Privacy Policy
Effective date: [[Insert date]]
Applies to: vivamedicalcenter.com and vivacenters.com (each a “Site,” collectively, the “Sites”), the Viva Medical Center patient portal and any related online services we operate (together, the “Services”).
Who we are: 10560NW 27Th ST Unit 101 Doral Florida 33172 (“Viva Medical,” “we,” “us,” or “our”).
Contact:
Email: privacy@vivamedicalcenter.com (or your preferred address)
- Phone: 305 209 0001
Important healthcare notice: This Privacy Policy covers information collected via our Sites and Services. If you are a patient, certain information we collect and maintain is Protected Health Information (PHI) governed by the Health Insurance Portability and Accountability Act (HIPAA). Where HIPAA applies, our use and disclosure of PHI is governed by our HIPAA Notice of Privacy Practices, not this website Privacy Policy. We will link or provide that Notice wherever PHI is collected.
1) Information We Collect
We collect information in the following categories:
A. You provide to us
- Account, profile, and contact details (name, email, phone, postal address, date of birth).
- Appointment requests, intake forms, messages, and files you submit.
- Billing and payment information (billing address, partial card details handled by our PCI-compliant processor; we do not store full card numbers).
- Communication preferences and consents (email/SMS opt-ins).
B. Automatically collected
- Device and usage data (IP address, browser type, pages viewed, referring/exit pages, timestamps).
- Cookies and similar technologies (pixels, SDKs) for session management, analytics, and preferences. See Cookies & Tracking below.
C. From third parties
- Patient portal vendors, payment processors, EHR systems, appointment and messaging platforms.
- Marketing/analytics partners and advertising networks.
- If enabled, social sign-on providers.
PHI obtained or created for treatment, payment, or healthcare operations is handled under HIPAA and our Business Associate Agreements with vendors.
2) How We Use Information
We use information to:
- Provide and improve the Sites and Services, including scheduling, reminders, patient communications, and support.
- Operate our patient portal and secure messaging.
- Process payments and manage billing.
- Send transactional communications (e.g., appointment confirmations, lab/result availability, prescription readiness, billing notices).
- With consent where required, send informational or educational messages about our services (no third‑party advertising of products we don’t offer).
- Detect, prevent, and respond to security incidents and abuse.
- Comply with legal obligations and enforce our terms.
Where required by law (e.g., the EU/UK), we rely on these legal bases: performance of a contract; legitimate interests (website operations, fraud prevention, basic analytics); consent (emails/SMS where required, cookies beyond strictly necessary); and compliance with legal obligations.
3) Email Marketing & Transactional Emails — Opt‑In/Opt‑Out Rules
3.1 Types of email we send
- Transactional/relationship emails: account creation, appointment confirmations, forms, portal invitations, results availability notices, and billing communications. These are sent to fulfill your requests or our Services and do not require marketing consent.
- Marketing or educational emails (optional): newsletters, updates about new services, wellness tips, events. These require your opt‑in consent where required by law.
3.2 Obtaining consent
- We collect your marketing email consent during signup, online forms, or in‑clinic registration via a clear checkbox or affirmative action that is not pre‑ticked.
- We record the date/time, source, and method of consent.
3.3 Managing preferences
- Every marketing email includes an Unsubscribe link that lets you opt out of marketing emails at any time.
- You can also email us at privacy@vivamedicalcenter.com with the subject “Unsubscribe.” We process opt‑out requests within 10 business days.
- Opting out of marketing emails does not affect transactional or legally required emails (e.g., appointment reminders, portal alerts, or billing notices). To stop most transactional emails you may need to deactivate your account or change portal notification settings where available.
3.4 Re‑subscribing
- If you unsubscribe, you may re‑subscribe by providing new consent (e.g., submitting a form with the marketing checkbox checked).
4) Text Messaging (SMS/MMS) — Consent & Opt‑Out
4.1 Content of texts
- We send care‑related, non‑marketing texts such as appointment reminders, pre‑visit instructions, lab/result availability notices, prescription notifications, and billing updates. We avoid including detailed medical information in SMS.
4.2 Opt‑in methods
- On‑page consent: you check a box at signup or registration agreeing to receive texts.
- Double opt‑in (recommended): after signup, we send a message asking you to reply Y/YES to confirm. We record confirmation details.
4.3 Frequency & charges
- Message frequency varies by activity (generally up to [[insert typical range, e.g., 8 msgs/month]]). Message and data rates may apply.
4.4 Commands
- STOP: Reply STOP to end all non‑emergency texts from us. You may receive a final confirmation message.
- HELP: Reply HELP for help. You may also contact us at [[insert phone]] or privacy@vivamedicalcenter.com.
- START/UNSTOP: If available with your carrier, send START to re‑subscribe, or contact us to re‑opt‑in.
4.5 Consent records & revocation
- We maintain opt‑in/opt‑out records as required by applicable carrier and communications guidelines. Revoking consent does not affect texts we are legally permitted or required to send (e.g., critical notices) but we strive to limit sensitive content in SMS.
5) Cookies & Tracking Technologies
5.1 Types
- Strictly necessary: site security, session management, load balancing.
- Functional: remember preferences (e.g., language, location).
- Analytics: measure site usage and performance (e.g., Google Analytics or similar).
- Advertising (optional/off by default): if enabled, used to deliver or measure ads; we do not share PHI for advertising.
5.2 Choices
- Use the cookie banner or your browser settings to manage cookies. Some features may not function without certain cookies. Where required, we request consent for non‑essential cookies.
6) Sharing of Information
We may share information with:
- Service providers/Processors: hosting, EHR/portal vendors, messaging platforms, analytics, payment processors, and support tools under appropriate contracts and, where applicable, Business Associate Agreements.
- Affiliates and providers involved in delivering your care.
- Legal and compliance recipients where required by law, to protect rights and safety, or in connection with a merger/sale.
- We do not sell your personal information or share it for cross‑context behavioral advertising where prohibited by law. If our practices change, we will update this policy and provide required notices.
7) Data Retention
We retain information for as long as needed to provide the Services, comply with legal/recordkeeping obligations (including medical record retention laws), resolve disputes, and enforce agreements. Retention periods vary by data type and legal requirements.
8) Security
We use administrative, technical, and physical safeguards appropriate to the nature of the information we process. No system is 100% secure. If we learn of a security incident affecting your information, we will notify you and/or authorities as required by law.
9) Children’s Privacy
Our Sites are not directed to children under 13. We do not knowingly collect personal information from children under 13 without appropriate parental/guardian consent. If you believe a child has provided us information, contact us to request deletion. (For patients, pediatric PHI is handled under HIPAA and state law.)
10) Your Privacy Rights
Your rights depend on your location. Subject to applicable laws and exceptions, you may have the right to:
- Access, correct, or delete personal information we hold about you.
- Object to or restrict certain processing, and withdraw consent.
- Receive a portable copy of certain information.
- Opt out of marketing communications and certain tracking.
How to exercise your rights: Email privacy@vivamedicalcenter.com or use available self‑service tools. We may verify your identity and request details necessary to process your request.
California residents (CCPA/CPRA): You may have rights to know, delete, correct, and opt out of sales/sharing of personal information, and to limit use of sensitive personal information. We do not sell personal information. We honor opt‑out preference signals where required. You will not be discriminated against for exercising your rights. See our California Notice at Collection if applicable.
EEA/UK/Swiss residents: We are a controller for personal data collected via the Sites. You may contact our EU/UK representatives (if designated) and your supervisory authority to lodge a complaint. For transfers to the U.S., we rely on appropriate safeguards (e.g., Standard Contractual Clauses) and supplementary measures.
11) International Data Transfers
If you access the Sites from outside the United States, your information may be processed in the U.S. or other countries that may not provide the same level of data protection. We implement appropriate safeguards for cross‑border transfers where required.
12) Third‑Party Links and Services
Our Sites may link to third‑party websites or include integrations (e.g., maps, forms, payment). We are not responsible for the privacy practices of those third parties. Review their policies before providing information.
13) Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with a new Effective date. If we make material changes, we will provide additional notice as required by law.
14) How to Contact Us
Questions or requests about this Policy or our privacy practices:
- Email: privacy@vivamedicalcenter.com
- Mail: 10560 Nw 27Th St Doral Florida 33172
- Phone: [[Insert phone]]
Appendix A — Communication Disclosures (Sample Notices)
Email footer (marketing):
“You’re receiving this because you opted in at vivamedicalcenter.com/vivacenters.com or in‑clinic. To unsubscribe, click here or email privacy@vivamedicalcenter.com. We respect your privacy and do not sell your information.”
SMS invitation (double opt‑in):
“Viva Medical: Reply YES to get SMS reminders & updates for your account. Up to 305 209 0001 msgs/mo. Msg&data rates may apply. HELP for help, STOP to cancel.”
SMS confirmation:
“You’re subscribed to Viva Medical texts (care‑related updates only). HELP for help, STOP to opt out.”
STOP confirmation:
“You’re opted out of Viva Medical texts. Reply START to re‑subscribe.”
Disclaimer (Not Legal Advice)
This document is a general template for informational purposes only and does not constitute legal advice. Privacy and healthcare laws vary by jurisdiction and may change. Consult your legal counsel to tailor this Policy, your HIPAA Notice of Privacy Practices, and your consent flows to your specific operations.
