Skip to content
¡Hablamos Español!(718) 509-9888

Privacy policy

How we handle your information, and what you can ask us to do with it.

Build note: unreviewed draft

Everything below is a generic starting-point draft, written so counsel has something to mark up rather than a blank page. It has not been reviewed by an attorney, it does not yet reflect RedCore’s actual vendors, retention schedule or Privacy Officer, and it must not be presented to patients as the practice’s privacy policy until a lawyer has signed it off.

Facts the practice or its attorney still has to supply are marked TO CONFIRM in the text. Search src/pages/privacy-policy.astro for that phrase to find every one of them. There is no effective date on purpose — a dated policy reads as settled, and this one is not.

The page stays noindex until that review is done, so draft privacy terms cannot be indexed, quoted back at the practice, or relied on by a patient. Remove noindex in src/pages/privacy-policy.astro at sign-off, and not before.

1. Who we are

RedCore Physical Therapy + Wellness (“RedCore”, “we”, “us”) is a physical therapy practice with clinics in Brooklyn, the Bronx and Jersey City. This policy explains what information this website collects, why we collect it, who we share it with, and what you can ask us to do with it.

It covers this website only. Information you give us in a clinic, over the phone, or through our secure intake system is protected health information, and is governed by our Notice of Privacy Practices rather than by this page.

TO CONFIRM — the registered legal entity name, the state it is organised in, and the postal address to give for written privacy requests.

2. This page is not our Notice of Privacy Practices

RedCore is a covered entity under HIPAA. HIPAA requires us to publish a separate Notice of Privacy Practices setting out how your protected health information may be used and disclosed, the rights you hold over it, and our legal duties to protect it. A website privacy policy is not a substitute for that notice and cannot satisfy that requirement.

Where anything on this page differs from the Notice of Privacy Practices in relation to health information, the Notice governs.

TO CONFIRM — the link to the published Notice of Privacy Practices, and the wording for how a patient requests a paper copy. Add the link here as soon as the Notice exists.

You can also ask for a copy at the front desk of any clinic, or by calling (718) 509-9888.

3. What this website collects

This site is built to collect as little as possible, and to collect no health information at all.

  • Appointment requests. The form on our appointment request page asks for your name, a phone number, an email address if you want to give one, which clinic suits you, the best time of day to reach you, and the language you would prefer we speak. It does not ask about your symptoms, your diagnosis or your insurance member number, and we ask you not to put those details in it.
  • Newsletter signups. An email address, and a first name if you give one. We do not ask what is bothering you, because a mailing list sorted by medical condition would itself be health information.
  • Anything you send us by email. If you write to info@redcorept.com about an appointment or a job, we receive whatever you chose to put in that message. Please do not put medical details in it — see section 7.
  • Technical information collected automatically. Like almost every website, our host records requests made to the server: an IP address, the page requested, the date and time, and basic browser information. We use it to keep the site running and secure.

This website is not directed at children, and we do not knowingly collect information through it from a child under 13.

4. What we use it for

  • To call you back and arrange an appointment, and to check your insurance benefits before your first visit.
  • To answer a question you have asked us, or to reply to an application for a job.
  • To send you our newsletter, if you asked for it. Every issue carries a one-click unsubscribe link.
  • To keep this site working, diagnose faults, and protect it against abuse.

We do not sell your information. We do not rent or trade it, we do not hand it to advertisers, and we do not use it to build an advertising profile of you.

5. Cookies and analytics

We keep third-party code on this site to a minimum, on purpose. On a healthcare website every extra outside connection is one more company able to see which condition page somebody was reading, so our typefaces are served from our own server rather than loaded from a font provider.

Nothing on this site requires you to accept cookies in order to read it. You can block or delete cookies in your browser settings at any time and the pages will still work.

TO CONFIRM — which analytics tool is in use once one is installed, whether it is configured without cookies, whether visitor IP addresses are truncated, and confirmation that no advertising or social media tracking pixel fires anywhere on the site, condition pages included. This section must not claim anything in either direction until that has been verified against the live build.

6. Who we share information with

We share information only where we need to, and only with people who are bound to protect it:

  • Service providers who run our systems — website hosting, email, appointment and intake software, and backups. They may handle your information only in order to provide that service to us. Where a provider handles protected health information, HIPAA requires a Business Associate Agreement to be in place before that provider may do so.
  • People involved in your care and in paying for it — a referring physician, or your insurer. Those disclosures involve health information and are governed by our Notice of Privacy Practices, not by this page.
  • Where the law requires it — a court order, a subpoena, a public health authority, or a regulator with power to compel disclosure.

We do not share your information with anyone else for their own marketing.

TO CONFIRM — the current list of service providers by category, and written confirmation that a Business Associate Agreement is in place with every one of them that touches protected health information.

6a. The intake application

TO CONFIRM — this policy covers the website only. The separate intake application (see docs/WISHLIST.md §1) is deferred and, when it ships, will collect symptoms, injury history and insurance member IDs — protected health information this page does not currently describe. Before it goes live this policy needs a section stating what it collects, where that is stored, who can access it and for how long, and the Notice of Privacy Practices must cover it. Carried forward from the original scaffold so counsel is not left to rediscover it.

7. How we protect it

No method of sending information over the internet is completely secure, so we cannot promise absolute security — but we treat protecting your information as a clinical responsibility rather than an IT one.

TO CONFIRM — the safeguards this section should actually describe. A draft cannot state them: transport encryption, who has access to systems holding patient information and on what basis, and whether privacy training is required and recorded are all facts about how the practice operates, and each one is a representation a patient and a regulator may rely on. Describe only what is verifiably true today.

Please do not email medical details

Ordinary email is not a secure channel for health information. Call us, or use our secure intake form, and we will take your history properly.

TO CONFIRM — the specific administrative, physical and technical safeguards counsel wants described here, consistent with the practice’s HIPAA Security Rule risk analysis, and confirmation that the encryption, access-control and training statements in the paragraph above are true of the practice as it actually operates. Do not describe a safeguard that is not in place.

8. How long we keep it

We keep information for as long as we need it for the purpose it was given for, and then dispose of it securely. An enquiry that never becomes an appointment is kept for far less time than a clinical record, which we are required by law to retain. Newsletter details are kept until you unsubscribe.

TO CONFIRM — the actual retention period for website enquiries, for newsletter contacts and for clinical records, together with the minimum retention periods New York and New Jersey law impose on a physical therapy practice. Do not publish a number that has not been checked against both states’ rules.

9. Your rights

HIPAA gives you rights over the protected health information we hold about you. Broadly, you can ask to see it and get a copy, ask us to correct something you believe is wrong, ask for a list of certain disclosures we have made, ask us to limit how it is used, ask us to contact you in a particular way or at a particular address, and complain if you think your privacy has been breached. Those rights, and how to use them, are set out properly in our Notice of Privacy Practices.

For the ordinary contact details this website collects, you can ask us what we hold, ask us to correct it, ask us to delete it, or unsubscribe from the newsletter. Email info@redcorept.com or call (718) 509-9888 and ask for the Privacy Officer.

We will never treat you differently, or refuse you care, because you exercised one of these rights. You can complain to the federal regulator responsible for HIPAA as well as to us.

TO CONFIRM — the exact name, postal address and complaint web address for the federal regulator; and whether any New York or New Jersey state privacy statute applies to a practice of RedCore’s size, since those statutes have coverage thresholds and only counsel should decide whether RedCore crosses them.

10. If information is ever breached

If protected health information we hold is breached, the HIPAA Breach Notification Rule requires us to tell the people affected, and in some cases to notify the federal regulator and the media as well. We would do that without unreasonable delay and within the time limits the rule sets, and we would tell you plainly what happened, what information was involved, and what we were doing about it.

TO CONFIRM — the notification timescales and thresholds counsel wants stated, and the person inside the practice who owns breach response.

11. Changes to this policy

We may update this policy as the practice, the law or our systems change. The current version will always be published on this page and will carry the date it took effect. If a change is significant we will say so, rather than quietly editing the page.

TO CONFIRM — the effective date, to be added when counsel signs the policy off, and how the practice wants material changes announced to existing patients.

How to reach us about your information

Call (718) 509-9888 and ask for the Privacy Officer, or email info@redcorept.com. Please do not include medical details in an email — tell us you need to talk and we will call you back.

TO CONFIRM — the name or title of the designated Privacy Officer, and a postal address for written requests.