Effective Date:  September 1, 2026

🔍 Understanding This Policy in Plain Language

This policy explains how we collect and use personal information when you visit our website, request an appointment, or interact with us outside of your treatment. It does not cover your medical records or protected health information – that is governed by our separate Notice of Privacy Practices.

We never use your health information for advertising or marketing

We do not sell your personal information. 

We may disclose limited information (such as browsing activity on our Site) to advertising or analytics partners only after you give affirmative consent through our cookie preference center. We treat Global Privacy Control (GPC) and other qualifying opt-out preference signals as valid requests to opt out of sale and sharing, which override prior consent for that browser or device.

You can opt out of sharing at any time

If you are a patient, your medical records and treatment information are handled under HIPAA and our Notice of Privacy Practices, not this policy. 

1. Scope — and What This Policy Does Not Cover

This Privacy Policy explains how ClinIVoy LLC and its affiliates (collectively, “ClinIVoy,” “we,” “us,” or “our”) collect, use, disclose, and retain personal information when you visit https://clinivoy.com/ (the “Site”), contact us, request an appointment, submit a form, apply for a job, or otherwise interact with us outside of the treatment relationship (collectively, the “Services”). ClinIVoy LLC is the “business” under Cal. Civ. Code § 1798.140(d) for the personal information described in this Policy. ClinIVoy LLC operates the Site and provides management, administrative, and technology services. Infucare Medical Group of California, a Professional Medical Corporation, d/b/a ClinIVoy Medical Group is a separate professional medical corporation that provides all clinical services and is the HIPAA covered entity responsible for your medical records. With respect to PHI, ClinIVoy LLC acts as a business associate of ClinIVoy Medical Group under a written business associate agreement and does not determine the purposes or means of processing PHI for its own account.

IMPORTANT — This Policy Does Not Cover Your Medical Records

This Policy does not apply to protected health information (“PHI”) governed by the Health Insurance Portability and Accountability Act (“HIPAA”) or to medical information governed by California’s Confidentiality of Medical Information Act, Civil Code § 56 et seq. (“CMIA”).

Information created or received about you as a patient of Infucare Medical Group of California, a Professional Medical Corporation, d/b/a ClinIVoy Medical Group in connection with your treatment, payment for treatment, or our health care operations is governed exclusively by the ClinIVoy Medical Group Notice of Privacy Practices, available at https://clinivoy.com/notice-of-privacy-practices  and at each of our centers.

California law expressly excludes such information from the California Consumer Privacy Act. Cal. Civ. Code § 1798.145(c). If your question concerns your medical records, your treatment, or your bill, please refer to the Notice of Privacy Practices, not this Policy.

If information you provide through the Services later becomes part of your medical record — for example, a symptom, diagnosis, medication, or insurance detail you describe in an appointment request or referral form — that information is governed by the Notice of Privacy Practices from the point it is incorporated into your record, and this Policy no longer applies to it.

In addition, information in our possession that constitutes “medical information” under Civil Code § 56.05(j) — that is, individually identifiable information regarding your medical history or mental or physical condition or treatment — is governed by the CMIA whether or not it also qualifies as PHI and whether or not a treatment relationship has yet been established. Where information is subject both to this Policy and to the CMIA or HIPAA, we will apply the more protective standard.

Use of cookies, pixels, tags, SDKs, and similar technologies is described in our separate Cookie and Tracking Technologies Policy at https://clinivoy.com/cookie-policy/ which is incorporated into this Policy by reference.

This Policy does not describe the practices of third parties we do not control, including your health plan, your referring physician, or any third-party website you reach through a link on the Site. We are not responsible for the privacy practices of those third parties; we encourage you to read their privacy policies.

2. Personal Information We Collect

We collect the categories of personal information described below. The categories track those enumerated in Cal. Civ. Code § 1798.140(v).

Category

What We Collect

Sources

Purposes

Disclosed To

Retention

A. Identifiers (Civ. Code § 1798.140(v))

Name, postal address, email address, telephone number, IP address, unique online identifiers, account name

You; your referring provider; your health plan; automatically from your device

Respond to inquiries; schedule appointments; verify insurance; site security; marketing where permitted

Service providers (hosting, email, scheduling, CRM); affiliates

Inquiry, appointment-request, and referral records not incorporated into a medical record: [24] months after your last interaction. Account records: life of the account plus [12] months. Records needed to establish, exercise, or defend legal claims: the applicable statute of limitations.

B. Customer records information (Civ. Code § 1798.80(e))

Name, signature, address, telephone number, insurance information, financial account information used for payment

You; your health plan

Billing and payment; insurance verification; fraud prevention

Billing and Payment processor; service providers

Billing and payment records: [7] years from the transaction date, consistent with applicable tax, audit, and limitations periods. Payment card data is not retained after the transaction is processed.

C. Protected classification characteristics

Age, date of birth; other characteristics only where you volunteer them

You

Identity verification; eligibility; legal compliance

Service providers; affiliates

Only as long as needed for the verification, eligibility, or compliance purpose for which you provided it, and no longer than the related Category A or B record.

D. Commercial information

Services inquired about or received (non-PHI), payment records

You; your interactions with the Site

Provide and improve the Services; billing

Service providers

[24] months after the inquiry or transaction; longer where required for billing, audit, or legal claims.

E. Biometric information

We do not collect biometric information. If identity verification requires a facial match, our vendor performs the match and deletes the image; we do not retain it. We require that vendor to delete the image immediately after the match and not retain or use it for any other purpose.

N/A

N/A

N/A

Not retained by ClinIVoy. Any facial-match data is held by our identity-verification vendor under its own schedule and deleted after the match is completed.

F. Internet or network activity

Browsing history on the Site, search history on the Site, pages viewed, referring URL, interaction with our advertisements, device and browser type

Automatically, via cookies and similar technologies (see Cookie Policy)

Operate and secure the Site; analytics; measure marketing

Analytics and advertising vendors, subject to your consent

Analytics and web logs: [12–26] months. Consent and opt-out records: [24] months, to demonstrate compliance. Longer where required by law.

G. Geolocation data

Approximate location inferred from IP address; center-locator queries

Automatically; you

Show you the nearest center; fraud prevention; analytics

Service providers; mapping provider

IP-derived approximate location is retained with the associated web log for [12–26] months. Center-locator queries are not retained in identifiable form.

H. Sensory data

Recordings of calls to our centers, where recording is disclosed to you and consented to. A recorded announcement at the beginning of the call informs you that the call may be recorded or monitored; your continued participation constitutes consent. Penal Code § 632.

You

Quality assurance; training; dispute resolution

Telephony service provider

Call recordings: up to [24] months for quality assurance, training, and dispute resolution; longer where required by law or needed for a pending claim.

I. Professional or employment information

Résumé, work history, education, references (job applicants)

You; references; background-check vendor

Evaluate applications; onboarding; legal compliance

Applicant tracking vendor; background-check vendor

Applicants not hired: [4] years from the application date. Employees and contractors: duration of the relationship plus [4] years.

J. Education information

Degrees, licenses, certifications (job applicants and clinicians)

You; licensing boards

Credentialing; employment

Credentialing vendor

Credentialing and licensure records: duration of the credentialing relationship plus [7] years, consistent with accreditation, licensing, and payer requirements.

K. Inferences

Preferences and characteristics derived from the above (marketing audiences only; we draw no clinical inferences outside the treatment record)

Derived

Marketing and Site personalization, subject to your consent

Marketing vendors

Marketing audiences and derived preferences: [24] months from creation, or until you withdraw consent or opt out, whichever is earlier.

L. Sensitive personal information

See Section 3 below

See Section 3

See Section 3

See Section 3

See Section 3. No longer than necessary for the permitted purposes in Cal. Civ. Code § 1798.121(a). Financial account information provided for a one-time payment is not retained after the payment settles.

2.1 Information We Do Not Knowingly Collect. We do not knowingly collect personal information from children under 13 through the Services. The Services are directed to adults. If you believe a child under 13 has provided personal information to us, contact us at Section 12 and we will delete it.

We do not sell and have not in the preceding twelve (12) months sold, the personal information of consumers under 16 years of age. If we were ever to sell or share the personal information of a consumer we know to be at least 13 and less than 16 years of age, we would do so only where that consumer has affirmatively authorized it, and for a consumer under 13 only where a parent or guardian has affirmatively authorized it. Cal. Civ. Code § 1798.120(c); 11 C.C.R. §§ 7070, 7071.

3. Sensitive Personal Information

“Sensitive personal information” under Cal. Civ. Code § 1798.140(ae) includes, among other things, a Social Security or other government identification number, financial account credentials, precise geolocation, racial or ethnic origin, contents of mail and messages, genetic data, biometric identifiers used for identification, personal information concerning health, and neural data. Most health information about you is PHI or CMIA-covered medical information and is therefore outside this Policy entirely (see Section 1).

Where we do collect sensitive personal information through the Services — for example, financial account information you provide to pay a bill, or a government identification number you provide for identity verification — we use and disclose it only for the purposes permitted by Cal. Civ. Code § 1798.121(a) and 11 C.C.R. § 7027(m), including but not limited to: performing the services or providing the goods reasonably expected by an average consumer who requests them, to prevent and investigate security incidents and fraud, to ensure physical safety, for short-term transient use, for internal service performance, and to verify or maintain quality. We also use sensitive personal information to resist malicious, deceptive, fraudulent, or illegal actions directed at us and to prosecute those responsible, and we may collect or process sensitive personal information where the collection or processing is not for the purpose of inferring characteristics about you. This description states the permitted purposes on which we currently rely and is not intended to be an exhaustive restatement of 11 C.C.R. § 7027(m).

Because we do not use or disclose sensitive personal information for purposes beyond those permitted purposes, we are not required to offer, and do not offer, a “Limit the Use of My Sensitive Personal Information” link. If that changes, we will update this Policy and provide the required link.

4. How We Use Personal Information

We use personal information to:

respond to your inquiries and requests, including appointment requests and referral submissions;

verify insurance eligibility and benefits, and process payments;

operate, maintain, secure, debug, and improve the Services;

detect, investigate, and prevent fraud, security incidents, and illegal activity;

send you administrative and transactional communications;

send marketing communications where you have consented or where permitted by law, and measure their effectiveness;

evaluate job applications and administer employment;

comply with legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims; and

carry out a merger, acquisition, financing, reorganization, or sale of assets, in which personal information may be among the assets transferred.

We will not use your personal information for a materially different, unrelated, or incompatible purpose without first providing you notice.

4.1 Automated Decision-Making. We do not use automated decision-making technology to make significant decisions about you — including decisions about the provision or denial of health care services, financial or lending services, housing, education, employment, or independent contracting opportunities — within the meaning of 11 C.C.R. § 7001. We do not engage in profiling that produces legal or similarly significant effects. If we begin to use automated decision-making technology to make a significant decision about you, or to conduct profiling that produces legal or similarly significant effects, we will update this Policy before doing so and will provide the pre-use notice, access right, and opt-out required by applicable law and regulation.

5. How We Disclose Personal Information

We disclose personal information to:

Service providers and contractors that process personal information on our behalf under written contracts meeting the requirements of Cal. Civ. Code § 1798.140(ag) and (j) — including website hosting, email delivery, appointment scheduling, customer relationship management, payment processing, telephony, analytics, and applicant tracking;

Affiliates, including ClinIVoy Medical Group, consistent with the restrictions in the Notice of Privacy Practices;

Professional advisors — lawyers, auditors, accountants, and insurers — under duties of confidentiality;

Government authorities and other parties when required by law, to comply with legal process, or to protect our rights, your safety, or the safety of others; and

A successor entity in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets.

5.1 Sale and Sharing. Under the CCPA, “sell” means disclosing personal information to a third party for monetary or other valuable consideration, and “share” means disclosing personal information to a third party for cross-context behavioral advertising, whether or not for money. We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising except where you have provided affirmative consent through our cookie preference center (or equivalent). Consent-based disclosures of limited browsing or device information to advertising or analytics partners are performed only in accordance with our Cookie and Tracking Technologies Policy and applicable law. We have not sold personal information and have not shared personal information for cross-context behavioral advertising without consent, in the preceding twelve (12) months.

5.2 Opt-Out Preference Signals. We honor the Global Privacy Control (“GPC”) and other browser-based opt-out preference signals that meet the requirements of 11 C.C.R. § 7025. When we receive such a signal, we treat it as a valid request to opt out of sale and sharing for that browser or device, and — if you are logged in to an account — for you as a consumer. A GPC or similar signal overrides any prior consent for that browser or device.

Confirmation. As required by the amended regulations effective January 1, 2026, we provide a means for you to confirm that your opt-out request, including one made through an opt-out preference signal, has been processed. 

Our cookie preference center and privacy-request page display a confirmation message (for example, “Your opt-out preference signal has been honored”) once the request is processed for that browser or device (and for a logged-in account, if applicable).

5.3 How to Opt Out — Homepage Link. Do Not Sell or Share My Personal Information” link. We provide a clear and conspicuous link on the homepage of the Site titled “Do Not Sell or Share My Personal Information,” which takes you to our cookie preference center, where you may withdraw consent to sharing for cross-context behavioral advertising. Cal. Civ. Code § 1798.135(a)(1); 11 C.C.R. § 7013.

5.4 “Do Not Track” Signals. Some browsers transmit a “Do Not Track” (“DNT”) signal. DNT is a different signal from the opt-out preference signals described in Section 5.2. Because no common industry or legal standard for responding to DNT signals has been adopted, the Site does not currently respond to them. We do honor the Global Privacy Control and other opt-out preference signals that meet the requirements of 11 C.C.R. § 7025, as described above. Bus. & Prof. Code § 22575(b)(5).

6. Your California Privacy Rights

If you are a California resident, you have the following rights under the CCPA, subject to verification and legal exceptions:

Right to know. Request the categories and specific pieces of personal information we collected about you; the categories of sources; the business or commercial purpose; the categories of third parties to whom we disclosed it; and the categories disclosed for a business purpose. Your request will cover personal information we collected on or after January 1, 2022, and is not limited to the twelve (12) month period preceding your request. The only exception is where providing information beyond that twelve-month period proves impossible or would involve disproportionate effort, in which case we will tell you why. Cal. Civ. Code § 1798.130(a)(2)(B).

Right to delete. Request deletion of personal information we collected from you, subject to the exceptions in Cal. Civ. Code § 1798.105(d). When we honor a deletion request, we will also direct our service providers and contractors to delete your personal information from their records and will notify any third parties to whom we have sold or shared it, unless an exception applies or doing so proves impossible or would involve disproportionate effort. Cal. Civ. Code § 1798.105(c).

Right to correct. Request correction of inaccurate personal information we maintain about you. In evaluating a correction request we will consider the totality of the circumstances relating to the contested information, including the nature of the information, how we obtained it, and any documentation you provide. You may submit documentation supporting the correction, and we will accept and consider it. If we deny your request, we will tell you the specific reasons for the denial, tell you whether we have instead deleted the contested information, and inform you that you may file a complaint with the California Privacy Protection Agency and the Attorney General. 11 C.C.R. § 7023.

Right to opt out of sale or sharing. See Section 5.1.

Right to limit use of sensitive personal information. See Section 3.

Right to non-discrimination. We will not deny you goods or services, charge you a different price, provide a different level of quality, or suggest that we will do any of these things, because you exercised a privacy right. Exercising a privacy right will never affect your medical care.

Right to no retaliation following opt-out, for employees and applicants.

Financial incentives. We do not offer any financial incentive, price or service difference, loyalty program, or other program that involves the collection, retention, use, or disclosure of personal information in exchange for a benefit. Cal. Civ. Code § 1798.125(b); 11 C.C.R. § 7016. If we offer such a program in the future, we will first provide the required notice of financial incentive, describe its material terms and the method we use to calculate the value of your personal information, obtain your opt-in consent, and allow you to withdraw at any time.

6.1 How to Exercise Your Rights

Online: https://clinivoy.com/privacy-request

Toll-free telephone: +1 844-243-7833

Email: [email protected]

Mail: Privacy Officer, ClinIVoy LLC, 17332 Von Karman Ave #110, Irvine, CA 92614 ]

Verification. We will verify your identity before responding, using information already in our possession, at a degree of certainty matching the sensitivity of the information requested. We will not use information you provide for verification for any other purpose.

Authorized agents. You may designate an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your written permission and may require you to verify your own identity directly with us, or to confirm the agent’s authority, except where the agent provides a valid power of attorney under Probate Code §§ 4000–4465.

Timing. We will confirm receipt within ten (10) business days and respond within forty-five (45) calendar days. If we need more time, we will notify you and may take up to an additional forty-five (45) days, for a maximum of ninety (90) days from receipt. Requests to opt out will be honored within fifteen (15) business days.

Fees. Responses are free, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act, and will explain why.

If we deny your request in whole or in part, we will explain the basis for the denial.

6.2 California “Shine the Light” — Civil Code § 1798.83. California residents may request information about our disclosure of personal information to third parties for those third parties’ direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes. To make a Shine the Light request, contact us as provided in Section 12.

6.3 Employees and Job Applicants. California employees, job applicants, and independent contractors have CCPA rights in the personal information we collect in that context. A separate Notice at Collection for Employees, Applicants, and Contractors is provided at or before the point of collection. That Notice at Collection is available at https://clinivoy.com/[employee-notice-at-collection] and is provided again at or before the point of collection. It describes the categories of personal information and sensitive personal information we collect in the employment context, the purposes for which each category is used, whether each category is sold or shared, and the retention period or the criteria used to determine it, as required by Cal. Civ. Code § 1798.100(a) and 11 C.C.R. § 7012. You may also request a copy by contacting us as provided in Section 12.

7. Residents of Other States

If you reside in a state with a comprehensive consumer privacy law — including Arizona, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others — you may have rights to access, correct, delete, and obtain a portable copy of your personal data, to opt out of targeted advertising, sale, and certain profiling, and to appeal a denial of a request. To exercise these rights, or to appeal a denial, contact us as provided in Section 12. We will respond within the time frames those laws require and will inform you of any appeal process available to you, including how to contact your state attorney general. As with California, information governed by HIPAA or CMIA is exempt from these state laws and is addressed in the Notice of Privacy Practices.

8. Data Security

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, destruction, use, modification, and disclosure. Where information is also PHI, those safeguards are designed to satisfy the HIPAA Security Rule, 45 C.F.R. Part 164, Subpart C. While no method of transmission over the internet or method of electronic storage can be guaranteed to be completely secure, we maintain administrative, technical, and physical safeguards designed to meet or exceed the requirements of applicable law, including the HIPAA Security Rule and Civil Code § 1798.81.5. You are responsible for maintaining the confidentiality of any credentials you use to access the Services and for securing your own devices.

Do not send us health information, Social Security numbers, or other sensitive information by unencrypted email or through a web form that is not identified as secure. If you need to communicate about your care, contact your center directly.

Breach notification. If a breach affecting your personal information occurs, we will notify you as required by Civil Code §§ 1798.29 and 1798.82 and, where applicable, by HIPAA and Health & Safety Code § 1280.15.

9. Data Retention

We retain each category of personal information for the period stated for that category in the table in Section 2, and thereafter only as necessary to comply with legal obligations, resolve disputes, and enforce our agreements. We do not retain personal information for longer than reasonably necessary for the disclosed purpose. Cal. Civ. Code § 1798.100(a)(3). Residual copies may persist in secure backups for the period set by our disaster-recovery schedule, after which they are overwritten. Category-specific retention schedules are maintained internally and are available upon request. The criteria we use to determine each retention period are: the length of time necessary to provide the Services you requested and to maintain our relationship with you; whether a legal, tax, audit, accreditation, or licensing obligation requires a longer period; whether the information is needed to establish, exercise, or defend legal claims, measured by the applicable statute of limitations; and whether you have asked us to delete the information and no exception applies. We do not retain personal information, including sensitive personal information, for longer than is reasonably necessary for the disclosed purpose. Cal. Civ. Code § 1798.100(a)(3); 11 C.C.R. § 7012(e)(3).

10. Third-Party Links and Social Media

The Site contains links to and embedded content from third-party services, including maps, review platforms, video, and social media. Those third parties may collect information about you directly, subject to their own privacy policies, and we do not control that collection. See the Cookie and Tracking Technologies Policy for how we obtain your consent before loading non-essential third-party content.

11. Changes to This Policy

We may update this Policy from time to time. We will post the revised Policy on the Site with a new “Last Updated” date. If we make a material change, we will provide additional notice — such as a banner on the Site or an email to you — before the change takes effect, and we will obtain your consent where required by law. We will not apply a material change retroactively to personal information already collected without providing notice and, where required, obtaining consent.

12. Contact Us

Privacy Officer
ClinIVoy LLC
17332 Von Karman Ave #110

Irvine, CA 92614
Phone: +1 844-243-7833
Email: [email protected]

For questions about your medical records or your care, contact your ClinIVoy Medical Group center or the Privacy Officer identified in the Notice of Privacy Practices.

Accessibility. If you need this Policy in an alternative format or need assistance exercising a privacy right because of a disability, contact us and we will provide it.

This Policy should be read together with the ClinIVoy Cookie and Tracking Technologies Policy and, if you are a patient, the ClinIVoy Medical Group Notice of Privacy Practices.

Effective Date: September 1, 2026

1. Purpose and Scope

This Policy explains how ClinIVoy uses cookies, pixels, tags, software development kits, session-replay tools, and similar technologies (collectively, “Tracking Technologies”) on https://clinivoy.com/and in our email communications. This Policy also applies to any subdomains, mobile applications we operate, and third-party booking or intake widgets embedded on our Site. It supplements, and is incorporated into, the ClinIVoy Website and Consumer Privacy Policy. This Policy applies to visitors to the Site wherever they are located. Where the comprehensive consumer privacy law of another U.S. state gives you rights concerning Tracking Technologies — including the right to opt out of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects — we honor those rights as described in Sections 4 and 5, and in Section 7 of the Website and Consumer Privacy Policy.

This Policy does not replace or limit the ClinIVoy Medical Group Notice of Privacy Practices (“NPP”). Information collected through Tracking Technologies may constitute protected health information (“PHI”) in certain circumstances and, when it does, will be handled in accordance with HIPAA and other applicable health-information privacy requirements. Information about your care that is maintained by ClinIVoy Medical Group as PHI is governed by the NPP. See Section 7 for the specific protections we apply where Tracking Technologies could otherwise collect, use, or disclose health information.

The privacy and security requirements applicable to Tracking Technologies may differ depending on whether a page or application is publicly accessible, requires authentication, permits submission of health or other personal information, or is operated by a third party. We apply safeguards based on the nature of the information and functionality involved.

For example, if you are signed in to a patient account and your activity on a clinical page is linked to your identity, that information may constitute PHI even though a Tracking Technology collected it, and it will be handled under HIPAA and the Notice of Privacy Practices rather than under this Policy. This is so whether or not you have an existing treatment relationship with us. Information in our possession that constitutes “medical information” under Civil Code § 56.05(j) is governed by the CMIA whether or not it also qualifies as PHI. Where information is subject both to this Policy and to HIPAA or the CMIA, we apply the more protective standard.

This Policy does not govern third-party websites, applications, or services that are linked to or embedded in the Site but are not operated by ClinIVoy. Those third parties may have their own privacy policies and terms.

🔍 Understanding This Policy in Plain Language.   We use small tools like cookies and pixels to make our website work, understand how it’s used, and show relevant information. We never use these tools to gather private medical information or for advertising on pages where you provide health details.

Strictly Necessary:These keep the site secure and functioning. They run automatically.

All Others:These are only turned on only after you give affirmative consent.  You can change your mind anytime.

Protecting Your Health Data:We apply strict controls (see Section 7) designed to keep health information out of advertising and analytics tools, and we monitor and audit to confirm those controls are working.

2. What Tracking Technologies Are

Cookies are small text files placed on your device by a website. First-party cookies are set by  com; third-party cookies are set by another domain, such as an analytics or advertising provider. Session cookies expire when you close your browser; persistent cookies remain for a set period.

Pixels, tags, and web beacons are small pieces of code or transparent images embedded in a page or email that signal to a server that content was loaded and can transmit information about your device and the page you viewed.

Local storage and software development kits (“SDKs”) may store, collect, or transmit information through your browser or application beyond the life of a cookie.

Fingerprinting is a technique that collects characteristics of a browser or device to create a distinctive identifier that may be used to recognize or track a device. We do not use fingerprinting to identify or track visitors to the Site, and our agreements with vendors prohibit the use of fingerprinting techniques in connection with the Site, including as a fallback when cookies are blocked, cleared, or unavailable. If that changes, we will identify the technology in Section 3 and treat it as requiring your consent

Session-replay and heat-mapping tools record how you move through a page.

3. Categories of Tracking Technologies We Use

3.1 Strictly Necessary — generally do not require consent

These technologies are reasonably necessary to operate the Site, provide functionality specifically requested by you, maintain security, or prevent fraud. They are not used for optional advertising or other purposes. They generally cannot be switched off through our preference center without affecting Site functionality.

Technology

Provider

Purpose

Duration

Information Collected

ClinIVoy session

ClinIVoy (first party)

Maintain your session

Session

Session identifier; no directly identifying information.

CF Clearance

Cloudflare

Detect and prevent malicious activity

30 minutes to 1 year, as configured by Cloudflare; currently [30 minutes]. We confirm this setting at each review under Section 3.7 and update this table if it changes.

IP address; browser and device characteristics; the result of the security challenge.

Cookie Consent

CookieYes

Remember your cookie choices

12 months

Your consent choices; a consent identifier; date and time; the version of the consent interface.

AWSALB

Amazon Web Services

Route traffic

Session (deleted when you close your browser)

Load-balancer routing identifier; IP address.

3.2 Functional — generally activated only after consent

Remember your preferences and enable optional enhanced features, such as the center locator and embedded maps. These technologies are activated only after you provide consent.

Technology

Provider

Purpose

Duration

Information Collected

NID

Google LLC

Remembers your preferences for Google services, such as display center locations and directions

6 months

Google-assigned device identifier; language and display preferences; approximate region.

ClinIVoy Preference

ClinIVoy

Remember language, location, display choices

12 months

The language, center, and display preferences you select; no directly identifying information.

maps.googleapis.com data

Google LLC

Necessary to load Google Maps functionality when you search for a location.

Session

IP address; approximate location; the location you search for.

    

‍

3.3 Analytics and Performance — consent required

Help us understand how the Site is used so we can improve it. We use these technologies only after obtaining consent where consent is required by applicable law or our consent practices.

Technology

Provider

Purpose

Duration

Information Collected

GA, GID

Google LLC

Aggregate usage measurement

_ga – [14] months; _gid – 24 hours. We have shortened the analytics identifier lifetime from the Google default of 2 years to the shortest period that still supports year-over-year usage measurement.

Pseudonymous device identifier; IP address (truncated where IP anonymization is enabled); pages viewed; referring URL; session timestamps; general device and browser information.

Hotjar

Hotjar Ltd.

User behavior analysis

1 year

Pseudonymous device identifier; pages viewed; clicks, scrolls, and mouse movement; device and browser information. Form fields containing personal information are masked.

3.4 Advertising and Cross-Context Behavioral Advertising — opt-in consent required

Used to deliver and measure advertising, including advertising shown to you on other websites and applications. These technologies involve the disclosure of personal information to third parties for advertising and cross-context behavioral advertising. These technologies load only after you give affirmative opt-in consent through the consent interface described in Section 4, and never before. They are used only in accordance with our Website and Consumer Privacy Policy and applicable law. We do not disclose PHI to advertising vendors. That disclosure constitutes a “sharing” of personal information as defined in Cal. Civ. Code § 1798.140(ah). We engage in it only where you have given affirmative consent, and you may withdraw that consent at any time. We do not sell personal information, and we have not sold personal information in the preceding twelve (12) months, as “sell” is defined in Cal. Civ. Code § 1798.140(ad). We receive no monetary or other valuable consideration for the disclosures described in this Section 3.4; they are made for advertising purposes only. Should that change, we will update this Policy and provide the opt-out rights and disclosures that Cal. Civ. Code § 1798.120 separately requires for a sale. You may exercise your right to opt out of sharing, and of any future sale, as described in Sections 4.1 and 4.4.

Technology

Provider

Purpose

Duration

Information Collected

fr, datr

Meta Platforms, Inc.

Ad delivery and conversion measurement

90 days

Pseudonymous advertising identifier; IP address; pages viewed on the Site; conversion events.

IDE, DSID

Google LLC

Ad delivery and remarketing

2 years

Pseudonymous advertising identifier; IP address; pages viewed; ad interactions and conversions.

LI SUGR

LinkedIn Corporation

Ad measurement

90 days

Pseudonymous browser identifier; IP address; ad interactions.

VISITOR_INFO1_LIVE

Google LLC

Video playback; ad delivery and remarketing where privacy-enhanced mode is not used

6 months

Pseudonymous device identifier; video playback preferences; and, where privacy-enhanced mode is not used, ad interaction data.

3.5 Why We Use Each Category, and the Basis for Using It

For each category above, the business or commercial purpose for which we collect and use the information, and the basis on which we do so, is as follows:

Strictly Necessary — to provide the Site and the security you have asked us for, to maintain your session, to route traffic, and to record your privacy choices. These are used without consent because they are reasonably necessary to deliver the service, and because recording your choice requires remembering it.

Functional — to remember preferences you have set and to enable optional features such as the center locator and maps. Used only with your consent.

Analytics and Performance — to measure how the Site is used in the aggregate so that we can improve it. Used only with your consent.

Advertising — to deliver and measure advertising, including advertising shown to you on other sites and applications. Used only with your affirmative opt-in consent, which you may withdraw at any time.

We do not use Tracking Technologies for any purpose that is materially different from, or incompatible with, the purposes stated here without first telling you and, where required, obtaining your consent. Cal. Civ. Code § 1798.100(a)(1); 11 C.C.R. § 7011.

3.6 How Long We Keep What These Technologies Collect

The Duration column above states how long a cookie or similar file remains on your device. That is different from how long we keep the information the technology collects. We retain that information as follows:

Strictly Necessary. Security and routing logs are retained for [90] days. Consent records are retained as described in Section 4.

Functional. Preference data is retained for as long as the preference remains set, and no longer than [12] months after your last visit.

Analytics and Performance. Event-level analytics data is retained for [14] months, after which it is deleted or retained only in aggregate form that cannot reasonably be linked to you. Session recordings are retained for [12] months.

Advertising. We do not retain advertising event data in identifiable form. Advertising partners retain the information they receive under their own retention schedules, which are described in their privacy policies and which we do not control.

We do not retain information collected through Tracking Technologies for longer than is reasonably necessary for the purpose stated in Section 3.5. Cal. Civ. Code § 1798.100(a)(3).

3.7 Where This Information Is Processed

We are located in the United States and process information here. Several of the providers listed above operate globally and may process or store information outside the United States: Google LLC and Meta Platforms, Inc. and LinkedIn Corporation maintain infrastructure in multiple countries, and Hotjar Ltd. is established in Malta and processes information in the European Union. Where a provider transfers information across borders, it does so under its own contractual and legal transfer mechanisms, which are described in its privacy documentation. Our agreements with these providers require them to protect the information they receive and to use it only as we permit.

3.8 Keeping This Section Accurate

Tracking Technologies change as vendors update their products. We review the tables and disclosures in this Section 3 at least quarterly, and whenever we add, remove, or reconfigure a Tracking Technology, and we update them when they no longer match what the Site actually does.

4. How We Obtain and Honor Your Consent

We do not place non-essential Tracking Technologies on your device before you consent. When you first visit the Site, a consent banner presents your choices. Non-essential technologies in the Functional, Analytics, and Advertising categories load only after you affirmatively accept them.

Our consent interface is designed to comply with 11 C.C.R. §§ 7004 and 7025:

“Accept All” and “Reject All” are presented with equal prominence — the same size, the same visual weight, and the same number of clicks. The interface also lets you accept or reject each category — Functional, Analytics, and Advertising — independently. Consent to one category is not consent to another, and you are never required to accept all categories in order to reject one. Cal. Civ. Code § 1798.140(h); 11 C.C.R. § 7004

Rejecting takes no more steps than accepting.

Closing or dismissing the banner is not consent. If you close the banner without choosing, only strictly necessary technologies load. See 11 C.C.R. § 7004(a)(2) (treating a banner that infers consent from dismissal as a dark pattern).

How often we ask. We re-present the consent interface only when you clear the cookies on your device, when your consent record reaches twelve (12) months, when we materially change the Tracking Technologies we use or the purposes for which we use them, or when you ask us to. We do not present the banner in order to repeat a request you have already declined. 11 C.C.R. § 7004(c).

You may change your choices at any time through the “Your Privacy Choices” link in the footer of every page and on our homepage. See Section 4.4. “[Cookie Preferences]” link in the footer of every page.

Withdrawing consent is as easy as giving it. Your choice regarding cookies or other Tracking Technologies does not constitute authorization under HIPAA for any use or disclosure of PHI.  We never use cookie consent as a substitute for a HIPAA authorization. Where a disclosure of PHI to a Tracking Technology provider requires a HIPAA authorization, ClinIVoy will obtain a separate, HIPAA compliant authorization from you before making the disclosure.

Records of your consent. We keep a record of each consent choice — the date and time, the categories you accepted or rejected, the version of the consent interface presented to you, and any later change or withdrawal — for at least five (5) years, so that we can demonstrate that consent was obtained and honored and so that we can respond to a question about your choices. These records are kept secure and are used only for privacy-compliance purposes. We chose five years because that is the period during which an enforcement action concerning the consent could be brought, and because the burden of showing that consent was obtained rests with us. Cal. Civ. Code § 1798.140(h); 11 C.C.R. §§ 7004, 7101.

4.1 Opt-Out Preference Signals and the Global Privacy Control

We honor the Global Privacy Control (“GPC”) and other qualifying opt-out preference signals as required by applicable California law. Where applicable, we treat a qualifying signal as a request to opt out of the sale or sharing of personal information and process the request without requiring you to take additional steps.  A GPC or similar signal overrides any prior consent for that browser or device. We honor opt-out preference signals in the same way for residents of every state whose law requires a business or controller to recognize a universal opt-out mechanism, including California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas. We apply one implementation everywhere rather than varying it by state, so a qualifying signal is treated as an opt-out from targeted advertising, the sale of personal data, and cross-context behavioral advertising regardless of where you live. Where a state’s law requires opt-in consent before personal data is processed for targeted advertising or before sensitive data is processed, we obtain that consent through the consent interface described in Section 4.

We provide a mechanism through which you may confirm whether your opt-out preference has been recognized and processed. You may also contact our Privacy Officer to confirm your opt-out status.

4.2 Do Not Track

We do not respond to browser “Do Not Track” signals because there is no commonly accepted industry standard governing how those signals should be interpreted. We do honor qualifying opt-out preference signals, such as the Global Privacy Control, as required by applicable law. This disclosure is provided under the California Online Privacy Protection Act, Bus. & Prof. Code § 22575(b)(5)–(6).

4.3 Third-Party Collection Across Sites

Third parties whose technologies are present on the Site, including analytics and advertising providers, may collect personal information concerning your online activities over time and across different websites when you visit the Site. We obtain consent before loading optional Tracking Technologies where consent is required, and we do not authorize those technologies to collect PHI from pages subject to the restrictions in Section 7.

4.4 Homepage Opt-Out Link

Because consent-based disclosures to our advertising partners constitute “sharing” of personal information under the CCPA, we provide the opt-out link required by Cal. Civ. Code § 1798.135(a). The “Your Privacy Choices” link appears in the footer of every page and on the homepage of the Site, is accompanied by the opt-out icon described in 11 C.C.R. § 7015, and opens the preference center, where you may withdraw consent to Analytics and Advertising Tracking Technologies. This is the same mechanism described in Section 5.3 of the Website and Consumer Privacy Policy — the two policies describe one link, not two. The “Your Privacy Choices” link is the alternative opt-out link permitted by 11 C.C.R. § 7015. A business that posts it is not required to post a separate “Do Not Sell or Share My Personal Information” link, and we do not post one; the single link satisfies Cal. Civ. Code § 1798.135(a) and also takes you to the controls described in Section 5.

5. How to Control Tracking Technologies

Beyond our preference center, you may:

Adjust browser settings to block or delete cookies. Instructions: Chrome, Safari, Firefox, Edge.. Blocking strictly necessary cookies may prevent parts of the Site from working.

Install an opt-out preference signal, such as a browser or extension that transmits the GPC.

Use industry opt-outs: the Digital Advertising Alliance at https://optout.aboutads.info/, the Network Advertising Initiative at https://optout.networkadvertising.org/. These are cookie-based and must be reset if you clear cookies or change devices.

Opt out of Google Analytics using Google’s browser add-on at https://tools.google.com/dlpage/gaoptout.

Use your device’s advertising controls, including “Limit Ad Tracking” (iOS) and “Opt out of Ads Personalization” (Android).

The availability and effect of third-party opt-out tools may vary by browser, device, technology, and provider. Use of a third-party opt-out tool does not limit any rights or controls available through our preference center or under applicable law.

Children. The Site is not directed to children under 13, and we do not knowingly deploy Tracking Technologies to collect personal information from a child under 13. If we learn that we have collected personal information from a child under 13 through a Tracking Technology, we delete it. Because a health care site may be visited by a patient or a family member under 18, we also apply the following to any visitor we know or estimate to be under 18: non-essential Tracking Technologies default to off and are not activated by an “Accept All” selection; we do not use Tracking Technologies to build an advertising profile of that visitor or to deliver cross-context behavioral advertising to them; and we do not sell or share their personal information. See the Website and Consumer Privacy Policy for our full statement concerning children’s information. 15 U.S.C. §§ 6501–6506; Cal. Civ. Code §§ 1798.120(c), 1798.99.31.

Your rights in this information. The information Tracking Technologies collect about you is personal information, and your rights apply to it just as they apply to any other personal information we hold. Subject to verification and to the exceptions in the law, you may request to know the categories and specific pieces of personal information we have collected through Tracking Technologies, to have it deleted or corrected, and to receive a portable copy; and you may opt out of its sale or sharing and limit the use of sensitive personal information. Because most of this information is tied to a browser or device rather than to your name, we may need information from you to connect a request to the right records, and we may be unable to identify the data if you have cleared your cookies. Submit a request through https://clinivoy.com/privacy-request or by any method in Section 6.1 of the Website and Consumer Privacy Policy, which describes the process, the timelines, and how we verify requests. Cal. Civ. Code §§ 1798.100, 1798.105, 1798.106, 1798.110, 1798.115, 1798.120, 1798.121.

6. Email Tracking

Our marketing emails may contain pixels or similar technologies that tell us whether you opened a message or clicked a link so that we can measure and improve our communications. You may reduce or prevent certain email tracking by disabling images or remote content in your email client, and you may unsubscribe from marketing emails at any time using the unsubscribe mechanism provided in the message or by contacting us. Transactional and appointment-related messages are not marketing communications and may continue as permitted by applicable law. Marketing emails, and the tracking pixels in them, are sent only to people who have asked to receive them; your consent to marketing email is obtained separately from any consent you give in the cookie preference center, and it is separate from your consent to receive appointment and billing messages. You may withdraw it at any time without affecting the messages we send about your care. Measurement pixels in transactional and appointment-related messages are limited to confirming delivery and are not used for advertising or profiling.

We do not combine individual-level email engagement information with your patient health records to create a comprehensive patient profile or use email-tracking technologies to collect PHI. We do not share individual-level email engagement information with advertising partners except as permitted by applicable law and our privacy policies. Our email platform is configured so that engagement data is held separately from the electronic health record, is not written back to any patient record, and is not keyed to a patient identifier; we review that configuration when we change email vendors or platforms.

7. Tracking Technologies and Health Information — Our Commitments

Tracking Technologies on a health care website present risks that ordinary commercial sites do not. Information about the pages you view can reveal a condition, a treatment, or a provider relationship. We apply the following restrictions:

Restrictions on Tracking Technologies involving health information. We do not deploy third-party analytics, advertising, session-replay, or similar Tracking Technologies on authenticated patient pages, patient intake or registration pages, appointment-booking flows that collect clinical information, or other pages where users submit information that constitutes PHI, except where a technology is strictly necessary for the operation or security of the service, has been reviewed and approved under our privacy and security requirements, and is configured so that it does not collect or use PHI for advertising, analytics profiling, or any secondary purpose. We maintain technical controls — including tag-manager restrictions, page-level allow lists, and content-security-policy rules — designed to prevent non-essential Tracking Technologies from operating on those pages, and we test and audit those controls quarterly, before any new page or flow of these kinds goes live, and after any material change to the Site or to a vendor’s product. We use automated scanning to detect Tracking Technologies present on these pages, and we remediate anything the scan finds before the page is released or, if it is already live, on discovery.

Protection of PHI. We do not disclose PHI to advertising vendors. A vendor that receives PHI on our behalf must be subject to appropriate contractual protections, including a business associate agreement where required by HIPAA, and may receive, use, or disclose PHI only as permitted by applicable law and the applicable agreement. We monitor outbound data flows from the Site for the presence of PHI and, if we identify an inadvertent disclosure, we will remediate it, direct the vendor to delete the affected information, and assess our obligations under the HIPAA breach notification rule and applicable California law.

Minimization of public-page tracking. Where analytics technologies are used on public pages, we configure them to minimize the collection and disclosure of identifying information and to disable advertising, data-sharing, and cross-device features. Where a vendor does not make a particular control available, we document the limitation and decide whether to keep the technology in light of it. We review these configurations quarterly and whenever a vendor materially changes its product, and we document the review.

Sensitive-page exclusions. We evaluate public pages that describe clinical conditions, treatments, or provider-specific services to determine whether Tracking Technologies should be restricted or disabled because a visit to such a page may reveal sensitive health information. Where a page is identified as sensitive, we configure our systems to prevent Tracking Technologies from collecting or transmitting information that could constitute PHI or otherwise create an unacceptable privacy risk. A page is treated as sensitive if a visit to it would tend to reveal a condition, a treatment, or a provider relationship. This evaluation may include pages describing immunoglobulin therapy, anti-infective therapy, immunosuppressive treatment, or other services that could reveal a health condition. We repeat this evaluation quarterly, before any new page describing a condition, treatment, or service line is published, and whenever we add a service line to the Site. Automated scanning runs against these pages on the same schedule.

Vendor diligence. Before adding any Tracking Technology, we assess what information it collects, where it sends that information, how the information may be used or disclosed, what technical configuration settings are available to minimize data collection and disable advertising features and what contractual or legal protections are required, including a business associate agreement, service-provider or contractor agreement, data processing agreement, or other appropriate contractual restrictions.

Session Replay and Heat Mapping. We do not deploy session-replay or heat-mapping technologies on pages where users enter PHI or other sensitive personal information, or on pages containing clinical information, unless the technology has been configured and approved for that use under our privacy and security requirements and does not record or transmit PHI. This includes patient portal login pages, appointment scheduling and intake flows, and condition-specific treatment pages. Where session-replay or heat-mapping technologies operate on permitted pages, they do so only after you consent through the preference center, and they are configured to mask or exclude keystrokes and form fields containing personal information. Where a tool cannot mask a particular field, we do not run it on the page containing that field. Penal Code §§ 631, 632.

8. Changes to This Policy

We may update this Policy as our use of Tracking Technologies changes. The revised Policy will be posted with a new “Last Updated” date. If we add a Tracking Technology or materially change the purposes for which Tracking Technologies are used in a manner that requires consent or renewed consent under applicable law, we will obtain the required consent before implementing the change.

If we make a material change to this Policy — for example, adding a category of Tracking Technology, adding an advertising vendor, or changing the purposes for which information is used — we will give notice before the change takes effect by email to registered users, by a prominent banner on the Site displayed for at least thirty (30) days, and by re-presenting the consent interface so that you can review and change your choices. Information collected before a material change continues to be governed by the version of this Policy in effect when it was collected, unless we obtain your consent to the new terms. If a third-party vendor materially changes its data collection or sharing practices, we will re-evaluate the vendor and applicable privacy requirements and, where required, provide notice or seek renewed consent.

9. Implementation and Accuracy

The Tracking Technologies described in this Policy are subject to change as the Site, applications, vendors, and technology configurations change. ClinIVoy periodically reviews its Tracking Technologies and updates this Policy as appropriate. The specific cookies, identifiers, technologies, providers, purposes, and durations listed in this Policy should be maintained consistently with the Tracking Technologies actually deployed on the Site. If you believe the cookies or technologies described in this policy are not consistent with what you experience on our Site, please contact us using the information provided in Section 10. We will investigate reported discrepancies promptly.

10. Visitors Located Outside the United States

The Site is operated from the United States and is directed to individuals in the United States. We do not target visitors in the European Union, the European Economic Area, the United Kingdom, or Switzerland, and we do not offer goods or services to, or monitor the behavior of, individuals located there. If you access the Site from outside the United States, you do so on your own initiative, and information collected through Tracking Technologies is processed in the United States under this Policy.

11. Contact Us

Privacy Officer
ClinIVoy LLC (d/b/a ClinIVoy)
17332 Von Karman Ave #110

Irvine, CA 92614
Phone: +1 844-243-7833
Email: [email protected]

See also the ClinIVoy Website and Consumer Privacy Policy and, if you are a patient, the ClinIVoy Medical Group Notice of Privacy Practices.

INFUCARE MEDICAL GROUP OF CALIFORNIA, A PROFESSIONAL MEDICAL CORPORATION, d/b/a CLINIVOY MEDICAL GROUP

Effective Date: September 1, 2026

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

🔍 Understanding This Policy in Plain Language

We use your health information primarily for treatment, payment, and healthcare operations.

California law gives you stronger privacy rights than federal law in many cases.

You have the right to see and copy your records, ask for corrections, and request that we communicate with you confidentially.

If you pay for a health care item or service entirely out of pocket, you can ask us not to disclose information about that item or service to your health plan, except where disclosure is required by law.

Certain health information receives additional protection under federal or California law, including information concerning HIV/AIDS, genetic information, reproductive health care, substance use disorder treatment, mental health services, and minors’ confidential services.

Information about you that is not covered by HIPAA or the CMIA — for example, information collected when you visit our website — is described in our separate Website and Consumer Privacy Policy and Cookie and Tracking Technologies Policy and is subject to your rights under the California Consumer Privacy Act.

1. Who Follows This Notice

This Notice is issued by Infucare Medical Group of California, a professional medical corporation, doing business as ClinIVoy Medical Group (“ClinIVoy Medical Group,” “we,” “us,” or “our”). We are a health care provider and a “covered entity” under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended by the Health Information Technology for Economic and Clinical Health Act (collectively, “HIPAA”).

This Notice describes the privacy practices of ClinIVoy Medical Group as the health care provider and covered entity. This Notice applies to the protected health information (“PHI”) we create, receive, maintain, or transmit in connection with your care at our infusion and injection therapy centers and to the physicians, nurses, advanced practice clinicians, technicians, employees, and other members of our workforce who provide services on our behalf. We may disclose PHI to our business associates when permitted by HIPAA and other applicable law. Our “workforce” includes employees, independent contractors, volunteers, trainees, and other individuals whose conduct, in the performance of their duties for us, is under our direct control. Workforce members are trained on their privacy and security obligations.

Our management company,  ClinIVoy Management Company, LLC provides administrative, technology, billing, and other non-clinical management services to ClinIVoy Medical Group. It is not a health care provider and does not practice medicine. To the extent it creates, receives, maintains, or transmits PHI on our behalf, it acts as our “business associate” under HIPAA and is required by a written business associate agreement to safeguard and use or disclose PHI only as permitted by applicable law and our agreement.

2. Our Legal Duties

We are required by law to:

Maintain the privacy and security of your PHI;

Provide you with this Notice describing our legal duties and privacy practices with respect to your PHI;

Notify you as required by law if a breach occurs that involves your unsecured PHI;

Follow the terms of the Notice currently in effect; and

Comply with HIPAA, California’s Confidentiality of Medical Information Act, Civil Code § 56 et seq. (“CMIA”), and other applicable federal and California privacy and confidentiality laws.

Where California law provides greater privacy protection and is not preempted by federal law, we will comply with the applicable California requirement. Certain California laws provide additional protections for particular types of health information, as described in Section 6.

We limit uses and disclosures of PHI to the minimum necessary to accomplish the intended purpose, consistent with HIPAA and CMIA, except where a more specific standard applies (for example, treatment disclosures or disclosures required by law).

3. How We May Use and Disclose Your Health Information Without Your Written Authorization

 

The following are examples of uses and disclosures that we may make without your written authorization. They are examples only and are not intended to describe every use or disclosure permitted by law. All uses and disclosures are subject to applicable federal and California privacy and confidentiality requirements.

3.1 Treatment. We use and disclose your PHI to provide, coordinate, and manage your infusion and injection therapy and related care. Examples of how we may use your information for treatment include:

Our nurses review your chart, allergies, and prior infusion reactions before administering a biologic.

Our pharmacist confirms your dose against your weight and laboratory values.

We send your infusion records to your referring rheumatologist, neurologist, or infectious disease physician.

We obtain laboratory results and monitoring data from the laboratory that performs your pre-infusion testing.

We send prescriptions to outside specialty pharmacies that dispense your medication.

3.2 Payment. We use and disclose your PHI to bill and obtain payment for the care we provide. Examples include:

Verifying your eligibility and benefits with your health plan.

Submitting claims and supporting clinical documentation.

Obtaining prior authorization for a biologic or immunoglobulin therapy.

Providing records to a payer conducting a claims audit.

Referring a delinquent account to a collection agency (which receives only the minimum information necessary).

3.3 Health Care Operations. We use and disclose your PHI to run our practice and ensure that our patients receive quality care. Examples include:

 Quality assessment and improvement review of infusion reactions.

Peer review and evaluation of clinician competence.

Accreditation, licensing, and credentialing activities.

Medical review, legal services, audits, and compliance and risk management programs.

Business management and general administrative activities related to our health care operations, including compliance, risk management, quality improvement, utilization review, and other activities permitted by HIPAA.

3.4 Others Involved in Your Care or Payment. Unless you object, we may disclose to a family member, relative, close personal friend, or other person you identify the PHI directly relevant to that person’s involvement in your care or payment for your care. We may also use or disclose your PHI to notify such a person of your location, general condition, or death. If you are not present or are incapacitated, we will use our professional judgment to determine whether the disclosure is in your best interest and will disclose only the information directly relevant to that person’s involvement. We may also disclose PHI to a public or private entity authorized to assist in disaster relief efforts so that your family can be notified of your condition and location.

3.5 Appointment Reminders, Treatment Alternatives, and Health-Related Benefits. We may contact you to remind you of scheduled infusion appointments, to inform you of treatment alternatives, or to tell you about health-related benefits and services that may be of interest to you. These communications are not “marketing” requiring your written authorization when they fall within the exceptions described in Section 4. If you have asked us to communicate with you in a particular way or at a particular location, we will honor reasonable requests (see Section 5.5).

3.6 Uses and Disclosures Required or Permitted by Law. We may use or disclose your PHI without your written authorization when permitted or required by applicable federal or California law, subject to all applicable conditions, limitations, and protections, including the requirements of 45 C.F.R. § 164.512 and any more protective California law that applies.

As required by law. When federal, state, or local law requires the use or disclosure.

Public health activities. To public health authorities to prevent or control disease, injury, or disability; to report births and deaths; to report reactions to medications or problems with products; to notify persons of recalls; to notify a person who may have been exposed to a communicable disease.

Victims of abuse, neglect, or domestic violence. To a government authority authorized by law to receive such reports, consistent with California reporting requirements.

Health oversight activities. To agencies conducting audits, investigations, inspections, licensure actions, and civil, administrative, or criminal proceedings related to oversight of the health care system.

Judicial and administrative proceedings. In response to a court or administrative order, subpoena, discovery request, or other lawful process, when the disclosure is permitted or required by applicable law and all applicable conditions and protections have been satisfied.

Law enforcement. For limited law enforcement purposes, including in response to a court order, warrant, or grand jury subpoena; to identify or locate a suspect, fugitive, material witness, or missing person; about a victim of a crime under limited circumstances; about a death we believe may have resulted from criminal conduct; and about criminal conduct on our premises.

Coroners, medical examiners, and funeral directors. To identify a deceased person, determine cause of death, or permit them to carry out their duties.

Organ and tissue donation. To organ procurement organizations for the purpose of facilitating donation and transplantation.

For research approved by an institutional review board or privacy board that has reviewed the research proposal and established protocols to protect your information, or under other limited circumstances permitted by law. We may also use or disclose PHI in connection with reviews preparatory to research, for research on the PHI of decedents, and through a limited data set subject to a data use agreement, in each case only as permitted by 45 C.F.R. §§ 164.512(i) and 164.514(e) and subject to any more protective California law.

To avert a serious threat to health or safety. To prevent or lessen a serious and imminent threat to the health or safety of you or the public, to someone able to help prevent the threat.

Specialized government functions. For military and veterans activities, national security and intelligence activities, protective services for the President and others, and correctional institutions and other law enforcement custodial situations.

Workers’ compensation. As authorized by and to the extent necessary to comply with California workers’ compensation laws. . Where California law limits the medical information that may be disclosed to an employer, we will comply with those limits. Civil Code §§ 56.20–56.245.

Fundraising.  We do not use or disclose your PHI for fundraising.

4. Uses and Disclosures That Require Your Written Authorization

Except as otherwise permitted or required by law, the following uses and disclosures require your written authorization:

Psychotherapy notes, except in the narrow circumstances permitted by 45 C.F.R. § 164.508(a)(2);

Marketing communications, other than a face-to-face communication with you or a promotional gift of nominal value;

Sale of PHI, meaning any disclosure that constitutes a “sale of PHI” under HIPAA, except as otherwise permitted by 45 C.F.R. § 164.502(a)(5)(ii);

Substance use disorder records subject to 42 C.F.R. Part 2, as described in Section 6.6;

California Law. Uses and disclosures of information subject to additional federal or California protections when those laws require a specific authorization or otherwise impose additional requirements; and

Any other use or disclosure not described in this Notice.

You may revoke an authorization at any time, in writing, by contacting our Privacy Officer. Revocation stops future uses and disclosures made in reliance on the authorization but does not undo any use or disclosure already made while the authorization was in effect. Under CMIA, an authorization must satisfy the form and content requirements of Civil Code § 56.11, and you are entitled to a copy of the signed authorization.

Redisclosure warning. Once your information is disclosed to a person or organization outside our practice, that recipient may be subject to different privacy requirements depending on the nature of the information and the recipient. Information protected by 42 C.F.R. Part 2 may be subject to additional restrictions on use and redisclosure. We encourage you to ask any recipient about its privacy practices.

5. Your Rights Regarding Your Health Information

5.1 Right to Inspect and Obtain a Copy. You have the right to inspect and obtain a copy of the PHI we maintain about you in a designated record set, including your billing records, for as long as we maintain it.

How to request. Submit a written request to our Privacy Officer at the address in Section 9.

If we maintain the record electronically, you may request an electronic copy in the form and format you request, if readily producible, or in a readable electronic form and format we agree to. You may also direct us in writing to transmit a copy to a person or entity you designate.

California timing. Where California law applies, we will comply with the applicable California deadlines for inspection and copying of medical records. Under Health & Safety Code § 123110, we will permit inspection during business hours within five (5) business days after receiving a written request and will provide copies within fifteen (15) days after receiving a written request, subject to applicable law. We will also comply with applicable HIPAA requirements where they apply.

We may charge fees permitted by applicable federal and California law for copies of your records. We will provide you with information about any applicable charges before fulfilling your request. Where Health & Safety Code § 123110 applies, our fee will be a reasonable, cost-based fee limited to the cost of labor for copying the records, supplies for the paper copy or for portable electronic media if you request it, postage if you ask us to mail the copy, and preparing an explanation or summary of the record if you agree to one; and that fee will not exceed twenty-five cents ($0.25) per page for paper copies or fifty cents ($0.50) per page for records copied from microfilm. Health & Safety Code § 123110(j). Where the HIPAA right of access applies, our fee will not exceed the reasonable, cost-based fee permitted by 45 C.F.R. § 164.524(c)(4). We do not charge a fee to inspect your records, and we will provide one copy of the relevant portion of your records at no charge when Health & Safety Code § 123110(d) requires it to support an application for public benefits.

In limited circumstances we may deny your request. If we deny access on a reviewable ground, you may request that the denial be reviewed by a licensed health care professional we designate who was not involved in the original decision. We will comply with the outcome of that review.

5.2 Right to Request an Amendment. If you believe PHI we maintain about you is incorrect or incomplete, you may request in writing that we amend it, stating the reason for the request. We may deny the request if the information was not created by us, is not part of the designated record set, is not available for inspection, or is accurate and complete. If we deny your request, you may submit a written statement of disagreement, which we will include with the record. Under Health & Safety Code § 123111, you may also submit an addendum of up to 250 words per alleged incomplete or incorrect item, which becomes part of your record.

5.3 Right to an Accounting of Disclosures. You have the right to receive a list of certain disclosures of your PHI made by us or our business associates in the six (6) years before your request. The accounting excludes disclosures made for treatment, payment, and health care operations; disclosures made to you; disclosures made pursuant to your authorization; and certain other disclosures identified in 45 C.F.R. § 164.528. The first accounting in any twelve (12) month period is free; we may charge a reasonable, cost-based fee for additional requests, and we will notify you of the cost in advance so that you may withdraw or modify your request.

5.4 Right to Request Restrictions. You may request that we restrict the PHI we use or disclose for treatment, payment, or health care operations, or to a person involved in your care. We are not required to agree to a requested restriction, except as follows:

We must agree to your request to restrict disclosure of PHI to a health plan if the disclosure is for the purpose of carrying out payment or health care operations, is not otherwise required by law, and the PHI pertains solely to a health care item or service for which you, or someone on your behalf other than the health plan, has paid us in full out of pocket. 45 C.F.R. § 164.522(a)(1)(vi); Civil Code § 56.107.

Example: If you pay for a specific infusion service entirely out of your own pocket (not through your health plan), and you ask us not to disclose information about that specific service to your health plan, we are required to honor that request. This allows you to keep certain services confidential from your insurer.

If we agree to a restriction, we will honor it unless the information is needed to provide you emergency treatment.

5.5 Right to Request Confidential Communications. You have the right to request that we communicate with you about medical matters in a certain way or at a certain location — for example, only by mail to a specified address, only to a specified telephone number, or only through a specified channel. We will accommodate reasonable requests and will not ask you to explain the reason for your request.

California confidential communications. California law provides additional rights to request confidential communications concerning certain sensitive health care services. Where applicable, we will process and accommodate such requests in accordance with California law, including applicable requirements concerning communications to a policyholder or subscriber. We will not require authorization from the policyholder or subscriber when California law prohibits that requirement.

Examples of reasonable requests: You may ask us to call you only at your work number rather than your home number, send mail to a post office box rather than your home address, or communicate with you through a secure patient portal rather than by phone.

5.6 Right to a Paper Copy of This Notice. You have the right to a paper copy of this Notice at any time, even if you have agreed to receive it electronically. Ask any staff member or contact our Privacy Officer. This Notice is also posted at each of our centers and on our website at https://clinivoy.com/.

5.7 Right to Be Notified of a Breach. You have the right to be notified if we discover a breach of your unsecured PHI.  We will notify you as required by applicable federal and California breach-notification laws, including the applicable provisions of 45 C.F.R. §§ 164.400–414, Civil Code §§ 1798.29 and 1798.82, and Health & Safety Code § 1280.15. . We will notify you without unreasonable delay and in no case later than sixty (60) calendar days after discovery of the breach, except where a law enforcement official requests a delay as permitted by 45 C.F.R. § 164.412.

5.8 Right to Choose Someone to Act for You. If you have given someone medical power of attorney, or if someone is your legal guardian or conservator, that person can exercise your rights and make choices about your health information. We will verify the person’s authority before taking action.

6. Special Protections Under Federal and California Law

Certain categories of health information may receive additional protection under federal or California law. We will use and disclose such information only as permitted or required by the applicable law, which may impose additional authorization, notice, consent, or other requirements. The protections described below apply only to the extent the applicable law covers the information and circumstances involved.

6.1 HIV/AIDS Test Results. The results of an HIV test that identifies you are protected by Health & Safety Code §§ 120975–121025 and generally may not be disclosed without your specific written authorization, except as those statutes expressly permit — for example, to your treating health care providers or to public health authorities as required by law.

6.2 Genetic Information. Genetic information may be subject to additional protections under California and federal law. We will use and disclose genetic information in accordance with applicable privacy and confidentiality requirements and will not use or disclose such information for purposes prohibited by applicable law, including prohibited underwriting purposes.

Genetic test results. Where California law requires a specific written authorization for the disclosure of the results of a test for a genetic characteristic, we will not disclose those results without an authorization that satisfies the applicable statutory requirements. Such an authorization must, among other things, be written in plain language and in a typeface no smaller than 14-point type; be signed and dated; state who is authorized to disclose the results, the nature of the information to be disclosed, and the persons or entities authorized to receive it; state the purpose of the disclosure; state an expiration date or the length of time the authorization remains valid; and advise you of your right to receive a copy of the authorization. A separate authorization is required for each disclosure. Civil Code §§ 56.17, 56.18.

Underwriting. We will not use or disclose genetic information for underwriting purposes, and we will not disclose genetic information to a health plan for use in underwriting, determining eligibility for or benefits under a plan, computing premium or contribution amounts, or applying preexisting condition exclusions. California law separately restricts the use and disclosure of the results of tests for genetic characteristics in connection with life and disability insurance. 45 C.F.R. § 164.502(a)(5)(i); Insurance Code §§ 10146–10149.1.

6.3 Abortion, Abortion-Related Services, Contraception, and Gender-Affirming Care. California law provides enhanced privacy protections for certain information concerning reproductive health care, including abortion and abortion-related services, contraception, and gender-affirming care. We will use and disclose such information in accordance with applicable federal and California law.

Out-of-state requests. Where California law restricts disclosure of medical information relating to lawful reproductive health care to an out-of-state person, agency, department, or other entity, we will comply with those restrictions. We will not release medical information related to a person seeking or obtaining abortion or abortion-related services, contraception, or gender-affirming health care in response to a subpoena, warrant, request, or investigation based on another state’s law that interferes with the right to seek or obtain that care. Civil Code §§ 56.108, 56.109, 56.110.

Legal process. We will evaluate subpoenas, warrants, court orders, discovery requests, and other legal process involving reproductive health information in accordance with applicable federal and California law. We will not voluntarily disclose information when disclosure is prohibited by applicable law.

Access and security. We maintain administrative, technical, and physical safeguards designed to protect sensitive health information from unauthorized access, use, or disclosure. Where California law requires particular protections or restrictions concerning sensitive reproductive health information, we will implement those requirements. Our electronic health record system is configured to enable the segregation of this information and to limit its disclosure, as required by Civil Code § 56.101.

Health information exchange. We will participate in health information exchange and other electronic information-sharing activities in accordance with applicable law and our applicable privacy and security policies.

Nothing in this Section 6.3 limits any privacy right or protection provided by applicable federal or California law.

6.4 Mental Health Information. Information obtained in the course of services provided under the Lanterman-Petris-Short Act is protected by Welfare & Institutions Code § 5328. Psychotherapy notes are protected by 45 C.F.R. § 164.508(a)(2).

6.5 Minors and Confidential Services. Where a minor lawfully consents to their own care under Family Code §§ 6924–6929 or Health & Safety Code § 123115, we will not disclose that information to a parent or guardian without the minor’s authorization, except as those statutes permit. A parent or guardian who is not entitled to access a minor’s confidential record will be denied access consistent with Health & Safety Code § 123115(a).

Examples of services a minor may consent to under California law include:

Pregnancy-related services (Family Code § 6925)

Contraception (Family Code § 6926)

Diagnosis and treatment of sexually transmitted diseases (Family Code § 6927)

Drug or alcohol abuse counseling and treatment (Family Code § 6929)

Mental health treatment, subject to certain conditions (Family Code § 6924)

We will not disclose information about these services to a parent or guardian without the minor’s authorization, except as permitted by law.

6.6 Substance Use Disorder Records. Certain records concerning substance use disorder (“SUD”) treatment may be subject to the federal confidentiality requirements of 42 C.F.R. Part 2 (“Part 2”), in addition to HIPAA. If we create, receive, maintain, or transmit records subject to Part 2, we will use and disclose those records in accordance with Part 2, HIPAA, and other applicable law.

Part 2 permits certain uses and disclosures pursuant to patient consent and permits certain uses and disclosures without consent under specified circumstances. Part 2 also provides additional protections concerning certain legal proceedings and redisclosure of Part 2 records. Under the Part 2 regulations as revised effective April 16, 2024, with compliance required as of February 16, 2026, a single written consent from you may permit us to use and disclose Part 2 records for treatment, payment, and health care operations until you revoke that consent in writing, and a recipient that is a HIPAA covered entity or business associate may redisclose those records as permitted by the HIPAA Privacy Rule, subject to the limitations in Part 2. Part 2 records, and testimony relaying the content of Part 2 records, may not be used or disclosed in a civil, criminal, administrative, or legislative proceeding against you without your written consent or a court order meeting the requirements of 42 C.F.R. Part 2, Subpart E. You also have the right to request restrictions on the use and disclosure of Part 2 records for treatment, payment, and health care operations, and to obtain a list of disclosures made with your consent, as provided in Part 2.

You have rights concerning records subject to Part 2, including the right to file a complaint concerning an alleged Part 2 violation with the U.S. Department of Health and Human Services.

If a record is subject to both HIPAA and Part 2, we will apply the requirements applicable to the information and disclosure at issue.

6.7 Immigration Status. We protect medical information concerning immigration status in accordance with applicable federal and California law. We will not disclose such information except as permitted or required by applicable law and will evaluate requests from governmental authorities in accordance with applicable legal requirements.

6.8 Medical Information and Employers. We do not provide occupational health services, employment-related medical examinations, or fitness-for-duty evaluations, and we do not disclose your medical information to your employer except with a written authorization that satisfies Civil Code § 56.21 or as otherwise required or permitted by law, including California’s workers’ compensation laws.

7. Complaints

If you believe your privacy rights have been violated, you may file a complaint with us and with the federal government. You will not be retaliated against, penalized, or denied care for filing a complaint.

Filing a Complaint With the Federal Government: U.S. Department of Health and Human Services, Office for Civil Rights. You may file a complaint online or obtain information about filing a complaint at the HHS Office for Civil Rights website – https://www.hhs.gov/hipaa/filing-a-complaint/index.html.

Filing a Complaint With California Authorities:

California Department of Justice, Office of the Attorney General — for matters within its jurisdiction — https://oag.ca.gov/report;

California Department of Public Health — for matters within its jurisdiction; and

Medical Board of California — for matters concerning physicians within its jurisdiction — https://www.mbc.ca.gov/.

Filing a Complaint With Us: You may file a complaint with us in writing, by telephone, or by email. Complaints should be directed to: Privacy Officer, ClinIVoy Medical Group, 17332 Von Karman Ave #110, Irvine, CA 92614; Phone: +1 844-243-7833; Email: [email protected].  There is no fee to file a complaint, and we will not retaliate against you for filing one

8. Changes to This Notice

We reserve the right to change this Notice at any time. Any revised Notice will apply to PHI we already maintain and to PHI we receive or create in the future to the extent permitted by applicable law. The current Notice will be posted in a clear and prominent location at our centers and on our website at https://clinivoy.com/. The effective date appears on the first page. You may request a paper copy of the current Notice at any time.

When we materially revise this Notice, we will make the revised Notice available as required by applicable law, including by posting it at our centers and on our website. In addition, when we make a material revision to this Notice, we will notify you directly — by mail to the address we have on file for you, or by email or through our patient portal if you have agreed to receive communications from us electronically — and we will make the revised Notice available to you at your next visit.

9. Contact Us

 

Privacy Officer
Infucare Medical Group of California, a Professional Medical Corporation d/b/a ClinIVoy Medical Group
17332 Von Karman Ave #110

Irvine, CA 92614
Phone: +1 844-243-7833
Email: [[email protected]]

Acknowledgment of Receipt. We are required to make a good faith effort to obtain your written acknowledgment that you received this Notice and, if we are unable to obtain an acknowledgment, to document our good faith efforts and the reason the acknowledgment was not obtained.

LANGUAGE ASSISTANCE. If you need this Notice in a language other than English or need assistance understanding this Notice, please contact our Privacy Officer. We will provide language assistance and interpretation services as required by applicable law.

This Notice is separate from, and does not replace, the ClinIVoy Website and Consumer Privacy Policy and the ClinIVoy Cookie and Tracking Technologies Policy. Those policies address information collected through our website and other non-treatment channels and may apply in addition to this Notice where appropriate. If information collected through a website or other non-treatment channel constitutes PHI maintained by ClinIVoy Medical Group as a HIPAA covered entity, the applicable HIPAA and California privacy requirements will also apply

PRIVACY POLICY — Clinivoy LLC