Privacy Policy

Summit Direct Health Care

Last Updated: November 2025

1. Our Commitment to Privacy

Summit Direct Health Care is committed to protecting your privacy and maintaining the confidentiality of your protected health information (PHI) in compliance with the Health Insurance Portability and Accountability Act (HIPAA) and other applicable laws.

2. Information We Collect

Health Information:

  • Medical history and current health conditions
  • Physical examination findings
  • Laboratory and diagnostic test results
  • Treatment plans and medications
  • Insurance information (if provided)

Personal Information:

  • Name, date of birth, and contact information
  • Emergency contact details
  • Payment and billing information
  • Communication preferences

Website Information:

  • IP address and browser type
  • Pages visited and time spent on site
  • Referral sources

3. How We Use Your Information

We use your information to:

  • Provide medical care and treatment
  • Coordinate care with specialists and other providers
  • Process payments and billing
  • Communicate with you about appointments and health matters
  • Comply with legal and regulatory requirements
  • Improve our services and patient experience

4. Information Sharing

We may share your information with:

  • Other healthcare providers involved in your care (with your consent)
  • Laboratory and diagnostic facilities
  • Insurance companies (only if you request superbills)
  • Legal authorities when required by law
  • Business associates who assist with our operations (under HIPAA-compliant agreements)

We will NEVER:

  • Sell your personal or health information
  • Share your information for marketing purposes without consent
  • Disclose your information to unauthorized parties

5. Your Privacy Rights

You have the right to:

  • Access and review your medical records
  • Request corrections to your records
  • Receive an accounting of disclosures
  • Request restrictions on how we use your information
  • Request confidential communications
  • Receive a paper copy of this privacy policy
  • File a complaint if you believe your privacy rights have been violated

6. Data Security

We protect your information through:

  • Secure, encrypted electronic health record systems
  • Password-protected access controls
  • Regular staff training on privacy and security
  • Physical security measures at our facility
  • Secure communication channels for telehealth

7. Communication Privacy

Text and Email:

  • We may communicate with you via text, email, or video chat as requested
  • These channels may not be fully secure
  • You consent to communication via these methods by providing your contact information
  • You may opt out of non-essential communications at any time

Phone:

  • We may leave voicemails regarding appointments and general health matters
  • We will not leave detailed medical information without your consent

8. Website and Cookies

Our website may use cookies to:

  • Improve user experience
  • Analyze website traffic
  • Remember your preferences

You can disable cookies in your browser settings, though this may affect website functionality.

9. Third-Party Services

We may use third-party services for:

  • Payment processing
  • Electronic health records
  • Appointment scheduling
  • Communication platforms

These vendors are HIPAA-compliant and contractually obligated to protect your information.

10. Data Retention

We retain your medical records according to Utah state law and HIPAA requirements:

  • Adult records: Minimum of 7 years after last visit
  • Minor records: Until age 25 or 7 years after last visit, whichever is longer
  • Billing records: Minimum of 7 years

11. Breach Notification

In the unlikely event of a data breach affecting your information, we will:

  • Investigate the breach immediately
  • Notify affected individuals as required by law
  • Take corrective action to prevent future breaches
  • Report to appropriate authorities as required

12. Children’s Privacy

We collect and maintain health information for pediatric patients as part of our family care services. Parents and legal guardians have the right to access and control their children’s health information in accordance with applicable laws.

13. Changes to Privacy Policy

We may update this privacy policy to reflect changes in our practices or legal requirements. We will post updated policies on our website and in our office. Significant changes will be communicated to active members.

14. Contact Us

For questions about these Terms of Service or Privacy Policy, or to exercise your privacy rights, please contact:

Summit Direct Health CareTooele, Utah

You may also file a complaint with:

  • U.S. Department of Health and Human Services
  • Office for Civil Rights

Consent and Acknowledgment

By enrolling in Summit Direct Health Care’s membership program, you acknowledge that you have read, understood, and agree to these Terms of Service and Privacy Policy. You consent to the collection, use, and disclosure of your information as described herein.

Effective Date: Upon enrollment or first use of services