Effective Date: 10/05/2025
Overview
Joyful Beauty NP (“we,” “our,” or “us”) is committed to protecting the privacy and confidentiality of your personal health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our practice, use our services, or interact with our website.
As a healthcare provider, we are required to comply with the Health Insurance Portability and Accountability Act (HIPAA) and other applicable privacy laws. This policy outlines your rights regarding your protected health information (PHI) and our legal obligations.
Information We Collect
Medical Information
- Personal identification information (name, address, phone number, email, date of birth, Social Security number)
- Medical history and current health status
- Treatment records and clinical notes
- Photographs (before/after treatment photos, with your written consent)
- Insurance information and billing records
- Emergency contact information
Website and Digital Information
- IP address and browser information
- Website usage data and cookies
- Online appointment requests and form submissions
- Email communications
- Social media interactions (if you choose to connect with us)
How We Use Your Information
Medical Care and Treatment
- Providing medical and aesthetic treatments
- Coordinating care with other healthcare providers
- Monitoring your response to treatments
- Managing follow-up care and appointments
Practice Operations
- Scheduling appointments and sending reminders
- Billing and insurance processing
- Quality improvement and patient safety initiatives
- Staff training and practice management
- Legal and regulatory compliance
Marketing and Communications (With Your Consent)
- Sending information about new services or treatments
- Educational materials about aesthetic procedures
- Practice newsletters and updates
- Special offers and promotions
- Before/after photos for marketing (only with explicit written consent)
Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
With Your Written Authorization
- Sharing treatment photos for marketing purposes
- Coordinating care with other healthcare providers you specify
- Any other use not covered by this policy
Required by Law
- Court orders or legal proceedings
- Public health reporting requirements
- Medical emergencies where disclosure is necessary to protect your health
- Law enforcement investigations when legally required
Business Associates
- Insurance companies for claim processing
- Medical laboratories for test processing
- IT service providers (with appropriate safeguards)
- Legal and accounting professionals
- Other third-party vendors who assist with practice operations
All business associates are required to sign agreements protecting your information and ensuring HIPAA compliance.
Your Privacy Rights
Under HIPAA and other applicable laws, you have the right to:
Access Your Records
- Request copies of your medical records
- Review your treatment history and billing information
- Receive an electronic copy if we maintain records electronically
Request Amendments
- Ask us to correct inaccurate information in your records
- Add clarifying information to your file
Request Restrictions
- Ask us to limit how we use or share your information
- Request restrictions on communications to certain phone numbers or addresses
Request Confidential Communications
- Ask that we contact you at a specific phone number or address
- Request communications in a particular format
File Complaints
- Complain to us if you believe your privacy rights have been violated
- File complaints with the U.S. Department of Health and Human Services
- No retaliation for filing complaints
Receive This Notice
- Obtain a paper copy of this privacy notice at any time
- Receive notification of any material changes to this policy
Website Privacy and Cookies
Cookies and Tracking
Our website may use cookies and similar technologies to:
- Remember your preferences and settings
- Analyze website traffic and usage patterns
- Improve user experience and site functionality
- Provide relevant content and advertisements
You can control cookie settings through your browser preferences.
Third-Party Services
Our website may integrate with third-party services such as:
- Google Analytics for website analytics
- Social media platforms
- Online scheduling systems
- Payment processing services
These services have their own privacy policies, and we encourage you to review them.
Data Security
We implement appropriate physical, electronic, and administrative safeguards to protect your information:
Physical Safeguards
- Locked filing cabinets for paper records
- Restricted access to medical records areas
- Secure disposal of documents containing PHI
Electronic Safeguards
- Encrypted data transmission and storage
- Secure passwords and user authentication
- Regular software updates and security patches
- Firewall and antivirus protection
Administrative Safeguards
- HIPAA training for all staff members
- Regular security risk assessments
- Written policies and procedures
- Incident response procedures
Data Retention
We retain your medical records and personal information in accordance with:
- New Hampshire state law requirements
- Professional medical standards
- HIPAA regulations
- Business and legal requirements
Generally, we retain medical records for at least 7 years after your last visit, or longer if required by law.
Marketing Communications
Opt-In Policy
We will only send you marketing communications if you have opted in to receive them. This includes:
- Email newsletters
- Treatment information and educational content
- Special offers and promotions
- Event invitations
Opt-Out Options
You can opt out of marketing communications at any time by:
- Clicking “unsubscribe” in email communications
- Contacting our office directly
- Updating your preferences during appointments
Note: Opting out of marketing communications will not affect necessary medical communications about your care.
Photography and Social Media
Before/After Photos
- We will only use your photos for marketing with explicit written consent
- You can revoke consent for future use at any time
- Photos are stored securely and shared only as authorized
- Your identity will be protected unless you specifically consent otherwise
Social Media Policy
- We may feature general practice information on social media
- Patient-specific information is never shared without written consent
- Comments and interactions on social media are subject to this privacy policy
Children’s Privacy
Our services are generally provided to adults (18 years and older). When treating minors:
- We obtain appropriate parental/guardian consent
- We follow all applicable laws regarding minors’ privacy rights
- We maintain the same security standards for all patient information
Changes to This Privacy Policy
We reserve the right to modify this privacy policy at any time. When we make changes:
- We will post the updated policy on our website
- We will notify patients of significant changes during their next visit
- The effective date will be updated to reflect when changes take effect
- We will maintain prior versions for our records
International Visitors
If you are visiting from outside the United States, please note that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country.
Contact Information
Privacy Officer
For questions about this privacy policy or to exercise your privacy rights, contact:
Joy DeRoche, NP
Privacy Officer
Address: 155 Main Street, Plaistow, NH 03865
Phone: (978) 702-3736
Email: [email protected]
Website: www.joyfulbeautymedspa.com
Filing Complaints
If you believe your privacy rights have been violated, you may file a complaint with:
Our Practice:
Contact our Privacy Officer using the information above
U.S. Department of Health and Human Services:
Office for Civil Rights
200 Independence Avenue, S.W.
Washington, D.C. 20201
Phone: 1-877-696-6775
Website: www.hhs.gov/ocr/privacy/hipaa/complaints/
Acknowledgment
By receiving services at Joyful Beauty NP, you acknowledge that you have received and understand this Privacy Policy. If you have questions or concerns, please don’t hesitate to discuss them with our team.