Privacy Policy
1. Overview
This Privacy Policy describes how Scottsdale Med Spa (“we,” “us,” or “our”) collects, uses, stores, and protects personal information and protected health information (“PHI”) obtained through our website, clinical services, consultations, and communications.
Scottsdale Med Spa is a medical aesthetic practice. Certain services provided are considered medical in nature and are subject to federal healthcare privacy laws, including the Health Insurance Portability and Accountability Act (HIPAA), as updated to align with 42 CFR Part 2.
2. Information We Collect
We may collect information you voluntarily provide, including but not limited to:
-
Contact details (name, email address, phone number)
-
Appointment and scheduling information
-
Medical history and intake information
-
Treatment and clinical records
-
Payment and billing information
-
Website usage data via cookies or analytics tools
Information is collected through our website, electronic forms, phone calls, email, text messages, and in-office interactions.
3. How We Use and Share Information
We use your information for purposes including:
-
Providing treatment and clinical care
-
Scheduling appointments and follow-up
-
Payment and healthcare operations
-
Internal quality improvement
-
Compliance with legal and regulatory requirements
We may share information as permitted by law with healthcare providers, service partners, billing entities, or technology vendors who support our operations. We do not sell or lease your personal or health information.
4. HIPAA & 42 CFR Part 2 — Consent and Care Coordination
Under federal law, including HIPAA and updated 42 CFR Part 2 regulations, Scottsdale Med Spa may use and disclose your protected health information for Treatment, Payment, and Healthcare Operations (“TPO”) using a single general consent, unless a more restrictive law applies.
Certain sensitive health information, including information that may relate to substance use disorder history, is subject to additional confidentiality protections under federal law. Such information will not be used or disclosed in legal proceedings without your written consent or a qualifying court order.
Redisclosure Notice:
When your information is shared with another healthcare provider or organization for care coordination, the receiving party may not be bound by the same federal confidentiality standards that apply to Scottsdale Med Spa. You may request restrictions on certain disclosures where permitted by law.
5. Your Rights
You have the right to:
-
Request access to or copies of your records
-
Request corrections to your information
-
Request limits on certain uses or disclosures
-
Receive an accounting of disclosures
-
Revoke previously granted authorizations
Requests may be submitted by contacting us using the information below.
6. Biometric Data & Medical Imaging
We may collect high-resolution facial photography, clinical images, and digital imaging used for treatment planning, documentation, and outcome evaluation. By providing this information, you give explicit consent for its use in connection with your care.
We do not sell or lease biometric or photographic data. Images are stored securely and used only for authorized clinical or operational purposes.
7. Data Security & Communication Risks
We use administrative, technical, and physical safeguards designed to protect your information. However, no system is completely secure.
-
Email and SMS messages are not encrypted.
-
If you choose to receive appointment reminders, updates, or non-urgent communications via email or text, you acknowledge and accept the risk of potential third-party interception.
-
Third-party platforms used for scheduling, communication, or marketing may have their own privacy practices.
8. Marketing & Non-Clinical Communications
If your information is used for marketing, newsletters, or promotional communications, you have a clear right to opt out at any time.
You may unsubscribe using links provided in emails or by contacting us directly. Opt-out requests will be honored promptly.
9. Cookies & Website Tracking
Our website may use cookies and analytics tools to improve functionality, understand usage patterns, and enhance user experience. You may adjust your browser settings to limit or block cookies, though some site features may be affected.
10. Policy Updates
We may update this Privacy Policy periodically to reflect changes in legal requirements, clinical practices, or operational procedures. Updates will be posted with a revised effective date.
11. Contact Information
If you have questions about this Privacy Policy or believe your privacy rights have been violated, please contact:
Scottsdale Med Spa
7045 E 3rd Ave
Scottsdale, AZ 85251
Phone: (480) 454-6959
Email: [email protected]
Arizona-Specific Compliance Notice
Scottsdale Med Spa complies with applicable Arizona healthcare and privacy laws, including A.R.S. § 12-2292 et seq., which governs the confidentiality of medical records and patient access rights. Under Arizona law, medical records are confidential and may only be disclosed as permitted by law or authorized by the patient.
Patients have the right to request access to their medical records, and such requests will be fulfilled within the timeframes required by Arizona and federal law.
In the event of a data security incident involving personal information, Scottsdale Med Spa complies with Arizona data breach notification requirements (A.R.S. § 18-552 et seq.), which may require notification to affected individuals and, where applicable, state authorities.
Arizona does not currently have a comprehensive consumer privacy statute comparable to the California Consumer Privacy Act (CCPA). Accordingly, healthcare privacy obligations applicable to Scottsdale Med Spa are primarily governed by HIPAA, federal regulations, and Arizona medical confidentiality laws, rather than a standalone Arizona consumer privacy act.


