HIPAA Policy

Effective Date: September 30, 2025

U Smile Dental (Dr. Jaebeom Lee, DDS) is committed to protecting your health information in compliance with the Health Insurance Portability and Accountability Act (HIPAA). This policy explains how we handle Protected Health Information (PHI) collected through our website and practice, and your rights regarding your health information.

Information Collection and Use

  • Personal Contact Information: If you contact us via our website form or email, we may collect personal identifiers such as your name, email address, phone number, and any details you voluntarily provide. We use this information solely to respond to your inquiries, schedule appointments, or follow up on your requests. Our website’s contact form is designed not to store submissions on the web server – messages are transmitted directly to our office (via secure email) and not retained in the website database, reducing the risk of unauthorized access or storage of your data.

  • Protected Health Information (PHI): PHI includes any health-related information that can identify you (e.g. medical history, dental records, insurance info). We do not ask for detailed health or treatment information through our general contact form, and we urge you not to include sensitive medical details in online form messages. If you do choose to provide any health information (for example, when describing a dental concern), we will treat it as PHI and protect it accordingly. No PHI is stored on our website unless submitted through a secure, HIPAA-compliant channel. Any PHI you provide is encrypted in transit via HTTPS (TLS 1.2 or higher) and delivered directly to our internal systems.

  • Technical Data (Non-PHI): Our website may automatically collect basic technical information such as your IP address, browser type, and pages visited (through analytics cookies – see our Cookie Policy below). This data helps us improve the site’s functionality and user experience. These analytics do not collect or store PHI and cannot identify you by name.

How We Use and Disclose PHI

If you become a patient or provide us with PHI, we will use and disclose your health information only as permitted by HIPAA and applicable law:

  • Treatment – to provide and coordinate your dental care. For example, information you share about your oral health may be used by Dr. Lee and our staff to diagnose issues and plan treatment.

  • Payment – to bill and obtain payment for services. We may use PHI to process insurance claims or communicate with your insurer about a procedure.

  • Healthcare Operations – for internal purposes such as quality improvement, staff training, customer service, or administrative activities that enhance your care.

  • Appointments and Services – to remind you of appointments or provide information on treatment alternatives or health-related benefits.

  • Required or Permitted by Law – We will disclose PHI when required to do so by state or federal law (for example, reporting certain findings to public health authorities or responding to a valid court order).

We will NOT use or share your PHI for marketing purposes without your explicit written authorization. We do not sell your PHI. Any uses beyond those listed above (for example, sharing your testimonial with your permission) will be done only with your consent or as otherwise allowed by law.

Third-Party Services and Business Associates

U Smile Dental may utilize trusted third-party services to assist in our practice operations (e.g. electronic health record systems, online appointment scheduling, dental laboratory services). Any third-party service that handles PHI is vetted for HIPAA compliance and we have a Business Associate Agreement (BAA) in place with them, as required by HIPAA. This means they must safeguard your information just as we do. Examples of such third parties might include practice management software or secure messaging services – all data transmitted to these providers is protected via encryption and stored with HIPAA-compliant security measures. We do not transmit PHI through any software or integration that is not HIPAA-compliant.

(At this time, our website does not host features like patient portals or live chat. If we introduce any online tools that collect health information, they will meet HIPAA standards for encryption and privacy.)

Your HIPAA Privacy Rights

You have the following rights regarding your health information, as provided by federal law:

  • Right to Access and Copies: You have the right to see and get copies of your health records that we maintain. This includes the right to electronic copies if available.

  • Right to Request Amendment: If you believe information in your record is incorrect or incomplete, you may request a correction. If we deny your request, we will provide an explanation.

  • Right to an Accounting of Disclosures: You can request a list of certain disclosures we have made of your PHI, for purposes other than treatment, payment, healthcare operations, and a few exceptional cases.

  • Right to Request Restrictions: You may ask us in writing to restrict how we use or disclose your PHI for treatment, payment, or operations. While we will consider all requests, please note we are not required to agree to a requested restriction in all cases.

  • Right to Request Confidential Communications: You can request that we contact you in a certain way or at a certain location (for example, only call your mobile, or send mail to a specific address). We will accommodate reasonable requests.

  • Right to a Copy of this Policy: You may request a paper copy of this HIPAA Privacy Policy (Notice of Privacy Practices) at any time, even if you have agreed to receive it electronically.

To exercise any of these rights, please contact our Privacy Officer (contact information below). For your protection, we will need to verify your identity before fulfilling certain requests (such as access or deletion requests).

Safeguards and Data Security

U Smile Dental employs administrative, technical, and physical safeguards to protect your information:

  • Encryption: Our website uses SSL/TLS encryption (HTTPS) to secure any data submitted online. Any PHI stored in our internal systems is protected with encryption at rest (in compliance with the AES 256-bit standard for healthcare data storage).

  • Secure Hosting and Networks: Our web hosting and email providers are configured for security. We use firewalls, antivirus, and monitoring to prevent unauthorized access. (We do not store form submissions on the web server to minimize risk.)

  • Access Controls: Only authorized staff can access patient information. Each team member is trained in HIPAA requirements and is required to keep information confidential. We implement role-based access so staff access only the minimum necessary information to perform their duties.

  • Physical Security: Our office maintains secure files and areas for any paper records. Facilities are locked and alarmed after hours.

  • Employee Training and Policies: We regularly train our team on patient privacy and security practices. Our office has written policies on handling PHI, and we periodically audit our procedures to ensure compliance.

Despite our safeguards, please note that no method of electronic transmission or storage is 100% secure. We strive to protect your privacy, but we cannot guarantee absolute security. In the unlikely event of a data breach involving your PHI, we will follow HIPAA’s breach notification requirements to inform you and authorities as needed.

Cookies, Analytics, and Tracking

Our website may use cookies or similar technologies for functionality and to analyze website traffic (see our Privacy Policy and Cookie Policy below for details). These cookies do not collect PHI – they are used for site performance and marketing analytics. For instance, we use Google Analytics to understand how users navigate our site, but this data is aggregated and not tied to individual identities. Any data collected through cookies is handled in accordance with privacy laws and never includes your medical or dental records.

We do not use cookies to collect sensitive health information. You can choose to disable cookies in your browser if you prefer (note that doing so may affect certain website features).

Questions, Concerns, or Exercising Your Rights

If you have any questions about this HIPAA Policy, or if you wish to exercise your privacy rights, please contact our HIPAA Privacy Officer:

U Smile Dental – HIPAA Privacy Officer
2364 W. Lincoln Ave. Anaheim CA 92801
Phone: (714) 772-2698
Email: [email protected]

We will respond to your inquiries or requests as promptly as possible. If you believe your privacy rights have been violated, you have the right to file a complaint with us at the contact above, or directly with the U.S. Department of Health & Human Services (Office for Civil Rights). We will not retaliate against you for filing a complaint.

Updates to This Policy

We may update this HIPAA Privacy Policy from time to time. If changes are made, we will post the updated policy on this page with a new effective date. Any material changes will apply only to PHI we collect after the effective date, unless we are required by law to apply changes to previously collected information. We encourage you to review this page periodically for the latest information on our privacy practices.

This policy is provided for informational purposes and to fulfill our HIPAA compliance requirements. It is not a substitute for professional legal advice. For specific questions about your rights or our obligations, please contact us or consult the U.S. Department of Health & Human Services.

Questions or Concerns?

If you have any questions or concerns about this policy, we’re here to help. Please don’t hesitate to contact our office for more information or support.