our Website uses a range of tracking technologies to support site functionality, analytics, and marketing. By using our Website, you consent to the use of these technologies as described below.
6.1 Cookies
Our Website uses cookies - small data files stored on your device - to improve site functionality, personalize your experience, and identify returning visitors. Cookie usage on this Website is not linked to individually identifiable health information. You may manage cookie preferences through your browser settings, though disabling certain cookies may affect the functionality of some areas of our Website.
6.2 Analytics Tools
We may use third-party analytics tools to understand how visitors interact with our Website. Information collected through analytics tools is used in aggregate and anonymized form and is not used to identify individual patients or to access Protected Health Information.
6.3 Advertising Measurement
Our Website may use advertising measurement tools to assess the effectiveness of our marketing campaigns. These tools measure whether visits to our website resulted from our advertising activity and are used for performance reporting purposes only. Any data collected through these tools is handled in accordance with the applicable platform provider's terms and our obligations under HIPAA.
6.4 Website Recording and Interaction Tools
Our Website may use tools that record visitor interactions including but not limited to mouse movements, scrolling behavior, and page clicks, for the purpose of improving website design and user experience. Where such tools are in use, they are configured to prevent the capture of information entered into form fields. They are not deployed on pages where patients submit health-related information.
Section 7 - Security Measures
We maintain administrative, technical, and physical safeguards designed to protect personal and health information against unauthorized access, use, disclosure, alteration, or destruction, in accordance with the HIPAA Security Rule and applicable state law.
Section 8 - Data Retention
We retain dental, medical, administrative, and communication records for as long as necessary to provide care, comply with applicable legal obligations, support claims resolution, and maintain accurate business and compliance records. Retention periods may vary based on applicable state dental board regulations and other legal requirements.
Categories of information we retain include but are not limited to:
- Patient dental and medical records: generally retained for a minimum of 7 years after the last date of service, or for such longer period as required by applicable state law or professional standards
- Dental imaging, diagnostic records, and treatment documentation: retained for the same minimum period as medical records
- Billing, insurance, and financial records: retained for a minimum of 7 years to comply with tax, insurance, and audit obligations
- Website analytics and cookie data: retained for up to 24 months
- Call recordings and form submissions accessed by Trusted Third Parties for quality assurance: retained in accordance with our service agreements and applicable law
Section 9 - Breach Notification
9.1 Definition of a Breach
A breach is the unauthorized acquisition, access, use, or disclosure of Protected Health Information or Personal Information that compromises its privacy or security, as defined under HIPAA's Breach Notification Rule and applicable state law. Examples include but are not limited to: cyberattacks, ransomware, loss or theft of devices containing patient data, unauthorized employee access, and accidental disclosure.
9.2 Patient Notification
If a breach is confirmed, we will notify affected patients within 60 days of discovering the breach, in accordance with HIPAA's Breach Notification Rule and the Texas Identity Theft Enforcement and Protection Act (Texas Business & Commerce Code § 521.053).
9.3 Regulatory Notification
In addition to notifying affected patients, we will notify the relevant regulatory authorities as required by HIPAA's Breach Notification Rule and applicable state law, including but not limited to the U.S. Department of Health and Human Services, Office for Civil Rights.
Section 10 - Your Rights and Choices
Subject to applicable law, you may have the following rights regarding your information. To exercise any of these rights, please contact us using the details in Section 14. We will respond within the timeframe required by applicable law.
Your rights under this Privacy Policy include but are not limited to:
- Access: Request confirmation of whether we hold Personal Information about you and, where applicable, obtain a copy
- Correction: Request correction of inaccurate or incomplete Personal Information we hold about you
- Restriction: Request that we restrict certain uses or disclosures of your information, subject to legal and operational limitations
- Opt-Out of Marketing Communications: Decline to receive marketing or promotional communications from us at any time without affecting your entitlement to care
- Revocation of Consent: Withdraw any prior authorization for non-essential uses of your information in writing, effective for future disclosures only
- Complaint: File a complaint with us or directly with the U.S. Department of Health and Human Services, Office for Civil Rights (www.hhs.gov/ocr). There will be no retaliation for filing a complaint
Section 11 - Call Recording and Third Party Vendors
Our Website uses tools to help us measure and improve the quality of our services. Calls to our practice and form submissions made through our Website may be recorded and accessed by Trusted Third Parties engaged by us for quality assurance and marketing performance purposes. Such information is used to improve our services and measure the effectiveness of our marketing. It is not used for advertising targeting and any Protected Health Information is handled in accordance with HIPAA.
Section 12 - Children's Privacy
12.1 Parental Consent and Authority
Where the practice treats minor patients, all collection, use, and disclosure of a minor patient's Protected Health Information is subject to the consent and authority of the minor's parent or legal guardian, except where applicable state law grants adolescents independent privacy rights for specific categories of care. Parents and legal guardians are recognized as personal representatives of minor patients under HIPAA and have the right to access, amend, and request restrictions on their child's Protected Health Information.
12.2 COPPA Compliance (Children Under 13)
We do not knowingly collect Personal Information directly from children under the age of 13 without verifiable parental or guardian consent. All online forms, scheduling tools, and appointment systems on our Website are designed for use by parents and guardians on behalf of minor patients. If we become aware that we have inadvertently collected information directly from a child under 13 without parental consent, we will delete that information promptly.
12.3 Adolescent Confidentiality (Ages 13-17)
We recognize that adolescent patients may have legally protected confidentiality rights for certain categories of care under applicable state law, including but not limited to mental health services, reproductive health, and substance use treatment. Where such rights apply, records relating to confidential services may be maintained separately from the general patient record to prevent unauthorized parental access. We follow the applicable confidentiality rules of the state in which care is provided.
12.4 Advertising and Marketing
Any marketing activity conducted on our behalf is configured to target parents, guardians, and adult prospective patients only. We do not engage in behavioral advertising directed at minors. Advertising measurement tools on our Website are not used to collect data from minors and are not deployed on pages where minor patients' health information may be submitted.
12.5 Call Recording - Parental Representative Context
Our Website uses tools to help us measure and improve the quality of our services. Calls to our practice and form submissions made through our Website may be recorded and accessed by Trusted Third Parties engaged by us for quality assurance and marketing performance purposes. If you are contacting us as a parent or legal guardian on behalf of a minor patient, your consent covers any discussion of your child's care. Such recordings and submissions are used to improve our services and measure the effectiveness of our marketing - they are not used for advertising targeting, and any Protected Health Information is handled in accordance with HIPAA.
12.6 Data Retention for Minor Patients
Records for minor patients are retained until the patient reaches the age of majority under applicable state law, plus the legally mandated minimum retention period for that state (typically 7 to 10 additional years). For example, where state law requires 7 years' retention and a patient is first seen at age 8, the record will be retained until the patient turns 25.
12.7 Age Transition
As minor patients reach the age of majority under applicable law, they assume independent rights over their own Protected Health Information. From that point, parental or guardian access to the patient's records requires the adult patient's own written authorization. Where a patient begins treatment as a minor and completes treatment as an adult, the applicable rights during each phase of treatment are determined by the patient's age at that time.
12.8 Mandatory Reporting
As licensed healthcare providers serving minor patients, we are mandated reporters under applicable federal and state law. We may disclose information about a minor patient without parental or guardian consent where required by law, including but not limited to: suspected or confirmed child abuse or neglect; threats of harm to the patient or others; and communicable disease reporting obligations. Such disclosures are limited to the minimum information necessary to fulfill the applicable legal obligation.
Section 13 - Changes to this Policy
We may revise this Privacy Policy from time to time to reflect changes in applicable law, our services, or our operational practices. When material changes are made, we will notify patients by one or more of the following methods: posting a revised version on our Website; displaying a notice at our office reception; or sending written or email notice to patients for whom we hold contact details. The Last Updated date at the top of this Policy reflects the date of the most recent revision. Your continued use of our Services following notice of changes constitutes your acceptance of the revised Policy.
Section 14 - Contact Us
If you have questions about this Privacy Policy, wish to exercise any of the rights described in Section 10, or need to raise a privacy-related concern, please contact us:
Address: 1300 E Ralph Hall Pkwy #114, Rockwall, TX 75032
Phone: 972-771-2213
Email: office@lssmiles.com
Section 15 - Addendum
In accordance with the Texas Medical Records Privacy Act (Chapter 181 of the Texas Health and Safety Code), your Protected Health Information may be disclosed electronically only for purposes of treatment, payment, healthcare operations, and other purposes permitted or required by law. Any electronic disclosure beyond these permitted purposes requires your written authorization. You have the right to access your electronic health records within 15 business days of a written request to us.
Part 2: Notice of Privacy Practices (HIPAA)
This notice describes how medical information about you may be used and disclosed, and how you can get access to this information. Please review it carefully.
If you have any questions about this Notice please contact our Privacy Officer or any staff member in our office.
Privacy Officer: Cindy Avant
Contact number: 972-771-2213
External HIPAA Privacy and Security Resource contact: David Wornica, CHPSE.
Contact number: 469-342-8300 ext. 628.
This Notice of Privacy Practices describes how we may use and disclose your protected health information to carry out your treatment, collect payment for your care and manage the operations of this clinic. It also describes our policies concerning the use and disclosure of this information for other purposes that are permitted or required by law. It describes your rights to access and control your protected health information. "Protected Health Information" (PHI) is information about you, including demographic information that may identify you, that relates to your past, present, or future physical or mental health or condition and related health care services.
We are required by Federal law to abide by the terms of this Notice of Privacy Practices. We may change the terms of our notice at any time. The new notice will be effective for all protected health information that we maintain at that time. You may obtain revisions to our Notice of Privacy Practices by accessing our website, calling the office and requesting that a revised copy be sent to you in the mail or asking for one at the time of your next appointment.
a. Uses and Disclosures of Protected Health Information
By applying to be treated in our office, you are implying consent to the use and disclosure of your protected health information by your doctor, our office staff and others outside of our office that are involved in your care and treatment for the purpose of providing health care services to you. Your protected health information may also be used and disclosed to bill for your health care and to support the operation of the practice.
USES AND DISCLOSURES OF PROTECTED HEALTH INFORMATION BASED UPON YOUR IMPLIED CONSENT
Following are examples of the types of uses and disclosures of your protected health care information we will make, based on this implied consent. These examples are not meant to be exhaustive but to describe the types of uses and disclosures that may be made by our office.
Treatment: We may use and disclose your protected health information (PHI) to provide, coordinate, or manage your healthcare and related services. This includes sharing your information with other healthcare providers, such as specialists or laboratories, who assist in your treatment at the request of your dentist.
Our office may also use HIPAA-compliant artificial intelligence (AI) tools to support your care. These tools help review dental images (such as X-rays) and other health data to assist with diagnosis and treatment planning. AI is used to enhance, not replace, your provider’s clinical judgment. All AI-assisted findings are reviewed and approved by a licensed dentist before being used in your treatment.
Payment: Your protected health information will be used, as needed, to obtain payment for your health care services, This may include certain activities that your health insurance plan may undertake before it approves or pays for the health care services we recommend for you such as making a determination of eligibility or coverage for insurance benefits, reviewing services provided to you for medical necessity, and undertaking utilization review activities, For example, obtaining approval for procedures may require that your relevant protected health information be disclosed to the health plan to obtain approval for those services.
Healthcare Operations: We may use or disclose, as needed, your protected health information in order to support the business activities of this office, These activities may include, but are not limited to, quality assessment activities, employee review activities and staff training.
For example, we may disclose your protected health information to interns or precepts that see patients at our office, In addition, we may use a sign-in sheet at the registration desk where you will be asked to sign your name and indicate your doctor. Communications between you and the doctor or his assistants may be recorded to assist us in accurately capturing your responses, We may also call you by name in the reception area when your doctor is ready to see you, We may use or disclose your protected health information, as necessary, to contact you to remind you of your appointment.
We will share your protected health information with third party "Business Associates" that perform various activities (e,g,, billing, transcription services for the practice), Whenever an arrangement between our office and a Business Associate involves the use or disclosure of your protected health information, we will have a written agreement with that Business Associate that contains terms that will protect the privacy of your protected health information.
We may use or disclose your protected health information, as necessary, to provide you with information about treatment alternatives or other health-related benefits and services that may be of interest to you, We may also use and disclose your protected health information for other internal marketing activities, For example, your name and address may be used to send you a newsletter about our practice and the services we offer. We may also send you information about products or services that we believe may be beneficial to you, You may request that these materials not be sent to you.
USES AND DISCLOSURES OF PROTECTED HEALTH INFORMATION THAT MAY BE MADE WITH YOUR WRITTEN AUTHORIZATION
Other uses and disclosures of your protected health information will be made only with your written authorization, unless otherwise permitted or required by law as described below.
For example, with your written, signed authorization, we may use your demographic information and the dates that you received treatment from our office, as necessary, in order to contact you for fundraising activities supported by our office.
You may revoke any of these authorizations, at any time, in writing, except to the extent that your doctor or the practice has taken an action in reliance on the use or disclosure indicated in the authorization.
OTHER PERMITTED AND REQUIRED USES AND DISCLOSURES THAT MAY BE MADE WITH YOUR AUTHORIZATION OR OPPORTUNITY TO OBJECT
In the following instance where we may use and disclose your protected health information, you have the opportunity to agree or object to the use or disclosure of all or part of your protected health information. If you are not present or able to agree or object to the use or disclosure of the protected health information, then your doctor may, using professional judgment, determine whether the disclosure is in your best interest. In this case, only the protected health information that is relevant to your health care will be disclosed.
Others Involved in Your Healthcare: Unless you object, we may disclose to a member of your family, a relative, a close friend or any other person you identify, your protected health information that directly relates to that person's involvement in your health care. If you are unable to agree or object to such a disclosure, we may disclose such information as necessary if we determine that it is in your best interest based on our professional judgment. We may use or disclose protected health information to notify or assist in notifying a family member, personal representative or any other person that is responsible for your care of your location or general condition. Finally, we may use or disclose your protected health information to an authorized public or private entity to assist in disaster relief efforts and to coordinate uses and disclosures to family or other individuals involved in your health care.
OTHER PERMITTED AND REQUIRED USES AND DISCLOSURES THAT MAY BE MADE WITHOUT YOUR AUTHORIZATION OR OPPORTUNITY TO OBJECT
We may use or disclose your protected health information in the following situations without your consent or authorization. These situations include:
Required By Law: We may use or disclose your protected health information to the extent that the use or disclosure is required by law. The use or disclosure will be made in compliance with the law and will be limited to the relevant requirements of the law. You will be notified, as required by law, of any such uses or disclosures.
Public Health: We may disclose your protected health information for public health activities and purposes to a public health authority that is permitted by law to collect or receive the information. The disclosure will be made for the purpose of controlling disease, injury or disability. We may also disclose your protected health information, if directed by the public health authority, to a foreign government agency that is collaborating with the public health authority.
Communicable Diseases: We may disclose your protected health information, if authorized by law, to a person who may have been exposed to a communicable disease or may otherwise be at risk of contracting or spreading the disease or condition.
Health Oversight: We may disclose protected health information to a health oversight agency for activities authorized by law, such as audits, investigations, and inspections. Oversight agencies seeking this information include government agencies that oversee the health care system, government benefit programs, other government regulatory programs and civil rights laws.
Abuse or Neglect: We may disclose your protected health information to a public health authority that is authorized by law to receive reports of child abuse or neglect. In addition, we may disclose your protected health information if we believe that you have been a victim of abuse, neglect or domestic violence to the governmental entity or agency authorized to receive such information. In this case, the disclosure will be made consistent with the requirements of applicable Federal and state laws.
Legal Proceedings: We may disclose protected health information in the course of any judicial or administrative proceeding, in response to an order of a court or administrative tribunal (to the extent such disclosure is expressly authorized), in certain conditions in response to a subpoena, discovery request or other lawful process.
Law Enforcement: We may also disclose protected health information, so long as applicable legal requirements are met, for law enforcement purposes. These law enforcement purposes include (I) legal process and otherwise required by law, (2) limited information requests for identification and location purposes, (3) pertaining to victims of a crime, (4) suspicion that death has occurred as a result of criminal conduct, (5) in the event that a crime occurs on the premises of the Practice, and (6) medical emergency (not on the Practice's premises) and it is likely that a crime has occurred.
Workers' Compensation: We may disclose your protected health information, as authorized, to comply with workers' compensation laws and other similar legally-established programs.
Required Uses and Disclosures: Under the law, we must make disclosures to you and when required by the Secretary of the Department of Health and Human Services to investigate or determine our compliance with the requirements of Section 164.500 et. seq.
Special Protections for Substance Use Disorder Records: If we receive or maintain records related to substance use disorder treatment that are protected under federal law (42 CFR Part 2), those records are subject to additional confidentiality protections.
- These records may be used and disclosed for treatment, payment, and health care operations as permitted by law.
- We will not use or disclose these records, or testimony about their contents, in civil, criminal, administrative, or legislative proceedings against you unless permitted by law, with your written consent, or pursuant to a court order that meets applicable legal requirements.
- Other uses and disclosures of substance use disorder records require your written authorization or must otherwise be permitted or required by law.
Special Protections for Reproductive Health Information: Information related to reproductive health care may be subject to additional privacy protections under federal law and our internal privacy practices.
- We may use and disclose reproductive health information for treatment, payment, and health care operations as permitted by law.
- We will not use or disclose reproductive health information for the purpose of investigating or imposing liability on an individual for seeking, obtaining, providing, or facilitating lawful reproductive health care.
- Other uses and disclosures of reproductive health information require your written authorization or must otherwise be permitted or required by law.
b. Your Rights
Following is a statement of your rights with respect to your protected health information and a brief description of how you may exercise these rights.
You have the right to inspect and copy your protected health information. This means you may inspect and obtain a copy of protected health information about you that is contained in a designated record set for as long as we maintain the protected health information. A "designated record set" contains medical and billing records and any other records that your doctor and the Practice uses for making decisions about you.
Under Federal law, however, you may not inspect or copy the following records: psychotherapy notes; information complied in reasonable anticipation of, or use in, a civil, criminal, or administrative action or proceeding, and protected health information that is subject to law that prohibits access to protected health information. Depending on the circumstances, a decision to deny access may be reviewed. In some circumstances, you may have a right to have this decision reviewed. Please ask your doctor if you have questions about access to your medical record.
You have the right to request a restriction of your protected health information. This means you may ask us not to use or disclose any part of your protected health information for the purposes of treatment, payment or healthcare operations. You may also request that any part of your protected health information not be disclosed to family members or friends who may be involved in your care or for notification purposes as described in this Notice of Privacy Practices. Your request must be in writing and state the specific restriction requested and to whom you want the restriction to apply.
Your provider is not required to agree to a restriction that you may request. If the doctor believes it is in your best interest to permit use and disclosure of your protected health information, your protected health information will not be restricted. If your doctor does agree to the requested restriction, we may not use or disclose your protected health information in violation of that restriction unless it is needed to provide emergency treatment. With this in mind, please discuss any restriction you wish to request with your doctor.
You may request a restriction by presenting your request, in writing to a staff member in our office. The staff member will provide you with "Restriction of Consent" form. Complete the form, sign it, and ask that the staff member provide you with a photocopy of your request initialed by them. This copy will serve as your receipt.
You have the right to request to receive confidential communications from us by alternative means or at an alternative location. We will accommodate reasonable requests. We may also condition this accommodation by asking you for information as to how payment will be handled or specification of an alternative address or other method of contact. We will not request an explanation from you as to the basis for the request. Please make this request in writing.
You may have the right to have your doctor amend your protected health information. This means you may request an amendment of protected health information about you in a designated record set for as long as we maintain this information. In certain cases, we may deny your request for an amendment. If we deny your request for amendment, you have the right to file a statement of disagreement with us and we may prepare a rebuttal to your statement and will provide you with a copy of any such rebuttal. Please ask your doctor if you have questions about amending your medical record.
You have the right to receive an accounting of certain disclosures we have made, if any, of your protected health information. This right applies to disclosures for purposes other than treatment, payment or healthcare operations as described in this Notice of Privacy practices. It excludes disclosures we may have made to you, to family members or friends involved in your care, pursuant to a duly executed authorization or for notification purposes. The right to receive this information is subject to certain exceptions, restrictions and limits.
You have the right to obtain a paper copy of this notice from us, upon request, even if you have agreed to accept this notice electronically.
c. Complaints
You may complain to us, to the Texas Attorney General's Office, or the Secretary of Health and Human Services, if you believe your privacy rights have been violated by us. You may file a complaint with us by notifying our Privacy Officer of your complaint. We will not retaliate against you for filing a complaint.
You may contact our Privacy Officer in writing at our office address. Our website may offer additional information about the complaint process.
This notice was published and becomes effective on February 16, 2026.