Privacy Notices
Part A — HIPAA Notice of Privacy Practices · Part B — Website Privacy Policy
Notice of Privacy Practices
We are required by law to protect the privacy of your health information, to give you this notice of our legal duties and privacy practices, and to follow the terms of the notice currently in effect.
01. Who This Notice Covers
This notice applies to Aone Health & Wellness and to every clinician, employee, contractor and volunteer who works with us and handles your health information. It covers the health information we create or receive when you have a telehealth visit with us, when you complete an intake form, when we bill for a service, and when we keep a record of your care.
"Protected health information" (PHI) means information that identifies you and relates to your health, your care, or payment for your care. Your name, phone number, date of birth, the conditions we evaluate you for, the medications we prescribe, and the fact that you are our patient at all are examples.
Effective Date
Effective date: to be confirmed by counsel prior to publication. This notice replaces any earlier privacy notice we have given you. If we change it materially, the revised notice applies to all health information we hold, including information created before the change.
02. Treatment, Payment and Health Care Operations
We may use and share your health information for these three purposes without asking you to sign anything first.
Treatment
We use your information to provide and coordinate your care. For example: during a video visit for testosterone therapy, your clinician reviews the lab results you uploaded and sends a prescription electronically to the pharmacy you chose. That means your name, date of birth and the prescription details go to that pharmacy.
Payment
We use your information to bill and collect for the care we provide. For example: to charge the card you used to book a weight-management consultation, we give our payment processor your name, contact details and the amount owed. If you use insurance, we may share the visit date and diagnosis codes with your plan so the claim can be paid.
Health Care Operations
We use your information to run the practice safely. For example: a supervising physician reviews a sample of completed cannabis certification evaluations to check that our clinicians are documenting state qualifying conditions correctly. Scheduling, staff training, licensure and credentialing checks, and internal quality review are all operations uses.
03. Other Uses and Disclosures We May Make
The law permits or requires us to share your health information in the following situations, without your authorisation. We share only the minimum necessary.
- As required by law. When a federal, state or local law requires us to disclose it. For example, mandatory reporting of suspected abuse or neglect.
- Public health activities. To public health authorities to prevent or control disease, report births and deaths, report reactions to medications or problems with products, or report to a prescription drug monitoring programme where state law requires it.
- Health oversight. To agencies that audit, licence, investigate or inspect health care providers — state medical boards, licensing agencies, and federal or state health oversight bodies.
- Judicial and administrative proceedings. In response to a court order, subpoena, discovery request or other lawful process, subject to the notice and protective-order safeguards the rule requires.
- Law enforcement. In the specific circumstances the rule allows — for example, in response to a valid court order or warrant, to identify or locate a suspect or missing person, or about a death we believe may have resulted from criminal conduct.
- To prevent a serious threat to health or safety. When we believe in good faith that disclosure is necessary to prevent or lessen a serious and imminent threat to you or to someone else, and the disclosure is to a person able to prevent or lessen that threat.
- Workers' compensation. As authorised by workers' compensation laws or similar programmes that provide benefits for work-related injury or illness.
- Coroners, medical examiners, funeral directors, and organ donation. As permitted by law.
- Business associates. To vendors who perform services for us and need your information to do so — our electronic health record, telehealth video platform, e-prescribing service, billing service, and messaging providers. Each must sign a written business associate agreement obliging it to protect your information under the same standards we follow.
For most other uses and disclosures — including anything not described in this notice — we will ask for your written authorisation first.
04. Medical Cannabis Certification Records
Medical cannabis certification records need a separate explanation, because they are governed by state programme rules on top of HIPAA, and because federal and state law treat cannabis differently.
Cannabis remains a controlled substance under federal law even in states that have legalised medical use. A state medical cannabis certification does not create any protection under federal law. This can matter for federal employment, federal housing, firearms eligibility, immigration status and certain professional licences. We cannot advise you on those consequences — if they are relevant to you, speak to a lawyer before you apply.
State Registry Information
When a clinician certifies you, information about that certification may be submitted to, or held by, a state programme registry. Once it is in the state's hands, the state's own confidentiality rules govern it — not this notice.
- Michigan. The Michigan Medical Marihuana Program is administered by the Cannabis Regulatory Agency within the Department of Licensing and Regulatory Affairs (LARA). Registry information is confidential under the Michigan Medical Marihuana Act and is disclosed only as that Act allows.
- Illinois. The Medical Cannabis Patient Registry is administered by the Illinois Department of Public Health (IDPH). Registry application and identification information is confidential and exempt from disclosure under the Compassionate Use of Medical Cannabis Program Act, except as that Act permits.
- California. The Medical Marijuana Identification Card Program is voluntary and is administered through county health departments under the California Department of Public Health. County programmes have their own confidentiality obligations, and California's Confidentiality of Medical Information Act applies to the medical records we hold.
Records we hold about your evaluation remain subject to this notice. Records the state holds are subject to state programme requirements, including any requirement that we report or verify a certification. If you want to know exactly what a state registry holds about you, contact that programme directly.
05. Uses That Require Your Written Authorisation
We will not do any of the following unless you sign a written authorisation first:
- Marketing. Using your information to encourage you to buy a product or service, where we are paid by a third party to send that message.
- Sale of your health information. We do not sell your health information. Any disclosure in exchange for payment would require your signed authorisation stating that we will be paid.
- Psychotherapy notes. Most uses and disclosures of psychotherapy notes, where such notes exist, require your authorisation.
- Testimonials, reviews, before-and-after content and case studies. We will never publish your story, your photograph, your results or anything else identifying you — on this website, in advertising, or on social media — without a signed authorisation covering that specific use. Being our patient is itself health information. Even a first name and a photo can identify you.
You can revoke an authorisation at any time. Send your revocation in writing to our Privacy Officer using the contact details in Section 09. Revoking it stops any future use or disclosure under that authorisation. It cannot undo something we already did while the authorisation was in force.
06. Your Rights Over Your Health Information
You have the following rights. To exercise any of them, write to our Privacy Officer at the address in Section 09, or email support@aonehealthwellness.com. We will tell you if a request needs to be on a specific form and we will help you complete it.
Right to Inspect and Get a Copy
You can inspect and get a copy of the health information we use to make decisions about your care. If we hold it electronically, you can ask for an electronic copy, and you can direct us to send it to a person or organisation you name. We will act on your request within 30 days, and may extend once by a further 30 days if we tell you why in writing. We may charge a reasonable, cost-based fee for copying and postage. If we deny any part of your request, we will explain why in writing and tell you whether the denial can be reviewed. (45 CFR 164.524)
Right to Amend
If you believe something in your record is wrong or incomplete, you can ask us in writing to amend it, and tell us why. We will respond within 60 days. If we deny the request, we will explain why, and you have the right to file a written statement of disagreement that we will keep with your record. (45 CFR 164.526)
Right to an Accounting of Disclosures
You can ask for a list of the disclosures we made of your health information in the six years before your request. The list excludes disclosures for treatment, payment and operations, disclosures you authorised, and a few other categories the rule sets out. The first accounting in any 12-month period is free; we may charge a cost-based fee for additional ones, and we will tell you the cost before we proceed so you can withdraw the request. (45 CFR 164.528)
Right to Request Restrictions
You can ask us to limit how we use or disclose your information for treatment, payment or operations, or to limit what we tell a family member or friend involved in your care. We are not required to agree to most restrictions, and we will tell you if we do not. We must agree to one: if you pay for a service in full out of pocket, you can require us not to disclose that information to your health plan, except where the law requires it. (45 CFR 164.522(a))
Right to Confidential Communications
You can ask us to contact you in a particular way or at a particular place — for example, only on your mobile, never by text, or only at an address you specify. We will accommodate reasonable requests, and we will not ask you why. (45 CFR 164.522(b))
Right to a Paper Copy of This Notice
You can ask for a paper copy of this notice at any time, even if you agreed to receive it electronically. Ask any staff member, or contact the Privacy Officer, and we will give you one.
Right to Be Notified of a Breach
If your unsecured health information is breached, we will notify you. We will do so without unreasonable delay and no later than 60 days after we discover the breach, and the notice will describe what happened, what information was involved, what you can do to protect yourself, and what we are doing about it. (45 CFR 164.404)
07. How to Complain
If you believe your privacy rights have been violated, you can complain to us, to the federal government, or both.
To Us
Contact our Privacy Officer in writing using the details in Section 09. Describe what happened and when. We will investigate and respond to you.
To the Federal Government
You can file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights. You do not need to complain to us first.
Online: hhs.gov/ocr/complaints
By post: Office for Civil Rights, U.S. Department of Health and Human Services,
200 Independence Avenue SW, Washington, D.C. 20201
By phone: 1-800-368-1019 · TDD 1-800-537-7697
We will not retaliate against you for filing a complaint. Complaining will not affect your care, your access to our services, or how you are treated by anyone here.
08. Our Duties
We are required by law to:
- Maintain the privacy and security of your protected health information.
- Give you this notice of our legal duties and privacy practices.
- Follow the terms of the notice that is currently in effect.
- Notify you if a breach compromises the privacy or security of your information.
- Get your written authorisation for uses and disclosures not described in this notice.
We reserve the right to change this notice and to make the changed notice effective for health information we already hold as well as information we receive in the future. When we make a material change, we will post the revised notice on this page with a new effective date, and make paper copies available on request.
09. Privacy Officer
We have designated a Privacy Officer responsible for this notice, for our privacy practices, and for responding to your requests and complaints.
Contact Our Privacy Officer
By Phone
(947) 957-9568By Email
support@aonehealthwellness.comWritten requests and complaints: postal address to be confirmed prior to publication. Until it is published here, contact us by phone or email above and we will give you the correct address for written correspondence.
Website Privacy Policy
Part A covers the health information we hold as your clinician. This part covers something different: the data this website collects when you browse it. Website analytics data is not the same thing as your medical record, so it gets its own rules and its own disclosures.
01. What This Website Collects
When you visit https://www.aonehealthwellness.com, we and our service providers may collect:
- IP address — the network address your device connects from, which indicates your approximate location.
- Device and browser information — browser type and version, operating system, screen size, language.
- Pages viewed — which pages you opened, when, and how long you stayed.
- Referrer — the site or search that sent you here.
- Cookies and similar storage — small files stored in your browser. See Section 03.
We also collect whatever you type into a form and submit — your name, email, phone number, preferred appointment date and any message. Once you submit it to us in a care context, we treat it under Part A.
Please keep web-form messages brief. Do not type detailed symptoms or medical history into a website form. You will discuss your history privately with your clinician during your visit.
02. Third Parties That Receive Data
We name them, because a vague policy is a useless one. The following third parties can receive data about your visit to this website.
Google Analytics — Google LLC
Measures site traffic. Receives your IP address (truncated — we have IP anonymisation switched on), the pages you view, and device and browser details. We have also disabled Google Signals and ad-personalisation signals. Google does not sign a business associate agreement for Analytics, which is precisely why we do not let it run on any page where you might be submitting health information.
Chat Widget — LeadConnector / HighLevel
Powers the chat bubble. Loads from widgets.leadconnectorhq.com and receives your IP address, the page you are on, and anything you type into the chat window. Do not type medical details into the chat widget.
Booking and Intake Form Widgets
Some booking and intake forms are embedded from a third-party platform hosted at business.corunit.com. When you use one, the information you enter goes to that platform as well as to us. Where that platform handles health information on our behalf, it acts as a business associate under Part A.
We do not sell your personal information, and we do not share it with advertisers for cross-context behavioural advertising. We do not use your health information to target advertising to you.
03. Cookies
- Strictly necessary. Needed for the site to work at all — session cookies, the security token that protects forms from cross-site request forgery, and the cookie that records your cookie choice. These are always set. You cannot browse the site without them.
- Analytics. Set by Google Analytics to measure traffic. Set only if you accept them.
- Functional. Set by the chat widget to keep your conversation together between page loads. Set only if you accept them.
To change or withdraw consent: delete the aone_consent cookie
in your browser settings and reload this site — the banner will reappear and you can
choose again. You can also block or delete cookies entirely through your browser. Doing so
will not stop you using the site. Most browsers also offer a "Do Not Track" or Global
Privacy Control signal; we honour Global Privacy Control as an opt-out of sale and sharing
where state law requires it.
04. Your State Privacy Rights
These rights apply to the personal information described in this Part B. Information that is protected health information under HIPAA is generally exempt from state consumer privacy laws — but your HIPAA rights in Part A cover it, and they are stronger.
To exercise any right below, email support@aonehealthwellness.com with the subject line "Privacy Rights Request", or call (947) 957-9568. We will verify your identity before acting, respond within the time your state's law allows, and will not discriminate against you for making a request. You may use an authorised agent where your state permits it.
California — CCPA / CPRA and CMIA
If you are a California resident you have the right to:
- Know what personal information we collect, where it came from, why we collect it, and who we disclose it to.
- Delete personal information we hold about you, subject to legal exceptions — including our obligation to retain medical records.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of your personal information. We do not sell or share it, and we honour Global Privacy Control signals.
- Limit the use of sensitive personal information to what is necessary to provide the services you asked for.
Separately, California's Confidentiality of Medical Information Act (CMIA) restricts how medical information about you may be disclosed and gives you rights of access and remedies that are independent of HIPAA. Where CMIA is more protective than HIPAA, we follow CMIA.
Washington — My Health My Data Act
Washington's My Health My Data Act covers "consumer health data" — personal information linked to your past, present or future physical or mental health. It applies to health data that falls outside HIPAA, which is exactly the kind of data this Part B describes: for example, the fact that you visited our ketamine therapy or weight management page.
If you are a Washington consumer you have the right to:
- Confirm whether we collect, share or sell your consumer health data, and access it, including a list of everyone it has been shared with.
- Withdraw consent to our collection and sharing of your consumer health data.
- Delete your consumer health data from our records and from our service providers' records.
We do not sell consumer health data. Selling it would require your separate, signed authorisation, which we do not seek.
The My Health My Data Act carries a private right of action. A Washington consumer can sue directly under the state Consumer Protection Act for a violation.
Nevada — SB 370
Nevada consumers have the right to opt out of the sale of consumer health data, and to request confirmation, access and deletion of it. We do not sell consumer health data. To submit an opt-out or any other request, email us with the subject line "Nevada Health Data Request".
Colorado, Connecticut, Virginia, Texas, Oregon and Other States
If you live in a state with a comprehensive consumer privacy law — currently including Colorado, Connecticut, Virginia, Texas, Oregon, Utah, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island, among others — you generally have the right to:
- Confirm whether we process your personal data, and access it.
- Correct inaccuracies.
- Delete personal data you provided or we obtained about you.
- Obtain a portable copy of data you provided to us.
- Opt out of targeted advertising, sale of personal data, and profiling that produces legal or similarly significant effects. We do none of these.
Most of these laws also let you appeal a refusal. If we decline your request, we will tell you why and explain how to appeal, and how to contact your state attorney general if the appeal is denied. Colorado, Connecticut and several other states additionally treat health data as sensitive data requiring your consent before processing.
05. Children and Minors
Our services are intended for adults aged 18 and over. This website is not directed at children, and we do not knowingly collect personal information from anyone under 13. If you believe a child has given us personal information, contact us and we will delete it.
Some state medical programmes allow a minor patient to be treated where a parent or legal guardian consents and acts as caregiver. Where we accept such a patient, the parent or guardian exercises the rights in Part A on the minor's behalf, subject to any state law that gives a minor independent control over particular records — for example, records relating to mental health or reproductive care. State rules on this vary, and we follow the law of the state in which the patient is located.
06. How Long We Keep Data, and How We Protect It
Retention. We keep medical records for as long as state law requires, which varies by state and is generally measured in years after the last date of service, with longer periods for minors. Website analytics data is retained on a shorter schedule set in our analytics configuration. Form submissions that do not become a patient record are kept only as long as we need them to respond to you.
Security Controls We Have in Place
- Encryption in transit. This site is served over HTTPS/TLS, so data moving between your browser and our servers is encrypted.
- Access controls. Access to patient records is limited to staff who need it for their role, with individual accounts and passwords.
- Third-party scripts blocked on sensitive routes. Analytics and chat scripts are not loaded on intake or booking pages, so those vendors never see form pages.
- Written agreements with vendors. Vendors that handle health information for us are required to sign business associate agreements.
We describe controls, not certifications. "HIPAA compliant" is not a certification anyone issues, and we make no such claim. No method of transmitting or storing data over the internet is perfectly secure. We cannot guarantee absolute security, and you should not send sensitive medical details through email, chat or a website form.
07. Contact Us About Privacy
Questions about this Website Privacy Policy, or about a privacy rights request, go to the same place as questions about Part A.
Effective date: to be confirmed by counsel prior to publication. We will post any changes on this page. If a change is material, we will say so at the top of the page and update the effective date.
Questions About Your Data?
Patient Support
(947) 957-9568Privacy Officer
support@aonehealthwellness.comSee also our Terms & Conditions.
