BlogPodcast lcteam@thelcoa.com
Book Now!

Notice of Privacy Practices

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Effective date: August 6, 2026 Version: 2 Supersedes prior notice.

This notice applies to: The Longevity Center FL LLC, The Longevity Center Greenville LLC, and The Longevity Center Orlando LLC

The Health Insurance Portability and Accountability Act (HIPAA) of 1996 is a federal law that requires strict confidentiality for all your personal health information. That includes all your medical information used or disclosed by us in any form, whether electronic, written or verbal. The Act gives you significant rights to understand and control how your health information is used. The Act also provides penalties for the misuse of Protected Health Information (PHI).

PHI is any information about you, including demographic data that identifies you and your past, present or future physical or mental health condition, as well as related healthcare services. This Notice describes how we may use or disclose your PHI to provide treatment, payment or healthcare operations or other purposes that are permitted or required by law. This Notice also describes your rights to access and control your PHI. Where an individual clinic’s state law provides greater protection for your health information than HIPAA, we follow the more protective law.

Uses and Disclosures of Protected Health Information

Your PHI may be used or disclosed by our physician, office staff or others involved in your care and treatment, whether providing healthcare services to you, paying your healthcare bills, supporting the operation of our practice or any other lawful use.

Treatment: We will use and disclose your PHI to provide, coordinate or manage your healthcare and related services. This includes the coordination or management of your healthcare by a third party. For example, your PHI may be given to a physician you have been referred to in order to ensure that he or she has the necessary information to diagnose or treat you.

Payment: Your PHI will be used, as needed, to obtain payment for healthcare services. For example, obtaining approval for a hospital stay may require that your relevant PHI be disclosed to your health insurance plan to obtain approval for a hospital admission or a health-related procedure.

Healthcare Operations: We may use or disclose your PHI to support our business activities. These activities may include quality assessment, employee review and conducting or arranging other business activities. We may also use a sign-in sheet at the registration desk where you will be asked to sign your name and indicate your physician. We may call you by name in our reception area when your physician is ready to see you. We may use or disclose your PHI, as necessary, to contact you to remind you of your appointment. We may phone your home and leave a message (on an answering machine or with the person answering the phone) to remind you of an upcoming appointment, the need to schedule a new appointment or to call our office. We may also mail a postcard reminder or letter to your home address. Please tell us if you prefer that we call or contact you at another phone number or location.

Transcription of communications. With your written consent, we create written transcripts of communications between you and our staff and providers, and use them to document your care, keep accurate records, support quality assurance and training, and improve our operations. Transcripts become part of your medical record. We do not create or store audio or video recordings — speech is converted directly into written text. Transcription is optional and is never a condition of care, and you may decline or withdraw at any time without any effect on your treatment. This is described in full in our separate consent form and in the section below.

Business Associates. We contract with outside companies to perform services on our behalf, including technology providers that transcribe, store, and analyze communications and the cloud providers hosting that processing. We disclose your health information to them only as needed for those services. Each is required by written agreement and by federal law to protect it and use it only as we specify.

We may use or disclose your PHI under the following circumstances without your authorization. These include, as required by law:

  • public health issues
  • communicable diseases
  • health oversight
  • abuse or neglect
  • Food and Drug Administration requirements
  • legal proceedings
  • law enforcement
  • coroners, funeral directors and organ donation
  • research, where an Institutional Review Board or Privacy Board has approved a waiver of authorization, or where you have authorized it
  • criminal activity; prison inmates
  • military activity and national security
  • Workers’ Compensation

Required Uses and Disclosures: The law requires us to disclose to you when we are investigated by the Secretary of the Department of Health and Human Services to determine our compliance with HIPAA. Other permitted and required uses and disclosures will be made only with your consent, authorization or opportunity to object unless required by law. You may revoke this authorization in writing at any time except to the extent that your physician or the physician’s practice has taken action in reliance on the use or disclosure indicated in your authorization.

Uses that always require your written authorization. We will not use or disclose your PHI for the following purposes without your separate written authorization: most uses and disclosures of psychotherapy notes; uses and disclosures for marketing purposes; and any disclosure that constitutes a sale of your PHI. We do not sell your protected health information.

Transcription of Communications and Use of De-Identified Information

With your written consent, we may create written transcripts of telephone calls, video and telehealth visits, email, and in-person conversations in our consultation and treatment rooms. We do not transcribe conversations at the front desk, in the lobby, or in waiting areas. We do not create or store audio or video recordings.

Transcription requires your signed consent, is optional, and is never a condition of care. You may withdraw in writing submitted to our Patient Care Coordination Team, or ask that any single conversation not be transcribed by telling a staff member. Neither affects your care.

We may remove identifying information from transcripts and use the resulting de-identified information to develop, train, test, and improve software and artificial intelligence systems used by this practice and by other healthcare practices. De-identification uses the Safe Harbor method under 45 CFR § 164.514(b)(2), which removes the eighteen categories of identifier specified by HIPAA. Once de-identified in this way, HIPAA no longer treats the information as protected health information. Once such information has been used to train a system, it cannot be located, extracted, or recalled; withdrawing consent stops future use but cannot reverse past use.

Financial interest. One or more of the technology providers we engage is affiliated with, or under common ownership with, the owners of this practice. Our owners may therefore have a financial interest in the technology processing your information and in products built from de-identified information. We disclose this so that your consent is fully informed.

How Long We Keep Your Information

We keep your medical record, including transcripts of communications, for at least ten years from your last date of treatment — thirteen years for patients who were minors at the time of service. Separately, we keep security and access logs (records of who accessed information and when, not its content) for at least six years as federal law requires.

Your Rights:

You have the right to inspect and copy your PHI, including in electronic form where we maintain it electronically. We will respond to your request within 30 days. Under federal law, however, you may not inspect or copy the following records:

  • psychotherapy notes
  • information compiled in reasonable anticipation of, or use in civil, criminal or administrative actions or proceedings
  • PHI that is subject to law prohibiting access to said PHI

You have the right to request a restriction of your health information. This means you may ask us not to use or disclose any part of your PHI for the purposes of treatment, payment or healthcare operations. You may also request nondisclosure of any part of your PHI to family members or friends who may be involved in your care or for notification purposes described in these Privacy Practices. Your request must state the specific restriction and to whom you want the restriction to apply.

In most cases we are not required to agree to a requested restriction, and we will tell you if we cannot. There is one exception we must honor: if you pay for a service in full, out of pocket, and ask us not to disclose information about that service to your health plan, we are required to agree, unless the disclosure is otherwise required by law.

You have the right to request to receive confidential communications from us by alternative means or at an alternative location. You have the right to obtain a paper copy of this Notice from us, upon request, even if you have agreed to accept this Notice alternatively (e.g., electronically).

You have the right to have your physician amend your PHI. If we deny your request for amendment, you have the right to file a statement of disagreement with us and we may prepare a rebuttal to your statement and provide you with a copy of any such rebuttal. You have the right to receive an accounting of certain disclosures we have made, if any, of your PHI.

You have the right to be notified of a breach. We are required by law to notify you if a breach occurs that may have compromised the privacy or security of your unsecured protected health information.

You have the right to stop transcription of your communications at any time, for a single conversation or entirely, as described above.

We reserve the right to change this Notice and to make the revised Notice effective for health information we already have as well as information we receive in the future. If we make a material change, we will post the revised Notice in our office and on our website and make copies available on request.

Complaints

You may complain to us or to the Secretary of Health and Human Services if you believe your privacy rights have been violated by us. You may file a complaint by notifying our privacy officer at our office and main telephone number. We will not retaliate against you for exercising your right to file a complaint.

Privacy Officer: Alexandra Mattingly, Clinical Operations Manager, (561) 223-9555, admin@thelcoa.com, 580 Village Blvd, Ste 210, West Palm Beach, FL 33409. You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, 200 Independence Avenue SW, Washington, D.C. 20201, or at www.hhs.gov/ocr/complaints. We will not retaliate against you for filing a complaint.

Privacy Policy

Effective August 6, 2026 · Version 2. This Policy applies to www.thelcoa.com, operated by The Longevity Centers of America, including The Longevity Center FL LLC, The Longevity Center Greenville LLC, and The Longevity Center Orlando LLC. Governing law: Florida. In this Policy, “personal information” means information that identifies, relates to, or could reasonably be linked with an individual or household.

What we collect

What we collect when you visit www.thelcoa.com, and what we do with it. If you are a patient, this does not cover your medical information. That is governed by our Notice of Privacy Practices under HIPAA (above) and at the front desk. Where we act as a HIPAA Covered Entity, our Notice of Privacy Practices (NPP) governs Protected Health Information (PHI) created or received for treatment, payment, or health care operations. This website Policy separately governs information collected through the website — including our Symptom Navigator tool, contact forms, cookies, and analytics — some of which may be “consumer health data” under state law even where it is not HIPAA PHI.

What you give us: name, email, phone, and anything you type into a contact form, appointment request**, Symptom Navigator tool,** or newsletter signup. This may include symptom or condition information you choose to share (e.g., “brain fog,” “chronic fatigue”). We treat this as sensitive information and use it only to respond to your inquiry and schedule care. Please don’t send detailed medical history, diagnoses, lab results, or records through website forms — use the patient portal or call us.

What we collect automatically: IP address, browser and device type, pages viewed (including which symptom or therapy pages you view), and how you reached the site, through cookies**, pixels,** and analytics**/advertising tools**. We currently use tools such as Google Analytics and Meta Ads. Some of these tools may constitute a “sale” or “share” of personal information under California and other state law when used for advertising. You can block cookies in your browser**, and we honor Global Privacy Control (GPC) and equivalent opt-out preference signals as valid requests to opt out of sale/sharing and targeted advertising, to the extent required by law. We do not serve advertising based on your proximity to, or visits to, any of our physical clinic locations.

How we use and share it

We use it to answer your questions and appointment requests, run and improve the site, keep it secure, and — if you opted in — send you news and updates. We do not use symptom or health-related information submitted through website forms to train AI/ML models, to make automated decisions about you, or for third-party advertising, without your separate opt-in consent.

We share it with service providers who help us operate (hosting, analytics, email, scheduling) under a written contract restricting their use of the data, and where the law requires**, subpoena, or to protect anyone’s safety**. We do not sell your personal information**, and we do not “share” personal information (as defined under the CCPA/CPRA — i.e., disclosure for cross-context behavioral advertising) except with your consent or subject to your opt-out rights below**, and text messaging opt-in data and consent are never shared with anyone, including for marketing.

Text messages

If you opt in, message frequency varies and message and data rates may apply. Consent to receive marketing texts is not a condition of purchasing any service. Reply STOP to opt out, HELP for help. We do not send autodialed or prerecorded marketing texts without your prior express written consent. Carriers are not liable for delayed or undelivered messages. Appointment-reminder/service texts and marketing texts require separate consent. Patient texting is covered by a separate consent form.

Your choices

Unsubscribe from emails using the link in any message, reply STOP to texts, control cookies in your browser, or ask us to delete what you submitted. Depending on where you live you may have further rights to know/access, correct, delete, or limit the use of sensitive personal information, and to opt out of the sale or sharing of your personal information and of targeted advertising. To exercise these rights, contact us at admin@thelcoa.com. We will verify your request and respond within the time required by applicable law (e.g., 45 days under the CCPA, extendable once by 45 days). We will not discriminate against you — including by denying services or charging different prices — for exercising these rights.

Security, children, and retention

We use administrative, technical, and physical safeguards designed to protect personal information — including encryption of data in transit, access controls, and periodic security review — consistent with the NIST Cybersecurity Framework and, for PHI, the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C), though no website is completely secure. If a breach affects your personal information, we will notify you and regulators as required by law, including Florida’s breach notification statute (Fla. Stat. §501.171) and South Carolina’s (S.C. Code Ann. §39-1-90). The site is not directed to children under 13**, and we do not knowingly collect personal information from children under 13; if we learn we have, we will delete it promptly, consistent with COPPA**. We keep website information only as long as we need it**, per our documented data retention schedule, and then delete or de-identify it**.

Changes and contact

We may update this policy and will post changes here with a new effective date. For material changes affecting how we use previously collected personal information, we will provide additional notice (e.g., by email or a prominent website notice) before the change takes effect. Questions: The Longevity Centers of America · 580 Village Blvd, Ste 210, West Palm Beach, FL 33409 · admin@thelcoa.com · (561) 223-9555

Text messaging originator opt-in data and consent are never shared or sold to any third party for any purpose.