Last updated: June 10, 2026
At CardioCare, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website, use our online services, or interact with our clinic. Please read this policy carefully.
We may collect the following categories of information:
We use the collected information for the following purposes:
CardioCare is a covered entity under the Health Insurance Portability and Accountability Act (HIPAA). Any Protected Health Information (PHI) you share with us — whether online, in‑person, or through our telehealth platform — is protected under HIPAA regulations. We maintain administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of your PHI.
We will never disclose your PHI without your written authorization, except as permitted or required by law (e.g., for treatment, payment, or healthcare operations).
We do not sell, rent, or lease your personal information to third parties. We may share your information only in these limited circumstances:
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and understand where our visitors come from. Cookies are small data files stored on your device. You can control cookie preferences through your browser settings. Disabling cookies may affect the functionality of certain parts of our website.
We use Google Analytics to collect anonymous usage data. Google Analytics may set its own cookies. You can opt out of Google Analytics by installing the Google Analytics Opt‑out Browser Add‑on.
We implement industry‑standard security measures to protect your personal information, including SSL encryption for data transmission, firewalls, secure servers, and regular vulnerability assessments. Access to your health information is restricted to authorized personnel who require it for treatment, payment, or healthcare operations.
Despite our best efforts, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your data to the highest standards.
We retain your personal and health information for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Medical records are typically retained for a minimum of seven years from your last visit, or longer if mandated by state or federal regulations. Non‑medical personal data is retained only as long as needed for business or legal purposes.
Depending on your jurisdiction, you may have the following rights regarding your personal information:
To exercise these rights, please contact our Privacy Officer using the information below. We will respond within the timeframe required by law.
Our website and services are not intended for individuals under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately, and we will take steps to delete such information.
Our website may contain links to external sites not operated by us. We are not responsible for the privacy practices or content of these third‑party websites. We encourage you to review their privacy policies before providing any personal information.
We reserve the right to update this Privacy Policy at any time. The "Last updated" date at the top of this page indicates when revisions were made. We encourage you to review this policy periodically. Material changes may be communicated via email or a notice on our website.
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact our Privacy Officer:
This privacy policy is intended to comply with applicable U.S. federal and state laws, including HIPAA and the California Consumer Privacy Act (CCPA) where applicable.