HIPAA Policy

Last updated: May 23, 2026

The Vein and Wound Center of LA is committed to protecting your health information in compliance with the Health Insurance Portability and Accountability Act (HIPAA). This policy explains how we handle Protected Health Information (PHI) collected through our website and practice, and your rights regarding your medical information.

Information Collection and Use

Personal Contact Information

If you contact us via our website form or email, we may collect personal identifiers such as your name, email address, phone number, and any details you voluntarily provide.

  • Purpose: We use this information solely to respond to your inquiries, schedule appointments, or follow up on your requests.

  • Security Note: Our website’s contact form is designed not to store submissions on the web server—messages are transmitted directly to our office via secure email and are not retained in the website database, reducing the risk of unauthorized access.

Protected Health Information (PHI)

PHI includes any health-related information that can identify you (e.g., medical history, vein or wound conditions, insurance info).

  • We do not ask for detailed health or treatment information through our general website contact form, and we urge you not to include sensitive medical details in online form messages.

  • If you do choose to provide any health information (for example, when describing a vascular or wound care concern), we will treat it as PHI and protect it accordingly.

  • No PHI is stored on our website unless submitted through a secure, HIPAA-compliant channel. Any PHI you provide is encrypted in transit via HTTPS (TLS 1.2 or higher) and delivered directly to our internal medical systems.

Technical Data (Non-PHI)

Our website may automatically collect basic technical information such as your IP address, browser type, and pages visited through analytics cookies. This data helps us improve the site’s functionality and online experience. These analytics do not collect or store PHI and cannot identify you personally.

How We Use and Disclose PHI

If you become a patient or provide us with PHI, we will use and disclose your health information only as permitted by HIPAA and applicable law:

  • Treatment: To provide and coordinate your specialized vein and wound care. For example, information you share about your medical history may be used by our physicians and medical staff to diagnose issues and plan your treatment.

  • Payment: To bill and obtain payment for services. We may use PHI to process medical insurance claims or communicate with your insurer about a procedure.

  • Healthcare Operations: For internal purposes such as quality improvement, staff training, customer service, or administrative activities that enhance your care.

  • Appointments and Services: To remind you of appointments or provide information on treatment alternatives or health-related benefits.

  • Required or Permitted by Law: We will disclose PHI when required to do so by state or federal law (for example, reporting certain findings to public health authorities or responding to a valid court order).

Important: We will NOT use or share your PHI for marketing purposes without your explicit written authorization. We do not sell your PHI. Any uses beyond those listed above will be done only with your explicit consent or as otherwise allowed by law.

Third-Party Services and Business Associates

The Vein and Wound Center of LA may utilize trusted third-party services to assist in our practice operations (e.g., electronic health record systems, online appointment scheduling, specialized medical laboratory services).

Any third-party service that handles PHI is thoroughly vetted for HIPAA compliance. We maintain a formal Business Associate Agreement (BAA) with them, as required by HIPAA. This means they are legally obligated to safeguard your information just as we do. All data transmitted to these providers is protected via encryption and stored using rigorous HIPAA-compliant security measures. We do not transmit PHI through any software or integration that is not HIPAA-compliant.

Your HIPAA Privacy Rights

You have the following rights regarding your health information, as provided by federal law:

  • Right to Access and Copies: You have the right to see and get copies of your medical records that we maintain, including electronic copies if available.

  • Right to Request Amendment: If you believe information in your record is incorrect or incomplete, you may request a correction. If we deny your request, we will provide a written explanation.

  • Right to an Accounting of Disclosures: You can request a list of certain disclosures we have made of your PHI, for purposes other than treatment, payment, healthcare operations, and a few exceptional cases.

  • Right to Request Restrictions: You may ask us in writing to restrict how we use or disclose your PHI for treatment, payment, or operations. While we will consider all requests, please note we are not required to agree to a requested restriction in all cases.

  • Right to Request Confidential Communications: You can request that we contact you in a certain way or at a certain location (for example, only call your mobile phone, or send mail to a specific address). We will accommodate all reasonable requests.

  • Right to a Copy of this Policy: You may request a paper copy of this HIPAA Privacy Policy at any time, even if you have agreed to receive it electronically.

To exercise any of these rights, please contact our Privacy Officer. For your protection, we will need to verify your identity before fulfilling requests (such as access or amendment requests).

Safeguards & Security

We employ strict administrative, technical, and physical safeguards to protect your information:

  1. Encryption: Our website uses SSL/TLS encryption (HTTPS) to secure data submitted online. Any PHI stored in our internal systems is protected with encryption at rest (in compliance with the AES 256-bit standard for healthcare data storage).

  2. Secure Hosting and Networks: We utilize firewalls, antivirus software, and continuous monitoring to prevent unauthorized network access.

  3. Access Controls: Only authorized medical and administrative staff can access patient information. We implement role-based access so staff members only access the minimum necessary information to perform their duties.

  4. Physical Security: Our clinic maintains secure files and restricted areas for any paper records. Facilities are securely locked and alarmed after hours.

  5. Employee Training: We regularly train our team on patient privacy and security practices, conduct internal audits, and strictly enforce our written PHI policies.

Please note: Despite our comprehensive safeguards, no method of electronic transmission or storage is 100% secure. In the unlikely event of a data breach involving your PHI, we will strictly follow HIPAA’s breach notification requirements to inform you and authorities immediately.

Questions, Concerns, or Exercising Your Rights

If you have any questions about this HIPAA Policy, or if you wish to exercise your privacy rights, please contact our HIPAA Privacy Officer:

Vein and Wound Center of LA Attn: HIPAA Privacy Officer

  • Address: 3663 W. 6th St Suite 103, Los Angeles, CA 90020

  • Phone: (213) 654-8346

  • Email: info@vwcla.com

If you believe your privacy rights have been violated, you have the right to file a complaint with us at the contact information above, or directly with the U.S. Department of Health & Human Services (Office for Civil Rights). We will not retaliate against you in any way for filing a complaint.

Updates to This Policy

We may update this HIPAA Privacy Policy from time to time. If changes are made, we will post the updated policy on our website with a new effective date. Any material changes will apply only to PHI we collect after the effective date, unless we are required by law to apply changes to previously collected information.