TeleHealthNP Privacy Policy
Effective Date: September 1, 2026
Last Updated: September 1, 2026
TeleHealthNP (“we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information through our website, scheduling, healthcare services, payments, and communications. We provide care in Oregon, Washington, and Arizona.
Our technology providers include SimplePractice for electronic health records, Acuity Scheduling for appointments, Stripe for payment processing, Gmail for email, AT&T for telephone and text communications, Squarespace for our website, and Google Analytics for understanding website traffic and use.
This Policy supplements our Notice of Privacy Practices, which governs protected health information (“PHI”) under the Health Insurance Portability and Accountability Act (“HIPAA”). If this Policy conflicts with applicable law or our Notice of Privacy Practices concerning PHI, the applicable legal requirements and Notice control. Visiting our website or receiving this Policy does not, by itself, authorize uses or disclosures that require your consent or authorization.
1. Scope
This Policy covers information we collect when you visit our website, request a consultation, schedule an appointment, complete forms, receive care, make a payment, manage a subscription, communicate with us, or interact with our social media pages.
It describes our handling of information, including information processed by vendors on our behalf. Third parties may also process information independently under their own privacy notices. Their separate notices do not remove our responsibilities for information we disclose to them.
2. Information We Collect
Information you provide
Depending on your interaction, we collect identifying and contact details, such as your name, date of birth, address, email address, and telephone number; appointment and registration details; billing and transaction information; and the content of your communications and requests.
When you seek or receive care, we also collect health history, symptoms, treatment goals, medications, allergies, diagnoses, clinical assessments, treatment plans, and other information relevant to your care. This information may be entered into or maintained in SimplePractice and other systems appropriate for the activity.
Acuity processes information submitted when scheduling an appointment. Stripe processes information submitted for payments. Gmail and AT&T services process email and telephone or text communications, respectively. Information you submit through public Squarespace pages or forms may be processed by Squarespace and any connected destination for those submissions.
Please do not submit medical records, symptoms, medication details, or other health information through ordinary website contact forms. Contact us for the appropriate patient intake or record-submission method.
Information from other sources
We may receive information from healthcare providers, pharmacies, laboratories, people you authorize to act for you, and service providers supporting scheduling, payments, or practice administration, as permitted by law.
Information collected automatically
Our Squarespace website and connected services may collect IP addresses, browser and device information, referring pages, pages viewed, dates and times of visits, interaction information, and approximate location inferred from an IP address. The information collected depends on the features, cookies, and integrations enabled on the site.
Information about a person's use of a healthcare website can be sensitive even if the person has not become a patient. We evaluate the protections applicable to the information and the context in which it is collected.
3. How We Use Information
We use information, as permitted by applicable law, to evaluate service eligibility; provide and coordinate care; manage prescriptions and follow-up; maintain records; schedule appointments through Acuity; process payments and subscriptions through Stripe; respond to inquiries through Gmail, telephone, text, or designated patient communications; and operate and protect our Squarespace website and practice systems.
We also use information for customer support, accounting, fraud prevention, quality improvement, legal compliance, and resolving disputes. Uses and disclosures of PHI for treatment, payment, and healthcare operations are explained in our Notice of Privacy Practices. Other uses require consent or authorization when applicable law requires it.
We use website analytics to understand how visitors find and navigate our website, which pages they visit, and how they interact with website features. We use this information to evaluate website performance and improve its content and usability.
4. Service Providers and Technology
We use the following providers for the functions described below. Naming a provider does not mean that every feature, account type, integration, or communication method offered by that provider is appropriate for PHI. A Business Associate Agreement (“BAA”) and suitable safeguards are required when a vendor's role and the information involved require them under HIPAA.
SimplePractice — electronic health records
We use SimplePractice to maintain electronic patient records and support clinical documentation and practice administration. Information in this system may include identifying details, intake information, health history, treatment records, and clinical correspondence. Where patient portal features are offered for your care, we will provide instructions for accessing them.
Requests for access to or amendment of your medical record should be directed to TeleHealthNP, even when the record is maintained in SimplePractice.
Acuity Scheduling — appointments
We use Acuity Scheduling, a Squarespace service, to arrange appointments. Scheduling information may include your name, contact details, appointment type, and appointment date and time. Depending on the settings used, Acuity may also process scheduling forms and send reminders or confirmations.
Appointment information can itself be PHI. Use of Acuity for PHI requires its HIPAA-enabled configuration and an applicable BAA; those protections do not extend automatically to other Squarespace website features or connected services. Please provide only the information requested for scheduling and use the clinical intake method we designate for detailed medical information.
Stripe — payments and subscriptions
We use Stripe to process payments and support billing or subscription transactions. Stripe may receive contact and billing information, payment credentials, transaction amounts, purchase or subscription details, and technical information used to process transactions and prevent fraud. We may receive payment status, transaction identifiers, receipts, and limited payment-method details.
Stripe is a payment service, not our medical record system. Please do not enter medical history, diagnoses, or treatment messages into payment fields. Payment processing does not provide blanket permission to disclose clinical information; information included in transaction descriptions, receipts, or connected systems remains subject to applicable privacy requirements.
Gmail — email
We use Gmail for email communications. Information processed through email may include your email address, message content, attachments, and correspondence history.
Gmail is not described here as a verified HIPAA-configured account. Handling PHI through Google's services requires an eligible service arrangement, an applicable BAA, and appropriate configuration and use. Please contact us for a designated method to send sensitive medical information rather than sending it to an ordinary email address.
AT&T — telephone and text communications
We use AT&T telecommunications services for telephone and text communications. These communications may involve telephone numbers, call or message metadata, and message content, depending on the service used.
Ordinary text messaging is not the same as a secure patient portal. Messages can be visible on shared devices, lock screens, backups, or connected services. Please avoid sending detailed medical information, photographs, or records by ordinary text and ask us for an appropriate method for clinical communications.
Squarespace — public website
We use Squarespace to host and operate our public website. Squarespace may process website usage information, cookies, and information submitted through website features. Standard Squarespace website forms are not a designated channel for collecting PHI. Our use of Acuity for scheduling does not make the rest of the Squarespace website a HIPAA clinical platform.
Please use our designated scheduling and clinical intake methods for those purposes. Do not enter payment-card details in general website contact forms or send them by ordinary email or text.
Google Analytics — website traffic analysis
We use Google Analytics to understand website traffic and visitor interactions. Depending on configuration and consent choices, information processed may include page addresses and titles, referring webpages, interaction events, browser and device information, and online identifiers. Google processes information in connection with this service.
Interactions with pages describing particular healthcare services or treatments may reveal health-related interests when linked or reasonably linkable to an individual. Google Analytics is separate from our use of Gmail for email communications. Cookie choices are described in Section 7.
Other providers and integrations
We may also use healthcare partners and vendors supporting pharmacy services, laboratories, information technology, professional services, and practice operations. Disclosures remain subject to applicable law and any required contractual protections. Connecting two services does not automatically extend one service's protections to the other.
5. Email, Text Messages, and Communication Choices
We may communicate about appointments, billing, account administration, service requests, and care using the contact methods appropriate to the communication and permitted by law. Email and text reminders may reveal your association with TeleHealthNP even when they contain no diagnosis or treatment details.
You may ask us to contact you by an alternative method or at an alternative location. We will accommodate reasonable confidential-communication requests as required by law. Tell us if your contact details change or if others have access to your phone, email, or voicemail.
Where applicable, we obtain required consent for messages. Message frequency varies, and carrier message and data rates may apply. To request that we stop texting you, contact us or reply with an opt-out request. If an automated messaging program provides STOP instructions, follow those instructions. Contact us directly if you need help confirming your preference.
Choosing email or text does not waive your privacy rights or our legal obligations. Where you request an unencrypted communication that the law permits, we may explain the risks and confirm your preference. We may use an alternative method when necessary to meet legal or security requirements.
Email, text, website forms, and portal messages are not emergency services. For an emergency, call 911.
6. Newsletters and Marketing
Where permitted by law and with any required consent, we may send educational content, practice news, service information, or promotional communications. You may unsubscribe using the instructions in a marketing email or by contacting us. You may also contact us to withdraw consent to marketing texts.
An inquiry, appointment, or purchase does not automatically constitute consent to every type of marketing. We obtain any authorization required for marketing involving PHI. Opting out of marketing does not prevent necessary care, billing, or administrative communications through a permitted method.
7. Cookies, Analytics, and Advertising
Our Squarespace website uses cookies and similar technologies for website functionality, security, preferences, and analytics. We use Google Analytics to understand website traffic and improve website content and usability. Depending on configuration and consent choices, analytics information may include pages visited, referring webpages, website interactions, browser and device information, and online identifiers.
Our website provides controls to accept, decline, or manage certain non-essential cookies. You can also adjust your browser’s cookie settings. Restricting cookies may affect some website features, and cookie controls do not necessarily prevent every form of technical data collection.
Information associated with visits to healthcare or treatment pages may reveal health-related interests when linked or reasonably linkable to an individual. Cookie consent does not replace a separate consumer health data consent or HIPAA authorization when either is required by applicable law.
8. How We Disclose Information
We disclose information to service providers such as SimplePractice, Acuity, Stripe, Google, AT&T, and Squarespace for the functions described above, subject to the requirements applicable to the information and each recipient's role. We also disclose information to healthcare professionals, pharmacies, laboratories, and authorized representatives as permitted for treatment or other lawful purposes.
We may disclose information to comply with legal obligations or valid legal process, respond to authorized oversight, address fraud or security incidents, or protect health and safety when legally permitted. A request from law enforcement, a subpoena, or a business need does not by itself override protections for health information.
Information may be transferred in a permitted business reorganization, merger, acquisition, or practice transition, subject to applicable confidentiality requirements. Other disclosures occur with your consent or authorization when required.
We do not sell personal information or consumer health data and do not disclose it for third-party targeted advertising. We do not share mobile numbers or messaging consent with third parties for their own marketing.
9. PHI and Your HIPAA Rights
Our Notice of Privacy Practices describes our responsibilities and your rights concerning PHI. Subject to applicable requirements and exceptions, these include rights to inspect or obtain copies of records; request an amendment; request confidential communications; request certain restrictions; receive an accounting of certain disclosures; obtain a paper copy of the Notice; and complain without retaliation.
Some requested restrictions need not be accepted, while others are required by law. HIPAA does not provide a general right to erase your medical record. Withdrawing an authorization generally does not undo actions already taken in reliance on it.
To exercise your rights, contact the privacy contact listed below. We may verify your identity and authority using information appropriate to the request and respond within applicable legal timeframes.
Notice of Privacy Practices: telehealthnp.net/notice-of-privacy-practices
10. Oregon, Washington, and Arizona
We are committed to meeting the federal and state privacy, confidentiality, security, and breach-notification requirements applicable to our activities, including HIPAA where applicable and relevant requirements in Oregon, Washington, and Arizona. Additional protections may apply to particular types of records. Nothing in this Policy limits rights provided by applicable law.
Oregon
Oregon law protects health information and patient access to records. Where the Oregon Consumer Privacy Act applies to particular non-exempt information and our processing, additional rights may include access, correction, deletion, portability, certain opt-outs, and an appeal of a denied request. Applicability depends on the law's coverage requirements and exemptions; website information should not automatically be treated as exempt merely because a healthcare practice collects it.
Washington
Washington's health-record confidentiality laws and, where applicable, the My Health My Data Act provide additional protections. Information outside HIPAA can qualify as consumer health data. The My Health My Data Act includes exemptions for specified information, including qualifying PHI; being a healthcare provider does not by itself exempt every category of information we handle.
Where that Act applies, consumers may have rights to confirm collection, access data, obtain information about sharing, withdraw consent, and request deletion, with the scope and exceptions established by law. Covered consumers can include certain nonresidents whose consumer health data is collected in Washington.
Requests and appeals may be submitted to our privacy contact. If we deny an applicable request, we will explain how to appeal. Consumers may also contact the Washington Attorney General. Additional details must appear in the separate Washington Consumer Health Data Privacy Policy when applicable.
Washington Consumer Health Data Privacy Policy: telehealthnp.net/washington-consumer-health-data
Arizona
Arizona law protects the confidentiality of medical and payment records and provides rights concerning records, subject to legal requirements and exceptions. We apply the requirements governing the particular information and disclosure, including additional protections when applicable.
11. Information Security and Breach Notification
We use safeguards designed to protect personal and health information and restrict access to authorized purposes. Safeguards must be appropriate to the information, systems, and risks involved. No internet transmission or electronic storage system can be guaranteed completely secure.
If an incident triggers notification duties, we will notify affected individuals, regulators, and others as required by applicable federal and state law. The use of an outside provider does not eliminate our own legal responsibilities.
12. Retention and Deletion
We retain information for the periods needed to provide services, maintain required clinical and business records, comply with law, and address legitimate legal or operational needs. Relevant considerations include the type of record, applicable retention requirements, ongoing care, and legal holds.
Closing an account, canceling a subscription, unsubscribing, or requesting deletion does not necessarily require deletion of records we must lawfully retain. Deletion requests are evaluated under the law that applies to the information; mandatory deletion rights are not overridden by a general business preference to retain data.
Information may remain in provider systems or backups under applicable retention and deletion requirements. When appropriate, information is securely deleted, destroyed, or de-identified. Aggregation alone does not establish that health information meets HIPAA's de-identification requirements.
13. Children and Representatives
Our public website is not intended to solicit personal information from children under 18. If you believe a child has submitted information improperly, contact us. Where we lawfully provide care to a minor, we handle records and representative access according to applicable consent and confidentiality laws. A parent's or guardian's access may depend on the type of care and the law that applies.
14. Third-Party Sites and Social Media
Our website may link to scheduling pages, payment services, pharmacies, laboratories, social media platforms, and other external resources. Their independent activities are governed by their own privacy notices. We remain responsible for disclosures we make under applicable law.
Avoid posting medical information in public comments or social media messages. Public posts may be accessible to others. We obtain any required authorization before using identifiable patient information in testimonials or other public communications.
15. Changes to This Policy
We may update this Policy to reflect changes in our practices, services, or legal requirements. We will post the revised version with its updated date and provide additional notice or obtain consent when required. A policy update does not retroactively authorize a use or disclosure that requires separate permission.
16. Contact and Complaints
TeleHealthNP
Legal entity name: TeleHealthNP, LLC
Privacy contact or officer: Debra Johnson
Mailing address: 4910 SE 138th Ave, Portland, OR 97236
Telephone: (602) 810-0868
Privacy email: telehealthnp@telehealthnp.net
Contact us with questions, privacy requests, communication preferences, or complaints. Please do not include detailed medical information in an initial ordinary email; we can arrange an appropriate method for exchanging records or verifying identity.
You may also file a HIPAA complaint with the U.S. Department of Health and Human Services Office for Civil Rights at https://www.hhs.gov/hipaa/filing-a-complaint/ or contact the appropriate state regulator. We will not retaliate against you for exercising privacy rights or filing a complaint.
17. Related Notices
Notice of Privacy Practices: telehealthnp.net/notice-of-privacy-practices
Washington Consumer Health Data Privacy Policy: telehealthnp.net/washington-consumer-health-data
Terms of Service: telehealthnp.net/terms-of-service