Privacy Policy
Privacy Policy
Last Updated: [8/9/2026]
Section 1: Introductory Statement
This Privacy Policy explains how Kelton Komprehensive (“we,” “us,” or “our clinic”) collects, uses, and safeguards your information in compliance with the Health Insurance Portability and Accountability Act (HIPAA), the Oklahoma Healthcare Information Security Act (75 O.S. § 7003), and applicable state privacy laws including the California Consumer Privacy Act (CCPA/CPRA), Virginia Consumer Data Protection Act (VCDPA), and Colorado Privacy Act (CPA). We take your privacy and medical data security extremely seriously. If you have questions about this policy, contact us at [INSERT EMAIL] or [INSERT PHONE].
Section 2: Information We Collect
Clinical Information
When you consult with or receive treatment from our clinic, we may collect: legal name, date of birth, and contact information; medical history, diagnoses, and current medications; known allergies and adverse reactions; previous treatments and surgical history; imaging results (MRI, X-ray, ultrasound); health goals and treatment preferences; insurance information; and payment information.
Website Information
When you visit our website, we may collect: IP address and general geographic location; browser type and operating system; pages visited and time spent; contact form submissions; and quiz or assessment responses.
What We Do NOT Collect
- Cookies for targeted advertising or cross-site tracking
- Biometric data without explicit written consent
- Social media profile data
- Data from third-party data brokers
Section 3: How We Use Your Information
We use your information solely for the following purposes:
- Providing medical consultation and treatment
- Pre-treatment medical evaluation and safety screening
- Coordination with other healthcare providers (with your written authorization)
- Post-treatment outcome tracking and follow-up
- Billing and insurance claims processing
- Appointment scheduling and administrative purposes
- Compliance with legal and regulatory requirements
- Website analytics and performance optimization (aggregate, non-identifiable data only)
We DO NOT: use your information for marketing without your explicit consent; share your information with third parties for marketing purposes; sell, lease, or trade your personal or health data; or use your information for any purpose unrelated to your care.
Section 4: HIPAA Compliance (Federal)
Our clinic is a HIPAA-covered entity. Your Protected Health Information (PHI) — including medical history, diagnoses, treatment plans, imaging results, medications, and insurance information — is protected by federal law under the Health Insurance Portability and Accountability Act of 1996 and the HITECH Act of 2009.
Your HIPAA Rights
- Right to Access: Request a copy of your medical records. We respond within 30 days.
- Right to Amend: Request correction of inaccurate or incomplete records.
- Right to an Accounting of Disclosures: Request a log of who has accessed or received your records.
- Right to Confidential Communications: Request that we contact you by specific means or at a specific location.
- Right to Restrict Use: Request restrictions on how we use or disclose your PHI. We honor all reasonable requests.
- Right to Breach Notification: We notify you within 60 days if your unsecured PHI is breached.
How We Protect Your Information
- HIPAA-compliant EHR with AES-256 encryption at rest and TLS encryption in transit
- Access restricted to authorized staff on a strict need-to-know basis
- All staff sign HIPAA compliance and confidentiality agreements
- Audit logs track all access to patient records
- Physical records stored in locked, access-controlled facilities
- Annual security audits and mandatory employee HIPAA training
- Business Associate Agreements (BAAs) executed with all vendors who access PHI
File a HIPAA Complaint
U.S. Department of Health and Human Services, Office for Civil Rights
200 Independence Avenue, S.W., Washington, D.C. 20201
Phone: 1-877-696-6775
https://www.hhs.gov/hipaa/filing-a-complaint/index.html
Section 5: Oklahoma & State Privacy Laws
Oklahoma Residents
Oklahoma patients are protected under HIPAA (Section 4) AND the Oklahoma Healthcare Information Security Act (75 O.S. § 7003), which requires: secure storage and transmission of health information; limited and controlled access to patient information; documented data security incident response procedures; and regular security assessments. The Oklahoma Breach Notification Law (75 O.S. § 7001) requires notification within a reasonable timeframe consistent with HIPAA’s 60-day requirement.
Your Oklahoma Rights: Access, amend, and restrict your medical records; know who has accessed your records; request confidential communications; and file complaints with Oklahoma regulators.
File an Oklahoma Complaint: Oklahoma State Department of Health, Office of Licensing & Regulation, 1000 NE 10th Street, Oklahoma City, OK 73117-1299. Phone: (405) 271-6868 | https://www.ok.gov/health/
California Residents (CCPA/CPRA)
California residents have the right to know what data we collect and how we use it; delete personal information (subject to legal exceptions); correct inaccurate data; opt-out of sale or sharing (we do not sell your data); and non-discrimination for exercising rights. Contact us at [INSERT EMAIL] or [INSERT PHONE]. We respond within 45 days.
Virginia, Colorado, Connecticut, and Other States
Residents of states with comprehensive privacy laws (VCDPA, CPA, CTDPA) have similar rights to access, delete, correct, and opt-out. Contact us at [INSERT EMAIL] or [INSERT PHONE] to exercise your rights. We respond within 45 days.
Section 6: Data Sharing
We share your information ONLY for: Treatment (with providers you authorize in writing); Payment (with insurers, minimum necessary); Healthcare Operations (billing, records, quality improvement staff); Legal Compliance (law enforcement, courts, public health — we notify you unless prohibited); and Safety (imminent threat to you or others).
We DO NOT share for: Marketing without explicit written consent; research without explicit opt-in consent; or sale, lease, or transfer to third parties for any commercial purpose.
Business Associates: All service providers with PHI access (EHR vendors, billing, IT) sign Business Associate Agreements (BAAs) and are legally bound to protect your data under HIPAA.
Section 7: Data Security
Technical: HTTPS/TLS in transit, AES-256 at rest, firewalls, intrusion detection, regular security updates, multi-factor authentication, encrypted redundant backups.
Physical: Restricted facility access, secure document disposal (cross-cut shredding), locked medical record storage, workstation privacy screens.
Administrative: Annual mandatory HIPAA and cybersecurity training, role-based access controls, background checks, documented incident response plan, regular internal and third-party security audits, cybersecurity insurance.
Limitation: No system is 100% secure. In the event of a breach, we respond per HIPAA and Oklahoma law (see Section 8).
Section 8: Breach Notification
If your unsecured PHI is breached, we notify you within 60 days via email, phone, or mail with: what information was involved; breach and discovery dates; protective steps you can take; our investigation and mitigation response; and contact information for questions. If 500 or more state residents are affected, we notify prominent media outlets. HHS and Oklahoma regulators are notified as required by law.
Section 9: Cookies & Website Tracking
We use: Google Analytics (website optimization only, not marketing — opt-out: https://tools.google.com/dlpage/gaoptout) and essential cookies (session management, basic functionality).
We DO NOT use: Targeted advertising, retargeting, third-party tracking, social media pixels, or email open tracking. You may disable cookies in your browser settings; disabling essential cookies may affect site functionality.
Section 10: Children’s Privacy
We do not knowingly collect information from individuals under 18 without verifiable parental consent. If we discover we have, we delete it immediately. Contact us at [INSERT EMAIL] or [INSERT PHONE] if you believe your child provided information to us.
Section 11: Third-Party Links
Our website may link to third-party websites (PubMed, FDA.gov, and other references). We are not responsible for their privacy practices. Review their policies before providing personal information.
Section 12: International Users
Our clinic is located in the United States. Information from outside the US will be transferred to and stored in the United States. By using our services, you consent to this transfer. US data protection laws may differ from those in your country.
Section 13: Your Rights — Summary
| Right | How to Exercise |
|---|---|
| Access your records | Contact [INSERT EMAIL] or [INSERT PHONE]; submit written request |
| Amend inaccurate records | Contact [INSERT EMAIL] or [INSERT PHONE]; provide corrections in writing |
| Know who accessed your records | Contact [INSERT EMAIL] or [INSERT PHONE]; submit written request |
| Request confidential communications | Contact [INSERT EMAIL] or [INSERT PHONE] |
| Restrict use of your information | Contact [INSERT EMAIL] or [INSERT PHONE]; submit written request |
| Opt-out of marketing | Unsubscribe in emails or contact [INSERT EMAIL] or [INSERT PHONE] |
| Delete personal data (CCPA/state law) | Contact [INSERT EMAIL] or [INSERT PHONE]; subject to legal exceptions |
| File a complaint | Contact us, Oklahoma Dept. of Health (405) 271-6868, or HHS OCR 1-877-696-6775 |
Section 14: Contact Information
Kelton Komprehensive — Privacy Officer
Email: [INSERT PRIVACY EMAIL]
Phone: [INSERT PHONE]
Address: [INSERT CLINIC ADDRESS]
Response Time: 30 days (we will notify you if additional time is required)
Oklahoma Regulator: Oklahoma State Department of Health, Office of Licensing & Regulation, 1000 NE 10th Street, Oklahoma City, OK 73117-1299. Phone: (405) 271-6868 | https://www.ok.gov/health/
Federal HIPAA Complaint: U.S. Department of Health and Human Services, Office for Civil Rights, 200 Independence Avenue, S.W., Washington, D.C. 20201. Phone: 1-877-696-6775 | https://www.hhs.gov/hipaa/filing-a-complaint/index.html
Section 15: Policy Updates
We may update this Privacy Policy periodically. Material changes will be communicated via email to patients of record and via prominent website notice, with an updated “Last Updated” date at the top of this page. Continued use of our services following notice of material changes constitutes acceptance of the updated policy.
Section 16: Severability
If any provision of this Privacy Policy is found invalid, illegal, or unenforceable by a court of competent jurisdiction, that provision shall be severed. All remaining provisions shall continue in full force and effect and shall be construed to give maximum effect to the intent of the parties.