North Shore Functional Medicine
Privacy Policy
North Shore Functional Medicine
Privacy Policy
Privacy Policy
North Shore Functional Medicine
Effective Date: November 1, 2025
North Shore Functional Medicine (“NSFM,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website, interact with us online, or use our digital services. It also describes your choices and rights regarding your information.
If you are a patient, your health information may also be protected under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Our HIPAA Notice of Privacy Practices explains how we use and disclose Protected Health Information (“PHI”) and your rights under HIPAA. Please review our Notice of Privacy Practices.
1. Information We Collect
A. Information You Provide to Us
When you use our website or contact us, you may voluntarily provide:
Contact information (name, email address, phone number, mailing address)
Appointment or inquiry details you submit through forms
Payment information if you pay for services online (processed by secure third-party vendors; we do not store full card details)
Health information you choose to share via online forms, portals, or secure messaging
B. Information Collected Automatically
When you visit our site, we may automatically collect:
Device and browser data (IP address, browser type, operating system)
Usage data (pages visited, time on site, referring/exit pages, clicks)
Approximate location inferred from IP address
This data helps us improve site performance, security, and usability.
C. Cookies and Similar Technologies
We use cookies, pixels, and similar technologies to:
Make the site work properly
Remember preferences
Measure analytics and traffic
Support marketing/retargeting where enabled
You can control cookies through your browser settings. Some features may not function if cookies are disabled.
2. How We Use Your Information
We may use your information to:
Respond to inquiries and provide requested services
Schedule and manage appointments
Provide patient care and support (including access to secure portals)
Process payments and confirmations
Improve our website, services, and patient experience
Send administrative messages (policy updates, service notices)
Send marketing communications where permitted by law (you can opt out anytime)
Maintain safety, prevent fraud, and secure our systems
If you submit health or medical details through our site, we will use that information only for purposes related to your care or your request.
3. How We Share Your Information
We do not sell your personal information. We may share your information only as follows:
A. With Service Providers
We may share information with trusted vendors who help us operate, such as:
Website hosting and IT support
Appointment scheduling software
Secure patient portal/EHR providers
Payment processors
Email/SMS communication platforms
Analytics providers (e.g., website traffic measurement)
These vendors are required to protect your information and use it only for services they provide to us. If they handle PHI, they are bound by HIPAA business associate agreements. HHS+1
B. For Legal and Safety Reasons
We may disclose information if required to:
Comply with law or legal process
Respond to lawful requests by public authorities
Protect rights, safety, or property of NSFM, our patients, or others
Investigate or prevent fraud or security issues
C. Business Transfers
If NSFM is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction, subject to applicable privacy protections.
4. HIPAA and Protected Health Information (PHI)
If you are a patient, certain information you provide may be PHI under HIPAA. Our HIPAA Notice of Privacy Practices explains:
Our duties to protect PHI
How we may use/disclose PHI for treatment, payment, and healthcare operations
Your rights to access, amend, and receive an accounting of disclosures
How to file a complaint
This online Privacy Policy does not replace our HIPAA Notice. HHS+1
5. Your Privacy Rights and Choices
A. Communication Preferences
You may opt out of marketing emails by clicking “unsubscribe” in any email or contacting us. Administrative or care-related messages may still be sent when necessary.
B. State Privacy Rights
Depending on your state of residence, you may have rights to:
Know what personal data we collect
Access or receive a copy of your data
Request deletion of certain data
Correct inaccurate data
Opt out of certain targeted advertising or data sharing
Appeal decisions about your privacy requests
Many U.S. states now have comprehensive privacy laws (e.g., CA, CO, VA, CT, UT and others). We honor applicable state rights where required. Foley & Lardner LLP+2Bloomberg Law+2
To make a request, contact us using the details in Section 11. We may need to verify your identity before completing your request.
6. Data Security
We use reasonable administrative, technical, and physical safeguards to protect your information, including encryption and access controls where appropriate. However, no online system is 100% secure, and we cannot guarantee absolute security.
If a breach involving unsecured personal health records occurs in a context not covered by HIPAA, we will follow applicable FTC breach notification rules. Federal Trade Commission+2Federal Register+2
7. Data Retention
We keep information only as long as needed for legitimate business and legal purposes, including:
Delivering services and care
Maintaining records required by law
Resolving disputes
Enforcing agreements
Medical and billing records are retained per HIPAA and state requirements.
8. Third-Party Links
Our website may contain links to third-party sites (e.g., social media, partner resources). We are not responsible for their privacy practices. Please review their policies separately.
9. Children’s Privacy
Our site is not intended for children under 13, and we do not knowingly collect personal information from children without parental consent. If you believe a child has provided personal information, please contact us so we can delete it.
10. Changes to This Policy
We may update this Privacy Policy occasionally. Any changes will be posted on this page with an updated Effective Date. Your continued use of our website after changes indicates acceptance of the updated policy.
11. Contact Us
If you have questions or want to exercise a privacy right, contact:
North Shore Functional Medicine
Attn: Privacy Officer
Address: [Street Address, City, State, ZIP]
Phone: [Phone Number]
Email: [Privacy Email Address]
If you are a patient and want to file a HIPAA-related complaint, you may also contact the U.S. Department of Health and Human Services Office for Civil Rights. Instructions are included in our Notice of Privacy Practices.