Text size:

Monday to Friday, 8:30 to 5:00 · A nurse answers

Website privacy policy

Route built, content not written. This page is excluded from the sitemap and set to noindex. It cannot publish until counsel review is confirmed by ACHS. Every page needs a named approver before it goes live — DCH General Services §605.1.28 makes each published version a retained advertising record.

A website privacy policy explains what a site collects from visitors, how it is measured, what happens to information sent through a form, how long it is kept and how to have it deleted. It is separate from the HIPAA Notice of Privacy Practices. This policy is in preparation and not yet in effect.

Status

This document has not been drafted, has not been reviewed by counsel, and is not in effect. Nothing on this page is an operative policy or a statement of current practice.

What this document must cover

This is the website-specific policy. It must not be conflated with the Notice of Privacy Practices, which is the HIPAA document governing protected health information.

The drafted policy must state, accurately and specifically:

  • What the site collects automatically. Server logs, IP handling, and what the hosting provider retains, with retention periods.
  • Analytics. The specific tool in use, that it is cookieless and does not track individuals across sites, what it measures, where the data is processed, and how long it is held. If the implementation ever stops being cookieless, this section and the consent position both change.
  • Cookies, or their absence. A plain statement of what is set in the browser, including anything stored for the text-size control in the top bar. If nothing tracking is set, say so and explain why no consent banner appears.
  • Forms. Which forms exist, which fields are required, where submissions are sent, who can read them, and how long they are retained before deletion.
  • The processor. That form submissions pass through a third-party processor operating under a Business Associate Agreement, with the categories of data covered. Confirm the executed BAA before publishing this sentence.
  • The instruction not to send health information. Stated plainly and early: the website is not the route for diagnoses, medications, Medicaid numbers or clinical detail, and anything outside the secure route should not carry them.
  • Deletion and access. How a person asks for their submitted information to be deleted or provided to them, who handles the request, and the timescale.
  • Third parties. Embedded content, fonts, maps or scripts loaded from other domains, or a statement that there are none.
  • Changes, an effective date, and a contact route consistent with site config rather than hard-coded into the page.

Questions people ask about this

Should health information be sent through this website?

No. Do not include diagnoses, medications, Medicaid numbers or other health details in a general web form or an email. Give a name and a way to be reached, and the conversation can continue through a route appropriate for health information.

Does this site use cookies or a consent banner?

The site is built to use cookieless analytics that do not identify individual visitors, which is why no consent banner appears. The final policy will state exactly what is measured, by what tool, and what is stored in the browser, if anything.

Is this the same as the Notice of Privacy Practices?

No. This policy covers the website. The Notice of Privacy Practices is a HIPAA document covering protected health information held by the agency. Both exist, and neither replaces the other.

Related questions