Privacy & Compliance

Privacy & HIPAA practices

How this website handles data, and how we handle patient information when we build systems for a practice.

No patient information is collected on this website

This website does not host contact forms, intake forms, patient portals, or file uploads. There is no place on this site to submit health information, and we do not ask visitors to do so.

The only conversion path is a phone call to our team. Please do not send clinical details, diagnoses, medical records, or any other protected health information (PHI) by unsecured email, text message, or voicemail.

What we do collect

Standard technical information created when any website is visited — such as browser type, device type, approximate region, referring page, and pages viewed — which is used only to keep the site working and to understand general traffic patterns.

If you call us, we collect the business contact details you choose to share so we can follow up about services for your practice. That is business contact information, not patient data.

HIPAA: how we work with practices

Jameela is a technology and growth implementation partner, not a covered entity. When an engagement involves creating, receiving, maintaining, or transmitting PHI on behalf of a practice, we operate as a business associate and execute a Business Associate Agreement (BAA) before any such data flows.

We design workflows around the minimum necessary standard: we collect only what is needed to book and follow up, and we keep clinical detail out of automated messaging by default.

Every third-party system in a build — CRM, messaging, scheduling, calling, storage, AI provider — is reviewed for whether it supports a BAA and a HIPAA-eligible configuration. Where a system does not, PHI is not routed through it, or the workflow is redesigned.

We do not claim that our platform or every possible integration is automatically HIPAA compliant. Compliance depends on your practice's policies, the specific vendors selected, and how each system is configured. We scope this explicitly during the audit and document it before implementation.

Safeguards we apply in engagements

Access to practice systems is limited to the team members who need it, granted through your own accounts and permissions rather than shared credentials, and revoked when an engagement or role ends.

Data is kept inside the practice-approved systems of record. We avoid copying patient data into spreadsheets, ad platforms, or analytics tools, and we do not use patient data to train models.

Marketing and analytics tracking is configured to exclude health-related identifiers and sensitive URL parameters from tags and pixels.

Patient rights and requests

If you are a patient of a practice we work with and want to access, correct, or delete your information, or exercise your HIPAA rights, contact that practice directly. They are the covered entity and control their records; we act only on their instructions.

Contact

Questions about this notice, our HIPAA posture, or a BAA: call (646) 983-9627 and ask for the compliance contact.

This page is general information about our practices and is not legal advice. Back to home