Joyful Beauty NP

Privacy Policy

Treatments

Effective Date: 10/05/2025

Overview

Joyful Beauty NP (“we,” “our,” or “us”) is committed to protecting the privacy and confidentiality of your personal health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our practice, use our services, or interact with our website.

As a healthcare provider, we are required to comply with the Health Insurance Portability and Accountability Act (HIPAA) and other applicable privacy laws. This policy outlines your rights regarding your protected health information (PHI) and our legal obligations.

Information We Collect

Medical Information

  • Personal identification information (name, address, phone number, email, date of birth, Social Security number)
  • Medical history and current health status
  • Treatment records and clinical notes
  • Photographs (before/after treatment photos, with your written consent)
  • Insurance information and billing records
  • Emergency contact information

Website and Digital Information

  • IP address and browser information
  • Website usage data and cookies
  • Online appointment requests and form submissions
  • Email communications
  • Social media interactions (if you choose to connect with us)

How We Use Your Information

Medical Care and Treatment

  • Providing medical and aesthetic treatments
  • Coordinating care with other healthcare providers
  • Monitoring your response to treatments
  • Managing follow-up care and appointments

Practice Operations

  • Scheduling appointments and sending reminders
  • Billing and insurance processing
  • Quality improvement and patient safety initiatives
  • Staff training and practice management
  • Legal and regulatory compliance

Marketing and Communications (With Your Consent)

  • Sending information about new services or treatments
  • Educational materials about aesthetic procedures
  • Practice newsletters and updates
  • Special offers and promotions
  • Before/after photos for marketing (only with explicit written consent)

Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

With Your Written Authorization

  • Sharing treatment photos for marketing purposes
  • Coordinating care with other healthcare providers you specify
  • Any other use not covered by this policy

Required by Law

  • Court orders or legal proceedings
  • Public health reporting requirements
  • Medical emergencies where disclosure is necessary to protect your health
  • Law enforcement investigations when legally required

Business Associates

  • Insurance companies for claim processing
  • Medical laboratories for test processing
  • IT service providers (with appropriate safeguards)
  • Legal and accounting professionals
  • Other third-party vendors who assist with practice operations

All business associates are required to sign agreements protecting your information and ensuring HIPAA compliance.

Your Privacy Rights

Under HIPAA and other applicable laws, you have the right to:

Access Your Records

  • Request copies of your medical records
  • Review your treatment history and billing information
  • Receive an electronic copy if we maintain records electronically

Request Amendments

  • Ask us to correct inaccurate information in your records
  • Add clarifying information to your file

Request Restrictions

  • Ask us to limit how we use or share your information
  • Request restrictions on communications to certain phone numbers or addresses

Request Confidential Communications

  • Ask that we contact you at a specific phone number or address
  • Request communications in a particular format

File Complaints

  • Complain to us if you believe your privacy rights have been violated
  • File complaints with the U.S. Department of Health and Human Services
  • No retaliation for filing complaints

Receive This Notice

  • Obtain a paper copy of this privacy notice at any time
  • Receive notification of any material changes to this policy

Website Privacy and Cookies

Cookies and Tracking

Our website may use cookies and similar technologies to:

  • Remember your preferences and settings
  • Analyze website traffic and usage patterns
  • Improve user experience and site functionality
  • Provide relevant content and advertisements

You can control cookie settings through your browser preferences.

Third-Party Services

Our website may integrate with third-party services such as:

  • Google Analytics for website analytics
  • Social media platforms
  • Online scheduling systems
  • Payment processing services

These services have their own privacy policies, and we encourage you to review them.

Data Security

We implement appropriate physical, electronic, and administrative safeguards to protect your information:

Physical Safeguards

  • Locked filing cabinets for paper records
  • Restricted access to medical records areas
  • Secure disposal of documents containing PHI

Electronic Safeguards

  • Encrypted data transmission and storage
  • Secure passwords and user authentication
  • Regular software updates and security patches
  • Firewall and antivirus protection

Administrative Safeguards

  • HIPAA training for all staff members
  • Regular security risk assessments
  • Written policies and procedures
  • Incident response procedures

Data Retention

We retain your medical records and personal information in accordance with:

  • New Hampshire state law requirements
  • Professional medical standards
  • HIPAA regulations
  • Business and legal requirements

Generally, we retain medical records for at least 7 years after your last visit, or longer if required by law.

Marketing Communications

Opt-In Policy

We will only send you marketing communications if you have opted in to receive them. This includes:

  • Email newsletters
  • Treatment information and educational content
  • Special offers and promotions
  • Event invitations

Opt-Out Options

You can opt out of marketing communications at any time by:

  • Clicking “unsubscribe” in email communications
  • Contacting our office directly
  • Updating your preferences during appointments

Note: Opting out of marketing communications will not affect necessary medical communications about your care.

Photography and Social Media

Before/After Photos

  • We will only use your photos for marketing with explicit written consent
  • You can revoke consent for future use at any time
  • Photos are stored securely and shared only as authorized
  • Your identity will be protected unless you specifically consent otherwise

Social Media Policy

  • We may feature general practice information on social media
  • Patient-specific information is never shared without written consent
  • Comments and interactions on social media are subject to this privacy policy

Children’s Privacy

Our services are generally provided to adults (18 years and older). When treating minors:

  • We obtain appropriate parental/guardian consent
  • We follow all applicable laws regarding minors’ privacy rights
  • We maintain the same security standards for all patient information

Changes to This Privacy Policy

We reserve the right to modify this privacy policy at any time. When we make changes:

  • We will post the updated policy on our website
  • We will notify patients of significant changes during their next visit
  • The effective date will be updated to reflect when changes take effect
  • We will maintain prior versions for our records

International Visitors

If you are visiting from outside the United States, please note that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country.

Contact Information

Privacy Officer

For questions about this privacy policy or to exercise your privacy rights, contact:

Joy DeRoche, NP
Privacy Officer

Address: 155 Main Street, Plaistow, NH 03865

Phone: (978) 702-3736

Email: [email protected]

Website: www.joyfulbeautymedspa.com

Filing Complaints

If you believe your privacy rights have been violated, you may file a complaint with:

Our Practice:
Contact our Privacy Officer using the information above

U.S. Department of Health and Human Services:
Office for Civil Rights
200 Independence Avenue, S.W.
Washington, D.C. 20201
Phone: 1-877-696-6775
Website: www.hhs.gov/ocr/privacy/hipaa/complaints/

Acknowledgment

By receiving services at Joyful Beauty NP, you acknowledge that you have received and understand this Privacy Policy. If you have questions or concerns, please don’t hesitate to discuss them with our team.