Privacy Policy
Effective date: September 23, 2026
Last updated: September 23, 2026
How This Policy Relates to HIPAA
As a health care provider, Renovo Orthopedic & Spine is a covered entity under the Health Insurance Portability and Accountability Act (HIPAA). Information that identifies you and relates to your health, your care, or payment for your care is "Protected Health Information" (PHI). How we use and disclose PHI, and your rights over it, are described in our Notice of Privacy Practices.
This Privacy Policy explains our practices for our website and online services, including information that is not PHI. Where this policy and the Notice of Privacy Practices both apply to PHI, the Notice of Privacy Practices controls.
The Short Version
- Your health information is protected by HIPAA. Our Notice of Privacy Practices controls how we use and share it.
- We don't sell your information. Not your health information, and not your website activity.
- No ad tracking where it matters. We don't run advertising pixels on our patient portal, appointment requests, or bill pay.
- You have choices. Opt out of marketing texts and emails, manage cookies, and ask us to access or delete your information.
Who This Policy Covers
This policy applies to [renovoortho.com] and any other website, patient portal, online form, or mobile application that links to it (together, the "Services"). The Services are operated by [Legal entity name, e.g., Renovo Orthopedic & Spine, PLLC] and its affiliated practices and locations ("Renovo," "we," "us," or "our").
This policy does not cover information you share with us in person, by phone, or in paper form during your care. That information is governed by our Notice of Privacy Practices.
Information We Collect
Information You Give Us
Depending on how you use the Services, you may give us:
- Contact details, such as your name, email address, phone number, mailing address, and date of birth.
- Appointment and intake information, such as the reason for your visit, your symptoms, the body area affected, prior treatment or imaging, your referring provider, and your insurance details.
- Account credentials for our patient portal.
- Payment information when you pay a bill online. Card details are collected directly by our payment processor; we do not store full card numbers.
- Messages you send through contact forms, live chat, or email.
- Job application materials, if you apply for a position with us.
Please do not include detailed medical information in general contact forms or email. Use the patient portal or call us for anything related to your care.
Information Collected Automatically
When you use the Services, we and our service providers may automatically collect your IP address, browser and device type, operating system, referring website, pages viewed, time spent on pages, and approximate location derived from your IP address. The Cookies and Tracking Technologies section below explains how we limit this collection on pages that relate to your care.
Information From Other Sources
If you are a patient, we may receive information about you from referring physicians, other providers involved in your care, imaging centers, laboratories, pharmacies, health information exchanges, and your health plan. This information is PHI and is handled under our Notice of Privacy Practices.
How We Use Information
We use information to:
- Schedule appointments, confirm insurance, and provide and coordinate your care.
- Respond to your questions and requests.
- Process payments and manage billing.
- Send appointment reminders, pre-visit instructions, and other messages about your care.
- Send newsletters or information about our services, if you have signed up to receive them.
- Operate, secure, troubleshoot, and improve the Services.
- Understand how visitors use our general website pages, in aggregate.
- Review job applications.
- Meet our legal, regulatory, and accreditation obligations, and protect the rights and safety of our patients, staff, and others.
We do not use PHI for marketing without your written authorization, except as HIPAA permits (for example, face-to-face communications or information about treatments related to your own care).
Cookies and Tracking Technologies
Cookies are small files stored by your browser. Similar technologies include pixels, tags, scripts, and software development kits (SDKs). We use them to keep the Services working, remember your preferences, and understand how our website is used.
Where We Limit Tracking
Information about your visit can reveal something about your health, even if you never type in a diagnosis. For that reason, we do not use third-party advertising or social media tracking technologies on:
- Our patient portal or any page that requires you to log in.
- Appointment request and scheduling pages.
- Online bill pay.
- Intake, symptom, or new-patient forms.
Any vendor that receives PHI through the Services does so under a HIPAA business associate agreement that limits how it may use that information.
Types of Cookies We Use
Essential cookies keep the site secure, remember your cookie choices, and keep forms and logins working. They cannot be turned off through our settings, but you can block them in your browser. Some features will stop working if you do.
Analytics cookies count visits and show which general pages are useful, using [analytics tool name]. They are configured to exclude the pages listed above. You can turn them off through our cookie settings or your browser.
Advertising cookies measure the performance of our ads on general, informational pages only. You can turn them off through our cookie settings, your browser, or Global Privacy Control.
You can change your preferences at any time through our [Cookie settings link].
Global Privacy Control and Do Not Track
We honor the Global Privacy Control (GPC) signal. If your browser sends it, we treat it as a request to opt out of advertising cookies for that browser. Browsers' "Do Not Track" setting has no common standard, so we do not respond to it separately; GPC is the better option.
How We Share Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not share PHI with third parties for their own marketing.
We share information only in these situations:
- Service providers. Companies that host our website, run our patient portal, electronic health record, scheduling, payment processing, reminders, secure messaging, telehealth, IT, and security. They may use information only to provide services to us. Those that handle PHI sign business associate agreements.
- Your care team. Other providers, facilities, and health plans involved in your treatment or payment, as described in our Notice of Privacy Practices.
- Affiliated practices. Our affiliated practices and locations, for the purposes described in this policy.
- Legal and safety reasons. To comply with law, a court order, or a valid legal process; to respond to public health or oversight authorities as the law requires or permits; or to protect the rights, property, and safety of our patients, staff, or others.
- Business changes. In connection with a merger, acquisition, or sale of all or part of our practice, subject to HIPAA and applicable law.
- With your permission. For any other purpose you authorize.
Online Reviews and Public Posts
If you post a review or comment about us on a public site, that content is visible to others and governed by that site's policies. To protect your privacy, we will not confirm that you are a patient or discuss your care in any public response.
Texts, Calls, and Email
If you give us your mobile number, we may send text messages about appointments, pre-visit instructions, billing, and your care. Message frequency varies. Message and data rates may apply. Reply STOP to stop receiving texts, or HELP for help.
We send marketing texts only if you have given us separate consent, and that consent is never a condition of receiving care. Mobile numbers and text-messaging consent are not shared with third parties or affiliates for their marketing purposes.
You can unsubscribe from marketing emails using the link in any message. You will still receive messages about your appointments and care.
Patient Portal, Telehealth, and Online Payments
Our patient portal is provided by [Portal vendor] on our behalf. Information in the portal is PHI and is protected under HIPAA and our Notice of Privacy Practices. The portal vendor may have additional terms that you accept when you create your account.
Telehealth visits are conducted on [Telehealth platform], a platform that has signed a business associate agreement with us. We do not record telehealth visits unless we tell you in advance and you agree.
Online payments are processed by [Payment processor], which follows the Payment Card Industry Data Security Standard (PCI DSS).
How We Protect Information
We use administrative, technical, and physical safeguards required by the HIPAA Security Rule to protect PHI, and we apply reasonable safeguards to other information. These include encryption of data in transit, access controls, staff training, and vendor oversight.
No website, network, or storage system is completely secure. If a breach of your unsecured PHI occurs, we will notify you as HIPAA and state law require.
Keep your portal password private and log out when using a shared device.
How Long We Keep Information
We keep medical records for the period required by [State] law and professional standards. We keep other information, such as website inquiries, only as long as needed for the purpose it was collected, to meet legal obligations, or to resolve disputes. Analytics data is retained for [retention period, e.g., 14 months].
Your Choices and Rights
Rights Over Your Health Information
Under HIPAA, you have the right to see and get a copy of your medical records, ask us to correct them, request limits on how we share them, request confidential communications, get a list of certain disclosures, and file a complaint. Our Notice of Privacy Practices explains how.
Other Information
For information that is not PHI, such as newsletter sign-ups or general website inquiries, you may ask us to access, correct, or delete it. We will honor your request unless the law requires or permits us to keep it. Deleting information does not remove it from your medical record, which we must keep by law.
How to Make a Request
Email [privacy@renovoortho.com], call [Privacy Officer phone], or write to the address listed under Contact Us below. We will verify your identity before acting on a request, and we will not discriminate against you for exercising your rights. An authorized agent may submit a request on your behalf with proof of authorization.
State Privacy Rights
Some states give residents additional rights over personal information that is not covered by HIPAA. Depending on where you live, these may include the right to know what we collect, to access, correct, or delete it, to opt out of targeted advertising, and to appeal a decision about your request.
Some states, including Washington, Nevada, and Connecticut, have specific laws for "consumer health data" collected outside of HIPAA. We do not sell consumer health data, and we do not collect or share it for purposes other than those described in this policy without your consent.
To make a request, use the contact information under How to Make a Request above. If we deny your request, you may appeal by replying to our decision. If you are not satisfied with the outcome of an appeal, you may contact your state attorney general.
Children and Minors
Our website is intended for adults. We do not knowingly collect personal information online from children under 13. If you believe a child has sent us information through the website, contact us and we will delete it.
We do treat pediatric and adolescent patients. A parent or legal guardian generally manages a minor's records and portal access, subject to state law on minors' rights to consent to and control certain care.
Third-Party Sites and Embedded Content
The Services may link to other websites, such as insurers, hospitals, or social media pages, and may include embedded content such as maps or videos. We do not control those services, and this policy does not apply to them. Review their privacy policies before sharing information with them.
Changes to This Policy
We may update this policy as our practices or the law change. We will post the updated version here and change the "Last updated" date. If we make a material change to how we use personal information, we will give notice on our website before the change takes effect and, where the law requires, ask for your consent.
Contact Us
For questions about this policy or our privacy practices, or to file a privacy complaint, contact our Privacy Officer.
Email: PatientFollowUp@RenovoOrthoSpine.com
Phone: (440) 96-ORTHO (67846)
You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr/complaints. We will not retaliate against you for filing a complaint.