HIPAA Website Privacy Policy
Effective Date: April 12, 2026
Websites Covered
This policy applies to all content and forms on the following websites:
This includes all subdomains, online scheduling pages, contact forms, and integrated tools.
Use of the Websites
Our websites allow users to:
- Request or book appointments
- Enroll in our Dental Wellness Plan
- Contact our team
- Learn about services and providers
- Access new patient forms and patient portals
We do not collect or store detailed medical records or treatment history through general website use.
Collection of Information
We may collect:
- Contact details you voluntarily submit (name, date of birth, address, email, phone)
- Insurance information you provide when booking an appointment
- Payment method information when enrolling in the Dental Wellness Plan (handled by Stripe; we do not store full card numbers)
- Technical data such as browser type, IP address, and visited pages
No Protected Health Information (PHI) beyond what you voluntarily submit through our forms is stored. PHI submitted through our forms is encrypted in transit and at rest.
Protected Health Information (PHI)
PHI includes any health-related data that identifies you. When you submit information through our online appointment booking, wellness plan enrollment, or contact forms, that information is encrypted, securely transmitted, and stored or transferred to our practice management systems in compliance with HIPAA regulations.
Use and Disclosure of PHI
Your PHI may be used for:
- Scheduling and treatment coordination
- Billing and insurance verification
- Internal operations and patient support
- Sending you appointment reminders and confirmations
We do not sell or share your PHI for marketing purposes without written authorization.
Services We Use
We use the following first-party and third-party services in connection with our websites and patient communications. Each service we use for PHI handling is HIPAA-compliant and is subject to a Business Associate Agreement (BAA) where required.
- AP Dental Online Booking — first-party appointment booking system that we built and host. It collects name, date of birth, contact details, and insurance information when you book an appointment, and submits this data directly to our practice management system (Dentrix Ascend).
- AP Dental Wellness Portal — first-party member self-service portal for our Dental Wellness Plan, allowing members to view their plan, manage payment, and update household members.
- Dentrix Ascend — HIPAA-compliant cloud-based practice management system used for patient scheduling, charting, billing, and treatment coordination.
- Stripe — PCI DSS Level 1 payment processor used for Dental Wellness Plan membership payments. Stripe handles all card data; we do not store full card numbers.
- Mailgun — transactional email delivery service used for appointment confirmations, membership notifications, and account-related emails.
- Twilio — transactional SMS delivery service used for appointment reminders and two-factor verification codes.
Cookies, Analytics, and Email Tracking
Website analytics: We use Google Analytics 4 (GA4) to understand how visitors use our websites. GA4 collects anonymized session data (pages visited, device type, general location, referrer) and does not collect or store PHI. You may disable cookies in your browser settings to opt out.
Marketing email tracking: When we send you marketing or appointment-related emails, we may track whether you opened the email and which links you clicked, using our self-hosted Mautic marketing platform. This information is used solely to improve email relevance and the quality of our patient communications, and is not shared externally. You may unsubscribe from marketing emails at any time using the link at the bottom of any marketing message.
Advertising: We use Google Ads and Google Tag Manager to measure the effectiveness of advertising campaigns. These tools use cookies but do not collect PHI.
Your HIPAA Rights
You have the right to:
- Request access to your health records
- Request corrections
- Request a list of disclosures
- Request communication preferences
- File a privacy-related complaint
Contact us below to exercise your rights.
Data Security Measures
We use administrative, technical, and physical safeguards including:
- SSL/TLS encryption for all website traffic
- Encrypted data transmission to and from our practice management systems
- HIPAA-compliant hosting and Business Associate Agreements with applicable third-party services
- User authentication and access controls for staff systems
- Ongoing security audits and compliance monitoring
Contact — HIPAA Privacy Officer
AP Dental Center — Privacy Officer
231 Border Street, Boston, MA 02128
Phone: 617-315-1515
Email: compliance@ap.dental
Policy Updates
This policy may be updated periodically. Any changes will be posted on ap.dental and apdentalcenter.com with an updated effective date.
Disclaimer
This policy is provided for informational purposes and describes how AP Dental Center handles website-collected information in compliance with HIPAA. For our full Notice of Privacy Practices required under HIPAA, please contact our Privacy Officer above.