Privacy policy

This practice is a HIPAA covered entity. Your health information is handled under 45 CFR Parts 160 and 164, every vendor that touches it works under a signed business associate agreement, and telephone calls are recorded with your consent as Florida law requires. This page explains what is collected and by whom. It does not ask you to waive anything.

1 · Two separate systems

This matters more than any sentence of policy, because it is architecture rather than intention.

This marketing website and the patient application are separate deployments, on separate domains, with separate databases and separate credentials. They share a visual design and one link. Nothing else.

The consequence is that a tracking tag added to this website is structurally incapable of reaching a page where you enter health information. That is not a promise about what we would choose to do. It is a statement about what the system can do.

This website carries no protected health information. It has no login, no patient records, and no form that asks about your health.

2 · What this website collects

Very little, and nothing about your health. Standard server logs — IP address, browser, the page requested — are kept for security and are not used to build a profile of you.

Analytics, if enabled, are consent-gated: nothing loads until you agree, and declining leaves the site fully usable. There is no session-replay tool on this site and no advertising pixel. That is a deliberate decision rather than an oversight — see the privacy and HIPAA notice for why Florida’s Security of Communications Act makes those a genuine liability on a healthcare site.

No procedure page you visit is ever sent to an advertising platform. Visiting a page about wisdom teeth does not put you in an audience.

3 · Recorded calls and the AI assistant

Fla. Stat. §934.03 is an all-party consent statute and a third-degree felony provision. It has no general business exception.

Calls to this practice are answered by an AI assistant and are recorded. You are told both things at the start of every call, before any speech recognition begins, because automated recognition of what you say is itself an interception under Florida law. Your consent is captured and logged with a timestamp. The disclosure is repeated at the end of the call.

If you decline, you are routed to a path that is not recorded. Declining does not affect your ability to become a patient or to be treated.

What the assistant processes

The audio of the call, a transcript, the answers you give to intake questions, and the insurance details needed to check your benefits. Intake answers are summarised for the surgeon by a language model running server-side under a business associate agreement — never in your browser, and never by a consumer AI product.

Clinical red flags in what you report — anticoagulants, bisphosphonates, cardiac history, pregnancy, a prior anaesthetic complication — are detected by rule-based code rather than by the model, and are surfaced to the surgeon whatever the summary says. That is a safety decision, not a privacy one, but it is the reason the model is never the last word on anything.

Recordings and transcripts are retained under the practice’s record retention schedule and are part of your record. You may request access to them on the same terms as the rest of your record.

4 · Who else sees your information

Every one of these has a signed, countersigned business associate agreement on file before it sees anything identifying.

A business associate under 45 CFR §160.103 is a vendor that handles protected health information on the practice’s behalf. They are bound by the same rules the practice is, they may use your information only to do the job they are engaged for, and they may not sell it.

Telephone and SMS
Carries the call and the text messages. Sees the audio and the number.
Voice assistant
Runs the conversation. Sees the transcript.
Language model provider
Summarises intake for the surgeon. Server-side only, never in your browser.
Insurance eligibility
Sends the medical and dental eligibility requests to your payer.
Practice management system
The clinical record. The system of record for your chart.
Secure email
Encrypted email where anything identifying is sent.
Electronic signature
Consent and authorisation forms.
Door access control
Issues the time-boxed arrival code. Sees that an appointment exists, not why.

Payment processing is deliberately absent from that list. The payment processor receives an amount and an opaque reference. It is not told what was done, or why.

Your information is not sold, and never has been

The practice does not sell protected health information, does not disclose it for marketing without a signed authorisation, and does not use it for advertising. Selling PHI without authorisation is prohibited by 45 CFR §164.502(a)(5)(ii).

5 · Your rights

HIPAA gives you rights over your own record. In summary, you may:

  • See and get a copy of your record, usually within 30 days — 45 CFR §164.524.
  • Ask for a correction where something is wrong or incomplete — §164.526.
  • Get a list of certain disclosures the practice has made — §164.528.
  • Ask for a restriction on how your information is used, and require one where you pay in full yourself and ask that the claim not go to your insurer — §164.522.
  • Ask to be contacted a particular way, or at a particular address — §164.522(b).
  • Get a paper copy of the Notice of Privacy Practices, whenever you ask.
  • Be notified if there is a breach affecting your information — §164.404.
  • Complain, without any effect on your care.

The full statement of these rights, with the detail HIPAA requires, is in the practice’s Notice of Privacy Practices, which you are given at your first visit and can ask for at any time.

6 · How to complain

Raise it with the practice first if you are willing — most things are a misunderstanding and are fixed the same day. Ask for the privacy officer.

You can also complain directly to the U.S. Department of Health and Human Services, Office for Civil Rights, and you do not need the practice’s permission to do it. Complaints go to 200 Independence Avenue SW, Washington DC 20201, or through the OCR complaint portal.

You will not be retaliated against, and your care will not change, because you made a complaint. Retaliation is itself prohibited by 45 CFR §164.530(g).

7 · Security, retention and children

Information is encrypted in transit and at rest, access is limited to those who need it to do their job, and access is logged. No system is perfect, and any practice claiming otherwise is overstating it — what can be said honestly is that the architecture keeps health information out of the places it does not need to be.

Records are retained for the period Florida law requires of a dental practice, and longer for a minor. Call recordings and transcripts are retained under the same schedule as the rest of the record.

This website is not directed at children and does not knowingly collect information from them. A patient under 18 is treated with a parent or legal guardian present, who signs on their behalf.

8 · Changes and contact

This policy may change. The version here is the one in force. Where HIPAA requires it, a material change is also reflected in the Notice of Privacy Practices and made available to you.

The Wisdom Tooth Clinic (The Wisdom Tooth Clinic for Teens and Adults, PC)
2960 Aventura Blvd, Suite 306, Miami, FL 33180

See also the terms of use and the privacy and HIPAA notice.

This policy is under review by counsel and is not yet in force. This site is in preparation and is not yet open to patients.