Website privacy policy
noindex.
It cannot publish until counsel review is confirmed by ACHS. Every page needs a named approver before it goes live — DCH General Services §605.1.28 makes
each published version a retained advertising record.
A website privacy policy explains what a site collects from visitors, how it is measured, what happens to information sent through a form, how long it is kept and how to have it deleted. It is separate from the HIPAA Notice of Privacy Practices. This policy is in preparation and not yet in effect.
Status
This document has not been drafted, has not been reviewed by counsel, and is not in effect. Nothing on this page is an operative policy or a statement of current practice.
What this document must cover
This is the website-specific policy. It must not be conflated with the Notice of Privacy Practices, which is the HIPAA document governing protected health information.
The drafted policy must state, accurately and specifically:
- What the site collects automatically. Server logs, IP handling, and what the hosting provider retains, with retention periods.
- Analytics. The specific tool in use, that it is cookieless and does not track individuals across sites, what it measures, where the data is processed, and how long it is held. If the implementation ever stops being cookieless, this section and the consent position both change.
- Cookies, or their absence. A plain statement of what is set in the browser, including anything stored for the text-size control in the top bar. If nothing tracking is set, say so and explain why no consent banner appears.
- Forms. Which forms exist, which fields are required, where submissions are sent, who can read them, and how long they are retained before deletion.
- The processor. That form submissions pass through a third-party processor operating under a Business Associate Agreement, with the categories of data covered. Confirm the executed BAA before publishing this sentence.
- The instruction not to send health information. Stated plainly and early: the website is not the route for diagnoses, medications, Medicaid numbers or clinical detail, and anything outside the secure route should not carry them.
- Deletion and access. How a person asks for their submitted information to be deleted or provided to them, who handles the request, and the timescale.
- Third parties. Embedded content, fonts, maps or scripts loaded from other domains, or a statement that there are none.
- Changes, an effective date, and a contact route consistent with site config rather than hard-coded into the page.
Questions people ask about this
Should health information be sent through this website?
No. Do not include diagnoses, medications, Medicaid numbers or other health details in a general web form or an email. Give a name and a way to be reached, and the conversation can continue through a route appropriate for health information.
Does this site use cookies or a consent banner?
The site is built to use cookieless analytics that do not identify individual visitors, which is why no consent banner appears. The final policy will state exactly what is measured, by what tool, and what is stored in the browser, if anything.
Is this the same as the Notice of Privacy Practices?
No. This policy covers the website. The Notice of Privacy Practices is a HIPAA document covering protected health information held by the agency. Both exist, and neither replaces the other.
Related questions
- Notice of Privacy Practices The HIPAA Notice of Privacy Practices describing how health information is used and disclosed. This document is in preparation and is not yet in effect.
- Terms of use The terms governing use of this website, including that its content is general information and not medical advice. This document is in preparation and is not yet in effect.