Privacy Policy
Effective Date: 01/01/2025
Last Updated: 02/05/2026
Jenesis Women’s Health (“Jenesis,” “we,” “us,” or “our”) is committed to protecting the privacy, confidentiality, and security of personal and health information. This Privacy Policy explains how we collect, use, disclose, and safeguard information in connection with our in-person and telehealth services, website, and communications.
This Privacy Policy is intended to comply with applicable federal and Massachusetts laws, including the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the HITECH Act, and relevant Massachusetts patient privacy and data protection laws.
1. Scope of This Policy
This Privacy Policy applies to:
-
Patients receiving in-person care
-
Patients receiving telehealth or virtual care
-
Prospective patients
-
Website visitors
-
Individuals communicating with us via phone, email, chat, or online forms
This Policy applies to information collected:
-
In person
-
Online
-
Electronically
-
Or in writing
This Privacy Policy does not replace our separate HIPAA Notice of Privacy Practices, which patients receive as required by law.
2. Services Covered
Jenesis Women’s Health provides:
-
In-person clinical services at our physical locations
-
Telehealth services, including virtual consultations and follow-up care conducted via secure electronic platforms
Both service types are subject to the same privacy, confidentiality, and security obligations under HIPAA and Massachusetts law.
3. Information We Collect
A. Personal Information
We may collect personal information such as:
-
Name
-
Date of birth
-
Contact information (address, phone, email)
-
Appointment and scheduling details
-
Insurance and billing information
B. Protected Health Information (PHI)
For both in-person and telehealth services, we may collect PHI, including:
-
Medical history
-
Symptoms and health concerns
-
Diagnoses
-
Treatment plans
-
Prescriptions
-
Test results
-
Provider notes
-
Insurance and payment records
PHI is handled in strict compliance with HIPAA, HITECH, and applicable Massachusetts regulations.
C. Telehealth-Specific Information
For telehealth services, we may also collect:
-
Audio and video communications
-
Device or connection information necessary to provide care
-
Telehealth platform usage data
Telehealth sessions are conducted using HIPAA-compliant platforms whenever required by law.
D. Website & Technical Information
When you visit our website, we may collect:
-
IP address
-
Browser type
-
Device type
-
Pages visited
-
Date and time of access
This information is used for security, analytics, and operational purposes only.
4. How We Use Information
We use personal and health information to:
-
Provide medical care (in-person and telehealth)
-
Schedule and manage appointments
-
Communicate regarding care, treatment, and follow-up
-
Process billing and insurance claims
-
Maintain accurate medical records
-
Comply with legal and regulatory obligations
-
Improve services and patient experience
-
Protect patient safety and system security
We do not sell personal or medical information.
5. Telehealth Privacy Considerations
Telehealth services involve electronic communication. While we take reasonable steps to protect privacy, patients should understand:
-
Telehealth carries inherent technology risks (e.g., connectivity issues)
-
Patients are responsible for participating in telehealth visits from a private, secure location
-
Telehealth is not intended for emergencies
By participating in telehealth services, patients acknowledge these risks and consent to electronic communication as permitted by law.
6. Website Communications & Live Chat
Our website may offer contact forms or live chat for general, non-medical inquiries only.
Please do not share sensitive medical or personal health information through website chat or contact forms.
Website chat and forms are not intended for diagnosis, treatment, or emergency use.
7. HIPAA Privacy Rights (Federal Law)
Under HIPAA, patients have the right to:
-
Access and obtain copies of their medical records
-
Request amendments to records
-
Request restrictions on certain uses or disclosures
-
Request confidential communications
-
Receive an accounting of disclosures
-
File a complaint if privacy rights are violated
Patients will receive a HIPAA Notice of Privacy Practices detailing these rights.
8. Massachusetts Patient Rights
In accordance with Massachusetts General Laws Chapter 111, Section 70E, patients have the right to:
-
Respectful, non-discriminatory care
-
Privacy and confidentiality of medical information
-
Informed consent
-
Information about diagnosis, treatment options, and risks
-
Participation in healthcare decisions
-
Access to medical records within statutory timeframes
-
Information about charges and billing
These rights apply to both in-person and telehealth services.
9. Massachusetts Data Protection & Security Laws
Jenesis Women’s Health complies with:
-
M.G.L. c. 93H – Data breach notification
-
M.G.L. c. 93I – Personal information protection
-
201 CMR 17.00 – Standards for safeguarding personal information
We maintain administrative, technical, and physical safeguards to protect personal and medical information.
10. Disclosures of Information
We may disclose information:
-
To healthcare providers involved in your care
-
To insurance carriers for billing and payment
-
To HIPAA-compliant business associates
-
When required by law (public health reporting, audits, court orders)
-
To protect patient safety or legal rights
All disclosures are limited to what is legally permitted or required.
11. Your Choices & Rights
You may:
-
Request access to your records
-
Request corrections
-
Ask questions about privacy practices
-
Request communication preferences
-
Withdraw consent where legally allowed
Requests must be submitted in writing and may be subject to legal limitations.
12. Jenesis Women’s Health Rights
Jenesis Women’s Health reserves the right to:
-
Use and disclose information as permitted by law
-
Maintain medical records as required by regulation
-
Deny requests that are legally prohibited or unreasonable
-
Update this Privacy Policy
-
Enforce website terms and protect legal interests
13. Data Retention
We retain personal and medical information as required by:
-
HIPAA
-
Massachusetts law
-
Medical licensing and professional standards
-
Insurance and billing regulations
14. Children’s Privacy
Services involving minors are provided in compliance with HIPAA, Massachusetts law, and applicable consent requirements involving parents or legal guardians.
15. Security Measures
We use reasonable safeguards including:
-
Secure electronic systems
-
Access controls
-
Staff training
-
HIPAA-compliant vendors and telehealth platforms
No system can be guaranteed 100% secure, but we take privacy seriously.
16. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted with a revised effective date.
17. Contact Information
Jenesis Women’s Health
35 Parkwood Drive, Suite 110
Hopkinton, MA 01748
info@jenesiswomenshealth.com
508-691-9327
Patients may also contact the U.S. Department of Health and Human Services Office for Civil Rights regarding HIPAA concerns.