Your Privacy Matters
Privacy Policy & HIPAA Notice
Crown Hair Institute is committed to protecting the privacy and security of your personal health information in compliance with federal and state regulations.
Notice of Privacy Practices (NPP)
This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully.
Crown Hair Institute is required by law to maintain the privacy of your Protected Health Information (PHI), to provide you with notice of our legal duties and privacy practices with respect to your PHI, and to notify you in the event of a breach of your unsecured PHI. We are required to abide by the terms of this Notice of Privacy Practices as long as it remains in effect. We reserve the right to change the terms of this notice and to make new notice provisions effective for all PHI that we maintain.
Information We Collect
In the course of providing you with hair restoration services, we may collect the following types of information:
- ✓Protected Health Information (PHI): Medical history, health conditions, medications, treatment records, surgical notes, photographs, lab results, and diagnostic information related to your hair restoration care.
- ✓Contact Information: Name, address, phone number, email address, date of birth, and emergency contact details.
- ✓Health History: Family medical history, current medications, allergies, prior surgical procedures, and relevant lifestyle information that may affect your treatment outcomes.
- ✓Financial Information: Insurance details, billing records, and payment information necessary for processing your care.
How We Use Your Information
We may use and disclose your PHI for the following purposes without your written authorization:
Treatment
We use your PHI to provide, coordinate, and manage your hair restoration treatment. This includes sharing information with other healthcare providers involved in your care, such as anesthesiologists, laboratory personnel, and referring physicians.
Payment
We may use and disclose your PHI to obtain payment for services rendered. This includes billing, claims management, collections activities, and obtaining prior authorizations.
Healthcare Operations
We may use and disclose your PHI for our internal operations, including quality assessment, staff training, compliance programs, auditing, and business management activities necessary to support our practice.
How We Protect Your Information
We implement comprehensive administrative, technical, and physical safeguards to protect your PHI:
Encryption
All electronic PHI is encrypted at rest and in transit using industry-standard AES-256 encryption protocols.
Secure Servers
Patient data is stored on HIPAA-compliant, SOC 2 certified servers with continuous monitoring and regular security audits.
Access Controls
Role-based access controls ensure only authorized personnel can access your information. All access is logged and audited.
Staff Training
All team members complete annual HIPAA training and are bound by confidentiality agreements to safeguard your information.
Your Rights Under HIPAA
As a patient, you have the following rights regarding your Protected Health Information:
Right to Access
You have the right to inspect and obtain a copy of your PHI maintained by our practice. Requests must be submitted in writing. We may charge a reasonable fee for copies.
Right to Amend
You may request an amendment to your PHI if you believe information in your record is incorrect or incomplete. We may deny the request under certain circumstances, but you have the right to submit a statement of disagreement.
Right to Restrict
You may request restrictions on how we use or disclose your PHI for treatment, payment, or healthcare operations. We are not required to agree to all requests but will comply with any restriction to which we agree.
Right to an Accounting of Disclosures
You have the right to receive a list of certain disclosures we have made of your PHI. This accounting will not include disclosures made for treatment, payment, or healthcare operations, or disclosures you have authorized.
Right to Confidential Communications
You may request that we communicate with you about your health information in a particular way or at a certain location. For example, you may ask that we contact you only at your work address or via a specific phone number.
Right to File a Complaint
If you believe your privacy rights have been violated, you may file a complaint with our Privacy Officer or with the U.S. Department of Health and Human Services Office for Civil Rights. You will not be penalized or retaliated against for filing a complaint.
Disclosure of PHI
We may disclose your PHI without your authorization in the following limited circumstances:
- •As Required by Law: When required by federal, state, or local law, including mandatory reporting requirements.
- •Public Health Activities: To public health authorities for disease prevention, injury reporting, or FDA-regulated product tracking.
- •Judicial and Administrative Proceedings: In response to a court order, subpoena, or other lawful process with appropriate protections in place.
- •Law Enforcement: To law enforcement officials under specific circumstances as permitted by law.
- •To Avert a Serious Threat: When necessary to prevent a serious and imminent threat to health or safety.
All other uses and disclosures of your PHI not described in this notice will require your written authorization, which you may revoke at any time.
Website Data Collection
Our website uses cookies and analytics tools to improve your browsing experience. This data is not Protected Health Information and is used solely for:
- •Analyzing website traffic and usage patterns
- •Improving website functionality and user experience
- •Remembering your preferences and settings
- •Delivering relevant content and advertisements
You may disable cookies through your browser settings. Doing so may limit certain features of our website.
Contact Forms & Consultations
When you submit information through our contact forms, consultation request forms, or other online tools, your data is transmitted securely using SSL/TLS encryption. Information submitted through these forms is treated as confidential and is used solely for the purpose of responding to your inquiry, scheduling consultations, or providing requested information about our services.
We recommend that you do not include detailed medical information in online forms. Sensitive health information should be discussed directly with our clinical team during your private consultation.
Third-Party Services
We work with carefully selected third-party service providers who may have access to your information in the course of providing services to us. All third-party service providers who may access PHI are required to sign Business Associate Agreements (BAAs) and comply with HIPAA regulations. These partners include:
- •Payment processors for secure transaction handling
- •Electronic health record (EHR) system providers
- •HIPAA-compliant email and communication services
- •Cloud storage and backup providers
- •Laboratory and diagnostic service partners
Data Retention
We retain your medical records and PHI in accordance with California state law and HIPAA requirements. Medical records for adult patients are maintained for a minimum of seven (7) years from the date of the last encounter. Records for minor patients are retained until the patient reaches age 19 or for seven years from the last encounter, whichever is longer.
Non-medical personal information collected through our website is retained only as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required by law.
Changes to This Policy
We reserve the right to update this Privacy Policy and Notice of Privacy Practices at any time. Changes will be posted on this page with a revised effective date. We encourage you to review this page periodically for the latest information on our privacy practices. Material changes affecting your rights will be communicated to you via email or prominent notice on our website prior to the changes taking effect.
Your California Privacy Rights
If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the following rights regarding your personal information:
Right to Know & Access
You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which the information is collected, the business purpose for collecting the information, and the categories of third parties with whom we share it.
Right to Delete
You have the right to request the deletion of your personal information that we have collected, subject to certain exceptions (for example, we may need to retain information to comply with legal obligations or complete a transaction you requested).
Right to Opt Out of Sale or Sharing
Crown Hair Institute does not sell your personal information. However, you have the right to opt out of any future sale or sharing of your personal information for cross-context behavioral advertising purposes.
Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. You will not receive different pricing, quality of services, or any other adverse treatment for exercising your rights.
To exercise any of these rights, please contact our Privacy Officer at privacy@crownhairinstitute.com or call (323) 947-2126. We will respond to verifiable consumer requests within 45 days.
Contact Information
If you have questions about this Privacy Policy, wish to exercise your rights, or want to file a complaint, please contact our Privacy Officer:
Crown Hair Institute Privacy Officer
You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights by visiting www.hhs.gov/ocr or calling 1-877-696-6775.