Effective Date: December 4, 2024
Vendetti Wellness Group (“we,” “our,” or “us”) values your privacy and is committed to protecting your personal information. This Privacy Policy outlines how we collect, use, disclose, and safeguard your data, including sensitive health and payment information. We comply with HIPAA, PCI DSS, TCR, and other applicable regulations to maintain the confidentiality and security of your information.
- Information We Collect
We collect various types of information to provide and enhance our services:-
- Personal Information
- Identifiers: Name, address, phone number, email, date of birth, and demographic details.
- Payment Information: Credit/debit card numbers and billing information, processed securely in compliance with PCI DSS.
- ePHI (Electronic Protected Health Information)
Protected under HIPAA, this includes:- Medical history and treatment plans.
- Provider notes and care details.
- Appointment information.
- Communication Information
- Information shared via text, email, and phone communications.
- Preferences for appointment reminders and promotional messages.
- Technical and Non-Personal Information
- Website Data: IP address, browser type, and usage patterns.
- Cookies and Tracking: Used for performance and personalization.
- Information from Third Parties
We may receive additional data from healthcare providers, insurers, or authorized representatives to facilitate care.
- Personal Information
-
- How We Use Your Information
-
- Healthcare and Operational Purposes
- To provide and coordinate care.
- To process payments securely.
- To send appointment reminders or administrative updates via text, email, or phone.
- Legal and Regulatory Compliance
- Compliance with HIPAA for ePHI and PCI DSS for secure payments.
- Adherence to TCR (Telecommunications Consumer Protection Regulations) for text and email communications.
- Marketing and Research
- With consent, we may send newsletters, surveys, or promotional content.
- De-identified data may be used for research or quality assurance.
- Healthcare and Operational Purposes
-
- Sharing Your Information
We do not sell your personal information. However, data may be shared under specific circumstances:-
- Service-Related Sharing
- With third-party providers (e.g., payment processors, billing services) under strict data protection agreements.
- With healthcare providers for care coordination.
- Legal Obligations
- With government or regulatory bodies when legally required.
- To comply with subpoenas, court orders, or law enforcement requests.
- Mergers and Acquisitions
- In case of a business transition, your information may be transferred to the successor entity.
- De-identified data may be used for research or quality assurance.
- Service-Related Sharing
-
- Protecting Your Information
We prioritize the security of your personal information through:-
- ePHI Safeguards
- Encryption of ePHI during storage and transmission.
- Access limited to authorized personnel with a need to know.
- Regular audits and monitoring of systems.
- Payment Information Security
- Use of PCI DSS-compliant platforms.
- No storage of full payment card details on our systems.
- General Data Protection
- Firewalls and anti-virus protections.
- Periodic security assessments and training.
- SSL Encryption
- Our website uses SSL encryption to protect your personal and payment information during transmission. All communications between your browser and our website are securely encrypted, ensuring that sensitive data, such as payment details and health information, cannot be intercepted by third parties.
- ePHI Safeguards
-
- Your Rights and Choices
We prioritize the security of your personal information through:-
- Access and Correction
You may request access to your personal information and request corrections to inaccurate data. - Deletion and Retention
You may request deletion of data unless retention is required by law (e.g., HIPAA mandates a 6-year retention period for ePHI). - Communication Preferences
- Unsubscribe from marketing emails or texts by following the provided instructions.
- Opt-out of text or email reminders by contacting us directly.
- Complaint Submission
You can file complaints about your data privacy rights with us or the Office for Civil Rights (OCR).
- Access and Correction
-
- Communications via Text and Email (TCR Compliance)
Vendetti Wellness Group follows the Telecommunications Consumer Protection Regulations (TCR), ensuring that text message communications are compliant. This includes all start, stop, and help functionalities for text communication.-
- Compliance with TCR Regulations
- Opt-In/Consent: By providing your contact information and consenting to communication, you agree to receive text messages from us about your care. You may opt-in for appointment reminders, treatment updates, and other service-related notifications.
- Stop/Opt-Out Functionality: You can opt-out of receiving further text messages at any time. Reply “STOP” to any text message you receive from us, and we will immediately cease sending you further text messages.
- Help Functionality: To receive assistance, reply with “HELP” to any text message you receive. We will provide instructions or contact you for support.
- Message Frequency and Charges: Message frequency may vary depending on your interaction with our services. We do not charge for text messages, but standard carrier message and data rates may apply.
- Opt-Out Process for Marketing Communications: If you have opted in for marketing communications, you may opt-out at any time by following the instructions in the messages or by contacting us directly.
- SMS Opt-In consent and phone numbers for the purpose of SMS are not being shared with any third parties under any circumstances.
- Compliance with TCR Regulations
Vendetti Wellness Group will maintain a log of your opt-in consent for SMS communications, and ensure that all text messages are sent in compliance with the Telephone Consumer Protection Act (TCPA), TCR, and other applicable regulations.
-
- Cookies and Tracking Technologies
-
- Types of Cookies
- Essential Cookies: Required for website functionality.
- Performance Cookies: Used to analyze website traffic and usage trends.
- Preference Cookies: Store user preferences for a personalized experience.
- Managing Cookies
Adjust cookie settings via your browser or our website’s cookie management tool. - Third-Party Cookies and Advertising
We may use third-party services to display ads or track user behavior on our website. These services may use cookies to collect information and display targeted ads based on your browsing behavior. You can opt-out of personalized advertising by visiting the Digital Advertising Alliance website or adjusting your browser settings to block third-party cookies.
- Types of Cookies
-
- Data Retention and Deletion Policies
We retain your personal information only as long as necessary to fulfill the purposes outlined in this Privacy Policy and comply with applicable legal, regulatory, and business requirements. For instance, ePHI is retained for a minimum of six years as required by HIPAA, while payment information is retained for transaction processing and any disputes. Non-essential data, such as marketing preferences, may be retained until you request deletion. - Disaster Recovery and Continuity
We maintain disaster recovery protocols to ensure data security and service continuity during emergencies. - Vendor and Third-Party Compliance
We vet all third-party service providers for compliance and require Business Associate Agreements (BAAs) when handling ePHI.-
- Vendor Privacy and Data Protection
- We enter into Business Associate Agreements (BAAs) with vendors who process ePHI to ensure they meet HIPAA, PCI DSS, and other relevant standards for safeguarding data. These agreements require vendors to adopt appropriate security measures, restrict the use of your data, and promptly report any breaches.
- We also ensure that these vendors are compliant with all applicable data protection regulations and conduct regular security reviews.
- Vendor Privacy and Data Protection
-
- Special Data Protections
-
- Behavioral Health and Substance Use Records
- Records for behavioral health and substance use are protected under 42 CFR Part 2.
- Disclosures require explicit consent or legal authorization.
- Telehealth Services
- Telehealth sessions are conducted on HIPAA-compliant platforms with encryption.
- Sessions are not recorded.
- Behavioral Health and Substance Use Records
-
- International Data Transfers
If you are accessing our services from outside the United States, please note that your personal information, including ePHI, may be transferred to, stored, and processed in the United States. By using our services, you consent to such transfers. - Updates to the Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version on our website and update the Effective Date at the top of this document. You are encouraged to review this policy periodically to stay informed about how we are protecting your data. - Dispute Resolution
Any disputes regarding this Privacy Policy will be resolved in accordance with the laws of the state of Massachusetts. In the event of a dispute, you agree to resolve the matter through binding arbitration, rather than through litigation, in a manner agreed upon by both parties. - Minors’ Privacy
Our services are not intended for children under the age of 18. We do not knowingly collect personal information from minors. If we learn that we have inadvertently collected data from a minor without appropriate consent, we will take steps to delete that information as required by law. - Artificial Intelligence and Emerging Technologies
If AI or emerging technologies are used, they will comply with HIPAA, ethical standards, and relevant privacy laws. - Consent for Data Collection
By using our services, you consent to the collection, use, and sharing of your information as outlined in this Privacy Policy. You can withdraw your consent at any time, except where retention of certain data is legally required. - Data Minimization
We strive to collect and retain only the information necessary to provide our services and comply with legal requirements. We will not collect unnecessary or excessive data beyond what is required for specific services. - Accessibility and Language Availability
This Privacy Policy is available in accessible formats and alternative languages upon request.
Contact us at info@vendettiwellnessgroup.com for assistance.
Contact Us
If you have any questions or concerns about this Privacy Policy, or how we handle your personal
information, please contact us:
- Email: info@vendettiwellnessgroup.com
- Phone: 508-589-5333
- Address: 77 Main Street, Second Floor, Hopkinton, MA 01748