PRIVACY POLICY
NeuroWell Medical Group
Effective August 18, 2026
Applies to: neurowellpsychiatry.com, the NeuroWell Portal iOS App, the NeuroWell Portal Android App, and the NeuroWell Patient Web Portal
──────────────────────────────────────────────────────
IMPORTANT NOTICE REGARDING HEALTH INFORMATION
NeuroWell Medical Group is a HIPAA covered entity. Much of the health information we handle as your psychiatric care provider constitutes Protected Health Information (PHI) governed by the Health Insurance Portability and Accountability Act (HIPAA). This Privacy Policy covers our website and patient portal app. For a full description of your rights as a patient regarding your medical records, please review our separate Notice of Privacy Practices (NPP), available upon request at our office and at neurowellpsychiatry.com/notice-of-privacy-practices.
Your rights under HIPAA are in addition to, not instead of, the rights described in this Policy.
──────────────────────────────────────────────────────
1. Who We Are
NeuroWell Medical Group ("NeuroWell," "we," "our," or "us") is a psychiatric medical practice located at 1820 West Orangewood Avenue, Suite 105, Orange, California 92868. We provide outpatient psychiatric evaluation, medication management, and related mental health care services.
This Privacy Policy describes how we collect, use, store, and share information when you:
• Visit our website at neurowellpsychiatry.com and its subpages (the "Website"); or
• Use the NeuroWell Portal mobile application (the "App"), available on iOS (App Store) and Android (Google Play); or
• Access the NeuroWell Portal through our patient web portal at [portal.neurowellpsychiatry.com].
This Policy does not apply to third-party websites, services, or resources that you access through links on our Website or App. We encourage you to review the privacy policies of any such third parties.
──────────────────────────────────────────────────────
2. Information We Collect
2a. Information You Provide to Us
Through the Website:
• Contact form submissions: name, email address, and the content of your message
• Any information you include when communicating with us by email or phone
Through the App:
• Account registration: email address and password (stored as a secure hashed credential; we never store your password in plain text)
• Profile information: first name, last name, date of birth, phone number, home address, and emergency contact name and phone number
• Mental health assessment responses and scores, including results from the PHQ-9 (depression), GAD-7 (anxiety), PCL-5 (PTSD), and other validated clinical instruments administered as part of your care
• Medication information: medication name, dose, frequency, prescribing provider, and start date
• Documents you choose to upload: insurance cards, government-issued identification, completed intake forms, clinical records, and other files you submit through the App
2b. Information Collected Automatically
Through the Website:
• IP address, browser type, operating system, referring URLs, and pages visited
• Cookie and session data (see Section 6)
Through the App:
• Device type, operating system version, App version, and device language settings
• Crash reports, error logs, and performance diagnostics collected through our crash reporting service (see Section 4b)
• Appointment data retrieved from our electronic health records system when you view the App
2c. Biometric Information (App Only)
If you choose to enable biometric sign-in (Face ID on iOS, or fingerprint or face unlock on Android), the NeuroWell Portal requests your device's built-in biometric authentication system. We do not receive, store, or transmit your biometric data at any point. The biometric comparison is performed entirely on your device by your operating system (iOS or Android). We store only a session authentication token in your device's encrypted secure storage (iOS Keychain or Android Keystore, via Expo SecureStore) to maintain your signed-in session. You may disable biometric sign-in at any time through your device's Settings.
2d. Sensitive Personal Information
Given the nature of our services, we collect categories of information that California law classifies as sensitive personal information, including mental health data, medications, and assessment scores. This information is used solely to provide your psychiatric care and to operate the App on your behalf. We do not use sensitive personal information to infer characteristics about you or for advertising purposes.
──────────────────────────────────────────────────────
3. How We Use Your Information
We use the information we collect to:
• Create and manage your patient portal account
• Deliver and coordinate your psychiatric care, including treatment, payment, and health care operations as permitted by HIPAA
• Populate the App with your appointment schedule, assessment history, and medication list from our electronic health records system
• Respond to inquiries submitted through our Website contact form
• Send transactional communications, including appointment reminders, password reset emails, and account notifications
• Detect, investigate, and prevent technical errors, security incidents, and unauthorized activity
• Improve the functionality and usability of our Website and App
• Comply with our legal and regulatory obligations under HIPAA, California law, and applicable federal regulations
We do not use your health information for advertising, behavioral profiling, or sale to any third party.
──────────────────────────────────────────────────────
4. How We Share Your Information
We share information only in the following limited circumstances.
4a. HIPAA Business Associates
Our electronic health records and practice management system is operated by Tebra Technologies, Inc. (formerly Kareo/PatientPop). Tebra acts as our HIPAA Business Associate under a signed Business Associate Agreement (BAA), which legally obligates Tebra to safeguard your Protected Health Information using the same standards we are required to maintain.
4b. Technology Service Providers
We use the following carefully selected technology vendors to operate our Website and App. Each vendor is contractually limited to accessing only the data necessary to perform its specific function.
Tebra Technologies, Inc.
Purpose: Electronic health records, scheduling, billing
Data received: Protected Health Information (BAA in place)
Resend, Inc.
Purpose: Transactional email delivery (password resets, notifications)
Data received: Recipient email address, email content
Sentry, Inc.
Purpose: App crash reporting and performance diagnostics
Data received: Device information, error logs, app state at time of crash. No PHI is included in crash reports.
We do not use advertising networks, retargeting pixels, or Google Analytics advertising features in connection with our App or any page that handles patient information.
4c. Legal Requirements
We may disclose information when required by applicable law, court order, subpoena, regulatory authority, or government investigation, or when we reasonably believe disclosure is necessary to protect the rights, property, or safety of NeuroWell Medical Group, our patients, or the public.
4d. Business Transfers
In the event that NeuroWell Medical Group is involved in a merger, acquisition, reorganization, or sale of assets, patient information may be transferred as part of that transaction. Any such transfer will be subject to the same privacy protections described in this Policy and all applicable HIPAA requirements, including the requirement to obtain a Business Associate Agreement with any successor entity that handles PHI.
4e. No Sale or Sharing of Personal Information
We do not sell, rent, lease, or share your personal information or Protected Health Information with any third party for their own commercial purposes, advertising, or marketing. We have not done so in the past twelve months.
──────────────────────────────────────────────────────
5. HIPAA and Your Health Information
NeuroWell Medical Group is a covered entity under the Health Insurance Portability and Accountability Act (HIPAA). We are required by law to maintain the privacy and security of your Protected Health Information (PHI) and to provide you with our Notice of Privacy Practices (NPP).
Under HIPAA, you have the right to:
• Access and receive a copy of your medical records
• Request amendments or corrections to your medical records
• Receive an accounting of certain disclosures of your PHI
• Request restrictions on how your PHI is used and disclosed
• Request that we communicate with you by alternative means or at alternative locations
• File a complaint with the U.S. Department of Health & Human Services Office for Civil Rights (OCR) at www.hhs.gov/hipaa or by calling 1-800-368-1019
Our complete Notice of Privacy Practices is available at neurowellpsychiatry.com/notice-of-privacy-practices and upon request at our office. Your HIPAA rights are separate from and in addition to the California privacy rights described in Section 10 of this Policy.
Submitting a HIPAA complaint will not result in any retaliation or adverse action against you as a patient.
──────────────────────────────────────────────────────
6. Cookies and Tracking Technologies
Our Website uses essential session cookies to maintain basic website functionality (such as remembering your preferences within a single visit). We do not use third-party advertising cookies, cross-site tracking technologies, or behavioral retargeting on any page of our Website.
You may configure your browser to block or delete cookies. Blocking essential cookies may prevent some parts of our Website from functioning correctly.
The NeuroWell Portal mobile app does not use browser cookies. Authentication state in the App is maintained through a secure JSON Web Token (JWT) stored in your device's encrypted keychain (iOS Keychain or Android Keystore, via Expo SecureStore). This token is accessible only to the NeuroWell Portal application on your device.
The NeuroWell Patient Web Portal uses a session cookie or secure browser-stored token solely to maintain your signed-in session. This cookie expires when you sign out or after a period of inactivity. We do not use web portal cookies for advertising or tracking purposes.
──────────────────────────────────────────────────────
7. Data Retention
We retain different categories of information for different periods, based on legal obligations and operational need.
Medical records and PHI
Retention: 7 years from date of service (or until the patient turns 21, whichever is later)
Basis: California Health & Safety Code § 123111; HIPAA
App account data (non-PHI)
Retention: Duration of active account, plus 2 years following closure
Basis: Operational
Crash reports and diagnostics
Retention: 90 days
Basis: Operational (via Sentry)
Website contact form submissions
Retention: 2 years
Basis: Operational
Password reset tokens
Retention: 15 minutes from issuance, then invalidated
Basis: Security
Medical record retention is managed through our Tebra EHR system. When records reach the end of their retention period, they are deleted or de-identified in accordance with applicable law.
──────────────────────────────────────────────────────
8. Security
We implement technical, administrative, and physical safeguards to protect your information against unauthorized access, use, alteration, or disclosure, including:
• Encrypted device storage: All sensitive data in the NeuroWell Portal App is stored in iOS Keychain or Android Keystore via Expo SecureStore, encrypted hardware-backed credential stores inaccessible to other applications on your device.
• Encrypted transmission: All communications between the App and our servers use HTTPS/TLS. The App enforces HTTPS in production and will not transmit data over unencrypted connections.
• Authentication controls: The App supports password-based sign-in and optional biometric sign-in (Face ID). Authentication tokens expire and are invalidated upon sign-out.
• Access controls: Patient data access is limited to authorized clinical and administrative personnel on a need-to-know basis.
• HIPAA Security Rule: We maintain administrative, physical, and technical safeguards for PHI as required by 45 C.F.R. Part 164, Subpart C.
No method of electronic transmission or storage is completely secure. If you have reason to believe your account has been compromised, please contact us immediately at hello@neurowellpsychiatry.com or (805) 900-7672.
──────────────────────────────────────────────────────
9. Children's Privacy
The NeuroWell Portal and our Website are directed to adults seeking psychiatric care. We do not knowingly collect personal information from individuals under the age of 13 without verifiable parental consent, as required by the Children's Online Privacy Protection Act (COPPA).
If you believe a minor has provided personal information through our Website or App without appropriate authorization, please contact us at hello@neurowellpsychiatry.com so that we may take appropriate action.
──────────────────────────────────────────────────────
10. California Residents — Your Privacy Rights
As a California resident, you have rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).
Important: Much of the health information we hold about you is Protected Health Information exempt from CCPA under California Civil Code § 1798.145(c)(1)(A) because it is governed by HIPAA. Your rights regarding PHI are described in our Notice of Privacy Practices (Section 5 above). The rights below apply to non-health personal information we hold about you, such as contact information and website usage data.
Right to Know
You may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months, including the sources, purposes, and categories of third parties with whom we shared it.
Right to Access
You may request a portable copy of the specific personal information we hold about you.
Right to Delete
You may request that we delete personal information we have collected from you, subject to exceptions for legal compliance, security, and ongoing service obligations.
Right to Correct
You may request correction of inaccurate personal information we hold about you.
Right to Opt Out of Sale or Sharing
We do not sell or share your personal information for cross-context behavioral advertising. No opt-out is required, but you may contact us to confirm this at any time.
Right to Limit Use of Sensitive Personal Information
You may request that we limit our use of sensitive personal information to the purposes necessary to provide our services and as otherwise permitted by law. We do not use sensitive information beyond these purposes.
Right to Non-Discrimination
We will not deny, degrade, or retaliate against you for exercising any of these rights.
How to Submit a Request
To submit a privacy rights request, please contact us by any of the methods listed in Section 14. We will respond within 45 days of receipt. We may need to verify your identity before processing requests that involve health information or account data.
You may designate an authorized agent to submit a request on your behalf by providing written authorization to us at the contact information below.
Shine the Light
Under California Civil Code § 1798.83, California residents may request a list of categories of personal information disclosed to third parties for direct marketing purposes in the preceding calendar year. We do not disclose personal information to third parties for direct marketing purposes, and have not done so in the past calendar year.
──────────────────────────────────────────────────────
11. Do-Not-Track
Our Website does not currently respond to browser Do-Not-Track (DNT) signals because no uniform standard for honoring DNT signals has been established. We do not track your activity across third-party websites for advertising purposes.
──────────────────────────────────────────────────────
12. Third-Party Links
Our Website and App may contain links to third-party websites and resources, such as insurance portals, pharmacy references, or crisis support lines. This Privacy Policy does not apply to those external sites. We are not responsible for the privacy practices or content of third-party sites and encourage you to review their privacy policies before providing any personal information.
──────────────────────────────────────────────────────
13. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or the services we offer. When we make material changes, we will update the "Effective" date at the top of this page. Where appropriate, we will notify registered App users by email or in-app notification before material changes take effect.
Your continued use of our Website or App after the effective date of any revision constitutes your acknowledgment of the updated Policy. We encourage you to review this Policy periodically. Prior versions of this Policy are available upon request.
──────────────────────────────────────────────────────
14. Contact Us
For questions about this Privacy Policy, to exercise your privacy rights, or to request our Notice of Privacy Practices, please contact us:
NeuroWell Medical Group
1820 West Orangewood Avenue, Suite 105
Orange, California 92868
Email: hello@neurowellpsychiatry.com
Phone: (805) 900-7672
For HIPAA-specific concerns or to request our Notice of Privacy Practices, you may use any of the contact methods above or ask at the front desk during your visit.
──────────────────────────────────────────────────────
© 2026 NeuroWell Medical Group. All rights reserved.