Legal

Website Privacy Policy

How this website handles information you submit through it and information it records automatically. This is a website policy. It is not the notice that governs your medical record.

Not yet reviewed — do not launch as written

[This page is an unreviewed template. A healthcare attorney licensed in the state where you practise must read it against how your site is actually configured before it goes live. A privacy policy that describes data handling you do not actually do is worse than no policy at all: it is a written, published misstatement, and both the FTC Health Breach Notification Rule and California's UCL treat an inaccurate privacy representation as an independent violation, separate from any underlying data problem. Every factual statement below must be verified against your real hosting, form and mail stack, not assumed.]

[Also confirm with counsel whether your practice meets the CCPA/CPRA applicability thresholds at all. Most solo and small psychiatric practices do not, and PHI held by a HIPAA covered entity is separately exempt. Publishing an expansive CCPA rights section you are not equipped to honour within the statutory response windows creates an obligation you would not otherwise have had.]

1. What this policy covers

This policy applies to mybrainstimulation.com and to information collected through this website. It describes what the site collects, how that information moves, who can read it, and how long it is kept.

This policy does not cover protected health information held in the clinical record. Information you provide once you are a patient — your history, assessments, notes, prescriptions, correspondence with the practice — is governed by the Notice of Privacy Practices and by state medical confidentiality law, which are more protective and more specific than anything on this page. Where the two documents overlap, the Notice of Privacy Practices controls.

2. Information you give us

The contact form on this site collects the following fields. The first four are required — the form will not submit without them.

  • First name. Required.
  • Last name. Required.
  • Email. Required, so a reply can reach you.
  • Phone. Required. A phone number is not optional on this form.
  • "How did you hear about the practice?" Optional. A dropdown with fixed choices: referred by a physician or therapist; referred by a friend or family member; web search; professional or specialty directory; a talk, paper, or media piece; something else.
  • "Are you inquiring for yourself or someone else?" Optional. A dropdown with fixed choices: for myself; for a family member or someone I care for; I am a clinician referring a patient; something else.
  • Message. Optional free text.

The form also carries one hidden field, labelled "Company", which is not shown to you and which you cannot fill in. It exists only to catch automated submissions: it is sent to the practice's form endpoint along with the fields above, and if it arrives with anything in it the submission is discarded as spam and no message is delivered. Its contents are never included in the email sent to the practice.

The message field is free text, which means you control what enters it. Please keep it brief and administrative. You do not need to describe symptoms, diagnoses, medications or history in order to ask whether the practice is taking new patients or how to arrange a consultation, and you should not.

[Re-verify this list against the live contact form on every deploy, field by field, and update it the same day the form changes. Open contact.html, read every name="..." attribute and every required attribute, and confirm that each one appears above with its true required/optional status — including hidden and honeypot fields, which are still transmitted. If you add a preferred-time selector, an insurance question, a reason-for-contact dropdown or a file upload, it goes in this list before it goes live. Regulators and plaintiffs compare the live form to the policy field by field, and an undisclosed collected field, or a required field described as voluntary, is the easiest discrepancy in the world to find.]

This form is not a secure medical channel

Messages sent through this website travel over ordinary email infrastructure and are not encrypted end to end. They may be stored on servers operated by third-party vendors and may be readable by those vendors. Do not send confidential health information, clinical details, medication lists, records, or anything you would not want disclosed through this form or by email.

Sending a message does not create a physician–patient relationship, does not constitute a request for treatment, and is not monitored continuously. If you are in crisis or thinking about harming yourself, call or text 988 (Suicide & Crisis Lifeline), call 911, or go to your nearest emergency department.

3. Information collected automatically

Like nearly all websites, this site's hosting infrastructure records ordinary server log data when a page is requested. That typically includes the IP address the request came from, the date and time, the page or file requested, the referring page if there is one, and the browser and operating system reported by your device. It is used to keep the site running, diagnose errors, and identify abusive traffic.

This site also loads its typefaces from Google Fonts. That means your browser makes a request to Google's servers on each page load, and Google receives your IP address as part of that request. The practice does not control what Google does with it. No analytics, advertising, or tracking scripts are used.

[If you would rather no third party saw visitors' IP addresses at all, the fonts can be self-hosted: download the Playfair Display, Libre Caslon Text and Inter files into assets/fonts/, replace the Google Fonts <link> in the <head> of every page with local @font-face rules in style.css, and drop fonts.googleapis.com and fonts.gstatic.com from the Content-Security-Policy in _headers. Then delete the paragraph above. This is a genuine improvement for a medical site and takes about an hour.]

[Name your host and confirm how long it retains raw request logs and IP addresses, and whether you or only the host can access them. Cloudflare, Netlify, Vercel and traditional shared hosts all differ, and several retain logs longer than a small practice would guess. If you cannot state the retention period, say so plainly here rather than guessing at a number.]

Analytics

[As written, this site loads no analytics, no tag manager, no advertising pixel and no session-recording script. If that is still true at launch, replace this placeholder with: "This site uses no analytics, advertising or tracking scripts." If you add anything — Google Analytics, Plausible, Fathom, Meta Pixel, a chat widget, a scheduling embed — you must name it here and say what it collects. A tracking pixel on the pages of a healthcare provider is the exact fact pattern behind the recent wave of FTC actions and class claims over pixel-based disclosure of health-seeking behaviour; if you are minded to add one, raise it with counsel first, not after.]

4. How contact-form submissions are transmitted, stored and read

When you submit the contact form, your browser sends the fields to an endpoint on this site, which relays the message to the practice's mailbox. From that point the message is an email: it is stored in the practice's mail system and is subject to that provider's security, retention and access controls.

[Describe your actual pipeline in one paragraph and in plain language: which endpoint receives the POST, which transactional mail service relays it (Resend, Postmark, SendGrid, SES, etc.), which mailbox it lands in, and whether any copy is written to a database, spreadsheet, CRM or log along the way. Copies you have forgotten about are the ones that surface in discovery.]

[State who can read submissions. If it is only you, say "Only Dr. Pellionisz has access to the practice mailbox." If an assistant, biller, virtual receptionist or answering service has access, say so and count them — patients are entitled to know how many people see what they write, and understating it is a misrepresentation.]

5. Cookies and similar technologies

[Do not publish a cookie statement until you have opened the browser's storage inspector on the live site and looked. State "This site sets no cookies and uses no local storage" only if that is what you observed after all third-party embeds are in place. Fonts loaded from Google, an embedded map, a scheduling iframe or a video player each set their own storage and each turns a no-cookie claim into a false one. If any exist, list them by name and purpose and ask counsel whether a consent banner is required for your audience.]

6. Third-party service providers

The practice uses outside vendors to host this site and to deliver mail. Those vendors process information only as needed to provide their service.

[List every processor that touches website data — hosting, DNS/CDN, form endpoint, transactional email, mailbox, and any scheduling or portal vendor — with a one-line description of what each one handles. For each, record separately whether a Business Associate Agreement is in place. A BAA is required for any vendor that may handle PHI on your behalf; if a patient types clinical detail into an unBAA'd contact form, the gap is yours to answer for. If no BAA exists for the form pipeline, that is an argument for keeping the form strictly administrative and saying so louder, not for quietly leaving this section vague.]

[This site currently loads web fonts from Google's servers, which means a visitor's IP address reaches Google on every page load. That is a documented friction point under EU law and an increasingly common complaint in US privacy suits. Either disclose it here explicitly or, cleaner, self-host the two font families and delete this placeholder.]

7. How long information is kept

[State a retention period for website contact-form messages and hold to it. Two distinct questions: (1) how long do you keep an inquiry from someone who never became a patient, and (2) what happens to an inquiry from someone who does become a patient — most practices should move it into the clinical record, where medical-record retention governs instead. Check the retention rule that actually applies to you before you write a number here: California's seven-year statutory minimum in Health & Safety Code 123145 is written for clinics and licensed health facilities, and there is no equivalent general statute for an individual physician in private practice, where seven years is a Medical Board recommendation rather than a floor. Your malpractice carrier and your own counsel may both want longer. A stray inquiry email sitting in a mailbox for a decade is retention by accident, not by policy.]

8. How information is protected

This site is served over HTTPS, so traffic between your browser and the site is encrypted in transit. No method of transmission or storage is perfectly secure, and no website can promise that information sent over the internet will never be intercepted or accessed without authorisation. That limitation is the reason for the warning in section 2.

9. Your choices

You are not required to use the contact form. You may reach the practice by [phone, or another route you actually offer and monitor — name it, and do not list a channel you do not check] instead. If you have already sent a message and want it deleted, you may ask, and it will be deleted unless it has become part of a medical record or must be kept for a legal reason.

10. California privacy rights

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives California residents rights over personal information that businesses subject to the Act collect about them. Where those rights apply to information collected through this website, they include:

  • Right to know. To request the categories and specific pieces of personal information collected, the sources, the business purpose for collecting it, and the categories of third parties it is disclosed to.
  • Right to delete. To request deletion of personal information collected from you, subject to exceptions — including information that must be retained to complete a transaction, to comply with a legal obligation, or that forms part of a medical record.
  • Right to correct. To request correction of inaccurate personal information.
  • Right to opt out of sale or sharing. The practice does not sell personal information and does not share it for cross-context behavioural advertising. [This sentence is only true while the site carries no advertising or analytics pixel. Adding one may constitute "sharing" under the CPRA even with no money changing hands, which would in turn require a "Do Not Sell or Share My Personal Information" link in the site footer. Re-check this line whenever you add a script.]
  • Right to limit use of sensitive personal information. Information concerning health is sensitive personal information under the CPRA.
  • Right to non-discrimination. You will not be denied service, charged a different price, or given a different quality of care for exercising these rights.

Important limit: personal information that is protected health information held by a HIPAA covered entity, and medical information governed by California's Confidentiality of Medical Information Act, is exempt from the CCPA. In practice that means these website rights reach website data, while your clinical information is governed by the stronger protections described in the Notice of Privacy Practices.

To exercise a right, contact the practice using the details in section 13. You will be asked to verify your identity before a request is fulfilled, and an authorised agent may make a request on your behalf with written permission. [Verification method and response timeframe. The CCPA response window is 45 days, extendable once. Decide now how you will verify a requester by email alone without collecting more sensitive data than the request itself, and write that method here.]

11. Children's privacy

This website is intended for adults. It is not directed to children, and the practice does not knowingly collect personal information through this site from a child under 13. If you believe a child has submitted information through this site, contact the practice and it will be deleted.

[If you see adolescents clinically, note that separately — the website policy stays as written, but California grants minors independent consent and confidentiality rights for certain mental-health services, and how you handle a parent's inquiry about a minor patient is a clinical-record question for the HIPAA notice, not this page.]

12. Changes to this policy

This policy may be updated as the website changes. When it is, the "last updated" date at the top of this page will change. Material changes will be described here rather than made silently. Continued use of the site after an update means the revised policy applies to information collected from that point on.

13. Contact

Questions about this policy, or requests relating to information collected through this website, may be directed to:

  • [Practice legal name — the entity that actually operates the site, matching your business registration and the footer.]
  • [Practice mailing address for privacy correspondence. If you do not want a home or clinical address published, use a registered agent or a mail-forwarding address, but a published policy does need a reachable postal route.]
  • [Practice email address on the practice domain — not ppellionisz@stanford.edu. A university address on a private-practice privacy policy blurs the line between your academic role and the treating entity, and Stanford's IT and compliance teams have a claim on anything sent there.]
  • [Practice phone number for privacy inquiries, if different from the main line.]
Related

Your medical record is governed by the Notice of Privacy Practices. Use of this website is governed by the Terms of Use. Accessibility is addressed in the Accessibility Statement.