Privacy Policy

Your privacy and the security of your personal health information are our top priorities. Learn how we protect and handle your data.

Last Updated: January 15, 2025

1. Introduction

DermaCare Dermatology Clinic ("we," "our," or "us") is committed to protecting your privacy and maintaining the confidentiality of your personal health information (PHI). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with our AI-powered symptom checker.

As a healthcare provider, we are required to comply with the Health Insurance Portability and Accountability Act (HIPAA) and other applicable privacy laws. This policy describes our practices regarding both protected health information (PHI) and general website information.

Our Commitment

We are committed to maintaining the highest standards of privacy protection and will never sell, rent, or share your personal health information for commercial purposes without your explicit consent.

2. HIPAA Compliance

DermaCare is a covered entity under HIPAA and is committed to protecting your protected health information (PHI). We have implemented physical, technical, and administrative safeguards to ensure the confidentiality, integrity, and availability of your PHI.

Your HIPAA Rights Include:

  • Right to Access: You have the right to inspect and copy your PHI
  • Right to Amend: You may request corrections to your PHI
  • Right to Restrict: You may request restrictions on how we use or disclose your PHI
  • Right to Confidential Communications: You may request that we communicate with you in a specific way or at a specific location
  • Right to Accounting: You may request an accounting of disclosures of your PHI
  • Right to File Complaints: You may file complaints about our privacy practices

Notice of Privacy Practices

Our complete HIPAA Notice of Privacy Practices is available upon request and describes in detail how we may use and disclose your protected health information.

3. Information We Collect

Personal Health Information (PHI):

  • Contact information (name, address, phone, email)
  • Demographic information (age, gender, date of birth)
  • Medical history and current symptoms
  • Treatment records and clinical notes
  • Insurance and billing information
  • Appointment and scheduling information

Website Information:

  • IP address and browser information
  • Pages visited and time spent on site
  • Referring website information
  • Search terms used to find our site
  • Cookie and session data

AI Symptom Checker Data:

  • Symptom descriptions and responses
  • Body part and condition information
  • Duration and severity indicators
  • Interaction timestamps and session data

4. How We Use Your Information

We use your information for the following purposes:

Treatment, Payment, and Healthcare Operations (TPO):

  • Providing medical care and treatment
  • Coordinating care with other healthcare providers
  • Processing insurance claims and billing
  • Quality improvement and safety monitoring
  • Staff training and competency assessment

Website and Service Improvement:

  • Improving our website functionality and user experience
  • Enhancing our AI symptom checker accuracy
  • Analyzing usage patterns to optimize services
  • Providing customer support and technical assistance

Communication:

  • Appointment reminders and confirmations
  • Test results and follow-up care instructions
  • Health education and preventive care information
  • Emergency notifications when necessary

5. AI Chatbot Data Handling

Our AI-powered symptom checker, built with Watson Assistant technology, follows strict privacy protocols:

Important Notice

The AI symptom checker is for informational purposes only and does not create a doctor-patient relationship. Information shared with the AI is not considered protected health information under HIPAA unless you become a patient.

Data Processing:

  • Conversations are processed using secure, encrypted connections
  • Data is anonymized and aggregated for AI training purposes
  • No personally identifiable information is stored permanently
  • Session data is automatically deleted after 30 days

Watson Assistant Privacy:

  • IBM Watson Assistant complies with GDPR and privacy regulations
  • Data is processed in secure, compliant data centers
  • No data is used for IBM's general AI training without consent
  • Conversations are encrypted both in transit and at rest
All AI interactions are logged securely and reviewed regularly for quality and compliance purposes.

6. Information Sharing and Disclosure

We may share your information only in the following circumstances:

Required by Law:

  • Public health reporting requirements
  • Court orders and legal proceedings
  • Law enforcement investigations
  • Reporting of abuse or neglect

Healthcare Operations:

  • Referrals to specialists or other healthcare providers
  • Insurance verification and claims processing
  • Quality assurance and accreditation activities
  • Business associates who provide services to us

Emergency Situations:

  • Serious threats to health or safety
  • Emergency medical situations
  • Public health emergencies

Business Associates

We may share PHI with business associates (such as IT providers, billing companies, or legal counsel) who help us provide healthcare services. All business associates sign agreements requiring them to protect your PHI.

7. Data Security

We implement comprehensive security measures to protect your information:

Technical Safeguards:

  • 256-bit SSL encryption for all data transmission
  • Multi-factor authentication for system access
  • Regular security audits and vulnerability assessments
  • Automated backup and disaster recovery systems
  • Firewalls and intrusion detection systems

Physical Safeguards:

  • Secure, locked facilities with restricted access
  • Security cameras and alarm systems
  • Secure disposal of physical records
  • Workstation security and automatic screen locks

Administrative Safeguards:

  • HIPAA compliance training for all staff
  • Background checks for employees with PHI access
  • Role-based access controls and permissions
  • Regular privacy and security policy updates
Our systems are regularly audited and certified for HIPAA compliance and industry security standards.

8. Your Rights and Choices

You have several rights regarding your personal information:

Access and Correction:

  • Request copies of your medical records
  • Request corrections to inaccurate information
  • Request restrictions on use or disclosure of your PHI

Communication Preferences:

  • Choose how and where we contact you
  • Opt out of non-essential communications
  • Request alternative communication methods

Website Data:

  • Disable cookies in your browser settings
  • Request deletion of non-medical website data
  • Opt out of analytics tracking

Exercising Your Rights

To exercise any of these rights, please contact our Privacy Officer using the contact information provided at the end of this policy.

9. Cookies and Website Tracking

Our website uses cookies and similar technologies to improve your experience:

Types of Cookies We Use:

  • Essential Cookies: Required for basic website functionality
  • Performance Cookies: Help us understand how visitors use our site
  • Functional Cookies: Remember your preferences and settings
  • Analytics Cookies: Provide insights into website usage patterns

Third-Party Analytics:

We may use Google Analytics or similar services to understand website usage. These services may collect information about your visits to our site and other websites. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

You can control cookie settings through your browser preferences, though disabling certain cookies may affect website functionality.

10. Third-Party Services

We work with trusted third-party services to provide our healthcare services:

IBM Watson Assistant:

  • Powers our AI symptom checker
  • Complies with healthcare privacy regulations
  • Data processing occurs in secure, compliant environments

Other Third-Party Services:

  • Payment processors for appointment booking
  • Email services for appointment reminders
  • Cloud storage providers for secure data backup
  • Analytics services for website improvement

All third-party services that handle PHI are required to sign Business Associate Agreements (BAAs) ensuring HIPAA compliance.

11. Children's Privacy

We provide pediatric dermatology services and are committed to protecting children's privacy:

  • Parental consent is required for treatment of minors
  • Our website is not directed to children under 13
  • We do not knowingly collect personal information from children under 13 without parental consent
  • Parents have the right to review and request deletion of their child's information

If you believe we have collected information from a child under 13 without proper consent, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make significant changes:

  • We will post the updated policy on our website
  • We will notify patients of material changes via email or mail
  • The "Last Updated" date at the top of the policy will be revised
  • We may provide additional notice for significant changes affecting PHI

Your continued use of our services after policy changes indicates your acceptance of the updated terms.

13. Contact Information

If you have questions about this Privacy Policy, want to exercise your rights, or need to file a complaint, please contact us:

Privacy Officer

DermaCare Dermatology Clinic

123 Medical Center Dr.

Healthcare City, HC 12345

Phone: (555) 123-4567

Email: privacy@dermacare.com

Fax: (555) 123-4568

Filing Complaints:

You also have the right to file a complaint with the U.S. Department of Health and Human Services if you believe your privacy rights have been violated:

U.S. Department of Health and Human Services
Office for Civil Rights
Website: www.hhs.gov/ocr/privacy/hipaa/complaints

No Retaliation

We will not retaliate against you for filing a complaint or exercising your privacy rights.