Effective Date: April 1, 2025
Last Updated: August 25, 2026
At OnPoint Medical Solutions ("Company," "we," "us," or "our"), accessible via onpointmed.com, we are committed to protecting your privacy, maintaining the confidentiality of your health information, and ensuring full transparency regarding how we handle your personal and protected health information (PHI). This Privacy Policy explains how we collect, use, store, and safeguard your data, including our compliance with the Health Insurance Portability and Accountability Act (HIPAA) and regulatory standards for text messaging (10DLC).
1. HIPAA Compliance & Protected Health Information (PHI)
As a healthcare-focused entity, we comply with all applicable provisions of the HIPAA Privacy, Security, and Breach Notification Rules.
- Definition of PHI: Protected Health Information (PHI) includes any individually identifiable health data transmitted or maintained by us, including medical records, appointment histories, treatments, billing data, and direct communications.
- Business Associate Agreements (BAAs): We ensure that any third-party technology providers or vendors who handle, transmit, or store PHI on our behalf (such as cloud hosting, communication suites, and electronic health record systems) execute formal, legally binding Business Associate Agreements (BAAs) establishing strict security and privacy standards.
- Minimum Necessary Standard: Our staff and technology workflows operate under the "minimum necessary" rule, ensuring PHI access is strictly restricted to those who require it to perform treatment, payment, or healthcare operations.
2. Technical & Physical Security Standards
We employ administrative, physical, and technical safeguards to secure your data against unauthorized access, loss, disclosure, or alteration:
- Encryption in Transit & at Rest: All data transmitted across onpointmed.com and through our telephony systems is encrypted using industry-standard Protocols (TLS 1.2+ for web traffic; AES-256 for data at rest).
- Secure Telephony & Voice Infrastructure: We utilize enterprise-grade communications infrastructure (including Zoho Voice) covered under signed Business Associate Agreements to process phone, voicemail, and messaging capabilities securely.
- Access Controls & Auditing: Systems containing sensitive data require multi-factor authentication (MFA), role-based access control (RBAC), and continuous logging and monitoring to prevent unauthorized intrusion.
3. Information We Collect
We collect personal information that you voluntarily provide to us when using our website, signing up for services, or communicating with us.
- Identity & Contact Data: Name, email address, physical address, and phone number.
- Medical Information: Any health conditions, treatment preferences, or history submitted via forms or patient portals.
- Technical Data: IP address, browser type, and interaction metrics gathered automatically via secure website cookies and analytics.
4. Mobile Messaging & 10DLC Compliance (SMS Communications)
We transactional and operational text messages (such as order referrals, appointment reminders, account updates, and customer support communications) to mobile numbers provided to us.
Strict 10DLC Non-Sharing Disclosure
Mobile Information Non-Sharing Policy:
No mobile information will be shared with third parties/affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with or sold to any third parties or affiliates under any circumstances.
SMS Opt-In & Consent
By providing your phone number and explicitly opting in (e.g., via a website form checkbox or direct opt-in prompt), you agree to receive text messages from On Point Med.
- Opting in to text messaging is optional and is never required as a condition to receive healthcare services.
- Message and data rates may apply. Message frequency varies based on your appointments and interactions with us.
We will not share your opt-in to an SMS campaign with any third party for purposes unrelated to providing you with the services of that campaign. We may share your Personal Data, including your SMS opt-in or consent status, with third parties that help us provide our messaging services, including but not limited to platform providers, phone companies, and any other vendors who assist us in the delivery of text messages.
All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
How to Opt-Out or Get Help
- To Opt-Out: You may reply STOP or CANCEL to any text message received from us at any time. You will receive a final confirmation text verifying that you have been unsubscribed.
- For Help: Reply HELP to any message, or contact our support team directly at orders@onpointmed.com.
5. Sharing & Disclosure of Information
Except as described below, we do not sell, rent, lease, or share your personal information with third parties:
- Service Providers: We share necessary data with trusted vendors (e.g., Zoho Voice for telecommunications) who perform services on our behalf under strict confidentiality agreements and BAAs.
- Legal Requirements: We may disclose information if required to do so by law, subpoena, or court order, or to protect the safety and rights of our patients, staff, or the public.
6. Your Rights
Under applicable privacy and health laws (including HIPAA), you have the right to:
- Access, review, or request a copy of your personal data and health records.
- Request amendments or corrections to inaccurate health information.
- Request restrictions on how your health information is used or disclosed.
- Withdraw your consent for non-essential communications (such as SMS or email notifications) at any time.
7. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, your health data, or our mobile messaging practices, please contact us at:
OnPoint Medical Solutions
Website: onpointmed.com
Email: orders@onpointmed.com
Phone: 801-332-9117