ReGlow Wellness Privacy Policy

Effective Date: February 8, 2026Last Updated: February 8, 2026

1. Introduction

1.1 Who We Are

ReGlow Wellness ("we," "us," or "our") operates as a Management Services Organization (MSO) providing scheduling, operational support, and administrative services to a physician-owned medical practice located in Levittown, NY.

Important: ReGlow Wellness (MSO) does not practice medicine, make clinical decisions, or own the medical practice. All medical care is provided by a separate physician-owned professional medical corporation. This Privacy Policy applies to our scheduling and operational systems only.

1.2 What This Policy Covers

This Privacy Policy describes how we collect, use, disclose, and protect your information through our scheduling platform and patient portal (the "System"). This System is an operational tool for appointment scheduling and coordination—it is not an electronic health records (EHR) system.

Scope:

1.3 HIPAA Designation

ReGlow Wellness operates as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) to the physician-owned medical practice. We handle certain protected health information (PHI) necessary for scheduling and operational purposes, and we maintain strict compliance with all HIPAA Privacy and Security Rules.

1.4 Geographic Scope

We operate in New York State and comply with all applicable New York privacy laws, including the NY SHIELD Act.

2. Information We Collect

2.1 Patient Demographics & Contact Information

We collect and maintain:

Collection method: Provided directly by you, entered by our staff, or synced from the medical practice's records.

2.2 Appointment & Scheduling Information

2.3 Medical Referral Information (Scripts)

To enforce medical requirements for massage and acupuncture treatments, our System reads (but does not store in our database) the following information from the medical practice's EHR:

Critical clarification: This medical referral information remains stored and controlled by the physician-owned medical practice. Our scheduling system only references this information to enforce booking rules. We do not make medical determinations about these scripts—they are issued solely by licensed medical providers.

2.4 Financial & Billing Information

2.5 Authentication & Portal Access Data

2.6 Communications

2.7 Audit & Operational Data

Our System automatically logs:

All logs include: user identity, action taken, date, time, and reason (when applicable).

2.8 Technical & Usage Information

3. How We Collect Information

3.1 Direct Collection

3.2 From Healthcare Providers

3.3 From Medical Practice EHR

3.4 Automatically

3.5 From Third Parties

4. How We Use Your Information

4.1 Primary Purposes (HIPAA Treatment, Payment, Healthcare Operations)

Scheduling & Appointment Management:

Medical Requirement Enforcement:

Note: This is operational enforcement of requirements set by the medical practice; we do not make medical determinations.

Communications:

Patient Portal:

Billing Support:

Staff Operations:

4.2 Secondary Purposes

System Security & Fraud Prevention:

Operational Analytics:

Legal Compliance:

Quality Improvement:

4.3 What We DON'T Use Your Information For

5. Legal Bases for Processing

We process your information based on:

6. Information Sharing & Disclosure

6.1 With the Physician-Owned Medical Practice

We share scheduling and operational data with the medical practice that provides your care, including:

Purpose: Care coordination and operational support. The medical practice maintains separate medical records that we do not control.

6.2 With Business Associates (HIPAA-Compliant Service Providers)

We work with third-party service providers who have signed Business Associate Agreements (BAAs) and maintain HIPAA compliance:

Service ProviderPurposeData SharedTwilioSMS notifications and authenticationPhone numbers, appointment details, OTP codesEmail Service ProviderEmail notificationsEmail addresses, appointment details, notificationsDatabase HostingSystem infrastructureAll scheduling data (encrypted)Payment ProcessorPayment processingName, payment information, amounts

All Business Associates are contractually required to:

You may request a current list of our Business Associates by contacting our Privacy Officer.

6.3 For Legal Reasons

We may disclose information when required by law:

We will notify you of such disclosures unless prohibited by law.

6.4 Business Transfers

If ReGlow Wellness or the MSO is involved in a merger, acquisition, sale of assets, or bankruptcy:

6.5 With Your Consent

We may share information with other parties if you provide specific written consent.

6.6 We Do NOT Share

7. Data Storage, Security & Protection

7.1 Technical Safeguards

Encryption:

Access Controls:

Monitoring & Logging:

Network Security:

7.2 Physical Safeguards

Data Center Security:

Geographic Storage:

7.3 Administrative Safeguards

Staff Training:

Policies & Procedures:

Risk Management:

7.4 System-Specific Security

Patient Portal:

Public Confirmation Links:

Database Architecture:

8. Data Retention & Deletion

8.1 Retention Periods

Active Patient Records:

Audit Logs:

Inactive Accounts:

Legal Holds:

8.2 Deletion Requests

You may request deletion of your information, subject to limitations:

What can be deleted:

What cannot be deleted:

Process: Submit written request to our Privacy Officer (see Section 17).

8.3 Account Closure

If you close your account or stop receiving services:

9. Your HIPAA Privacy Rights

Under HIPAA and New York law, you have the following rights regarding your information:

9.1 Right to Access

You have the right to inspect and obtain a copy of your scheduling information.

How to make a request: See Section 17 for contact information.

9.2 Right to Amend

You have the right to request corrections to your information.

Note: Medical determinations (scripts, medical clearances) can only be amended by the physician-owned medical practice, not by ReGlow.

9.3 Right to an Accounting of Disclosures

You have the right to receive a list of certain disclosures we made.

9.4 Right to Request Restrictions

You have the right to request limits on how we use or share your information.

Example: Request that we not leave appointment reminders as voicemail.

9.5 Right to Confidential Communications

You have the right to request we contact you in specific ways.

How to request: Update preferences in patient portal or contact our office.

9.6 Right to Breach Notification

You have the right to be notified if your information is breached.

9.7 Right to a Paper Copy of This Policy

You have the right to receive a paper copy of this Privacy Policy.

9.8 Right to File a Complaint

You have the right to complain if you believe your privacy rights were violated.

File a complaint with us:

File a complaint with HHS:

No Retaliation: We will not retaliate, intimidate, or discriminate against you for filing a complaint or exercising your rights.

10. MSO Structure & Clinical Separation

10.1 Understanding Our Role

ReGlow Wellness (MSO) provides:

ReGlow Wellness (MSO) does NOT:

10.2 Medical Practice Relationship

Your medical care is provided by Alliance Wellness Medical PLLC, a separate physician-owned professional corporation. This legal structure is required by New York's Corporate Practice of Medicine doctrine.

Medical Practice (Physician-Owned Entity):

MSO–Medical Practice Agreement:

10.3 Data Separation

Two Separate Systems:

Scheduling System (ReGlow MSO):

Medical Records System (Medical Practice):

Integration:

10.4 Script Enforcement Clarification

When our System checks for valid medical referrals (scripts) before booking:

We do not:

11. New York State Law Compliance

11.1 NY SHIELD Act

We comply with the New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act, which requires:

11.2 NY Data Breach Notification

New York requires faster breach notification than federal HIPAA:

11.3 Corporate Practice of Medicine Compliance

Our MSO structure complies with NY's prohibition on corporate practice of medicine:

12. Children's Privacy

12.1 Minors Under 18

Parental Consent Required:

Age of Majority:

12.2 Children Under 13 (COPPA)

For children under 13:

12.3 Emancipated Minors

If you are an emancipated minor or legally authorized to consent to your own care under New York law, please notify us to ensure appropriate access controls.

13. Cookies & Tracking Technologies

13.1 What We Use

Essential Cookies:

Functional Cookies:

Analytics Cookies (if applicable):

13.2 Your Choices

Browser Controls:

Do Not Track:

13.3 Third-Party Tracking

We do not allow third-party advertising or tracking on our patient portal.

14. Notifications & Communications

14.1 Appointment Reminders

Methods:

Timing:

Content:

14.2 Communication via Twilio

SMS Provider: We use Twilio as our Business Associate for SMS delivery.

Security:

Limitations:

14.3 Opt-Out Options

You may opt out of:

You cannot opt out of:

How to opt out: Update preferences in patient portal or contact our office.

14.4 Failure Retry

If SMS or email delivery fails:

15. International Data & Transfers

15.1 US-Based Operations

15.2 GDPR & International Privacy Laws

We do not target or serve patients outside the United States. If you are located outside the US:

16. Changes to This Privacy Policy

16.1 Updates

We may update this Privacy Policy to reflect:

16.2 Notice of Changes

How we notify you:

Material Changes:

16.3 Version History

Previous versions of this Privacy Policy are available upon request.

16.4 Your Acceptance

By continuing to use our services after changes, you accept the updated Privacy Policy.

If you do not agree with changes, you may:

17. Contact Information

17.1 Privacy Officer

For privacy questions, requests, or complaints:

ReGlow Wellness — Privacy Officer11 Emerson AveLevittown, NY 11756

17.2 Types of Requests

Privacy Officer can help with:

17.3 Medical Practice Contact

For medical record requests or clinical questions:

Alliance Wellness Medical PLLC11 Emerson AveLevittown, NY 11756

Note: The medical practice maintains separate medical records not covered by this Privacy Policy.

17.4 Response Times

18. Compliance Certifications & Audits

18.1 Our Commitments

We maintain:

18.2 Verification

You may request:

Contact our Privacy Officer to request compliance verification information.

18.3 External Audits

We undergo:

19. Data Breach Response

19.1 Our Commitment

We take data security seriously. Despite our safeguards, no system is 100% secure.

19.2 What Constitutes a Breach

A breach occurs when:

19.3 Our Response

If a breach occurs:

Immediate:

Notification:

Remediation:

19.4 What You'll Receive

Breach notifications include:

19.5 Low Risk Exceptions

If we determine a breach poses low risk of harm (after thorough risk assessment), notification requirements may differ. We document all risk assessments.

20. Patient Portal Specifics

20.1 Authentication Security

Login Process:

  1. Enter date of birth (DOB)
  2. Receive SMS one-time password (OTP) to phone on file
  3. Enter OTP within 5 minutes
  4. Access granted for secure session

Security features:

20.2 Public Confirmation Links

How they work:

Security:

20.3 Portal Capabilities

What you can do:

What you cannot do:

For medical questions: Contact the medical practice directly.

21. Additional Disclosures

21.1 No Medical Advice

This System provides scheduling services only. It does not provide medical advice, diagnosis, or treatment.

21.2 System Availability

While we strive for 24/7 availability:

21.3 Third-Party Links

Our patient portal may contain links to third-party websites (e.g., payment processors). We are not responsible for the privacy practices of third-party sites. Review their privacy policies separately.

21.4 Limitation of Liability

To the extent permitted by law and HIPAA:

Note: This limitation does not waive your HIPAA rights or our HIPAA obligations.

22. Definitions

23. Legal Notices

23.1 Governing Law

This Privacy Policy is governed by:

Venue: Any disputes shall be resolved in New York State courts.

23.2 Severability

If any provision of this Privacy Policy is found invalid or unenforceable, the remaining provisions remain in full effect.

23.3 No Waiver of Rights

23.4 Entire Agreement

This Privacy Policy, together with our Terms and Conditions, constitutes the entire agreement regarding privacy practices for our scheduling system.

24. Acknowledgment

By using our scheduling system or patient portal, you acknowledge that:

For questions about this Privacy Policy, contact our Privacy Officer using the information in Section 17.

Last Updated: February 8, 2026Effective Date: February 8, 2026Version: 1.0

© 2026 ReGlow Wellness. All rights reserved.