Privacy Policy
Effective Date: May 17, 2026
Last Updated: May 17, 2026
Romans Orthodontics ("Practice," "we," "us," or "our"), owned and operated by Dr. Nicholas Romans, DMD, MSD, is committed to protecting the privacy of our patients and website visitors. This Privacy Policy explains how we collect, use, disclose, and safeguard your information — both as a healthcare provider under federal and Arizona law, and as the operator of romansorthodontics.com.
This Policy incorporates our Notice of Privacy Practices as required by the Health Insurance Portability and Accountability Act (HIPAA), 45 C.F.R. Parts 160 and 164.
1. Information We Collect
1.1 Protected Health Information (PHI)
As a healthcare provider, we collect and maintain Protected Health Information as necessary to provide orthodontic care. This includes:
-
Name, date of birth, address, phone number, and email
-
Medical and dental history, medications, and allergies
-
Orthodontic records (photographs, X-rays, CBCT scans, models)
-
Treatment plans, clinical notes, and progress records
-
Insurance information and billing records
-
Payment history and financial agreements
1.2 Website and Technical Information
When you visit our website, we may automatically collect:
-
IP address and browser type
-
Pages visited and time spent on the Site
-
Referring website or search terms
-
Device type and operating system
-
Cookie identifiers (see Section 6)
1.3 Information You Submit
If you submit an appointment request, contact form, or email through our website, we collect the information you provide, which may include your name, phone number, email address, and the content of your message.
2. How We Use Your Information
2.1 Treatment, Payment, and Healthcare Operations (HIPAA Permitted Uses)
We use and disclose PHI without your separate written authorization for the following HIPAA-permitted purposes:
-
Treatment: Providing, coordinating, and managing your orthodontic care, including sharing information with referring dentists, specialists, and labs involved in your treatment
-
Payment: Billing and collecting fees, submitting insurance claims, verifying coverage, and processing payments
-
Healthcare Operations: Quality assessment, staff training, practice management, accreditation, legal compliance, and business planning
-
Appointment Reminders: Contacting you via phone, text, or email with appointment reminders and recall notices
-
Treatment Alternatives: Informing you of treatment options relevant to your care
2.2 Uses Requiring Your Authorization
We will obtain your written authorization before using or disclosing your PHI for purposes not described in Section 2.1, including:
-
Marketing communications (other than face-to-face or nominal value promotional gifts)
-
Sale of your PHI
-
Use of your photographs or treatment records in advertising or social media
-
Most uses of psychotherapy notes (not applicable to our scope of practice)
You may revoke a previously given authorization at any time in writing; revocation will not affect disclosures already made in reliance on the authorization.
2.3 Website Analytics
We use anonymized, aggregated technical information to understand how visitors use our Site, improve website content, and measure the effectiveness of our online presence. This data is not linked to your PHI.
3. Disclosures of Your Information
3.1 Disclosures Permitted or Required by Law
We may disclose your PHI without your authorization as required or permitted by law, including:
-
Public health reporting (e.g., communicable disease reporting to the Arizona Department of Health Services)
-
Reporting abuse, neglect, or domestic violence as required under Arizona law (A.R.S. § 13-3620)
-
Health oversight activities (e.g., audits by the Arizona Board of Dental Examiners)
-
Judicial and administrative proceedings pursuant to a court order or valid subpoena
-
Law enforcement purposes as permitted by HIPAA
-
Serious threats to health or safety
-
Workers' compensation programs
-
Military and veterans' activities (where applicable)
-
Decedents: disclosure to coroners, medical examiners, and funeral directors as permitted by law
3.2 Business Associates
We may share PHI with vendors and contractors ("Business Associates") who perform services on our behalf — such as billing companies, IT service providers, and dental labs — under written Business Associate Agreements that require them to protect your PHI in compliance with HIPAA.
3.3 Incidental Disclosures
Incidental disclosures that occur as a by-product of a permitted use (e.g., a patient in the waiting room overhearing staff) are permissible under HIPAA provided we have applied reasonable safeguards, which we do.
3.4 No Sale of PHI
Romans Orthodontics does not sell your PHI to third parties for any purpose.
4. Your HIPAA Patient Rights
You have the following rights with respect to your PHI. To exercise these rights, submit a written request to our Privacy Officer using the contact information in Section 9.
-
Right to Access: You have the right to inspect and obtain a copy of your PHI in a designated record set. We will provide access within 30 days of your request (with one possible 30-day extension). A reasonable, cost-based fee may apply for copies.
-
Right to Amend: You may request that we correct or amend your PHI if you believe it is inaccurate or incomplete. We may deny the request if we determine the record is accurate and complete.
-
Right to an Accounting of Disclosures: You may request a list of disclosures of your PHI that we have made for purposes other than treatment, payment, or healthcare operations, for the six years prior to your request.
-
Right to Request Restrictions: You may request that we restrict how we use or disclose your PHI. We are not required to agree to all requested restrictions, except that we must honor a request to restrict disclosure to a health plan if you pay for the service in full out of pocket.
-
Right to Request Confidential Communications: You may request that we communicate with you by alternative means or at an alternative location (e.g., contact you only at a specific phone number). We will accommodate reasonable requests.
-
Right to a Paper Copy of This Notice: You have the right to receive a paper copy of this Privacy Policy / Notice of Privacy Practices upon request.
-
Right to Be Notified of a Breach: You have the right to receive timely notification if there is a breach of your unsecured PHI.
5. Data Security
We implement administrative, physical, and technical safeguards to protect your PHI in compliance with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C). These include:
-
Encrypted electronic health records and secure data storage
-
Password-protected workstations and role-based access controls
-
Secure, encrypted patient communications where available
-
Staff training on HIPAA privacy and security practices
-
Physical security measures at our office location
No transmission over the internet or electronic storage is guaranteed to be 100% secure. If you submit information through an unsecured web form, you do so at your own risk. For sensitive communications, please call our office directly.
6. Cookies and Website Tracking
Our website may use cookies and similar tracking technologies to enhance your browsing experience and analyze site traffic. Cookies are small data files stored on your browser. You may configure your browser to refuse all cookies or to indicate when a cookie is being sent; however, some features of our Site may not function properly without cookies.
We do not use website cookies to collect PHI. Any analytics data collected is anonymized and not linked to your patient records.
7. Children's Privacy
We provide care to minor patients; however, our website is not designed to collect personal information directly from children under the age of 13. All information collected from or about minor patients is provided by and managed through their parent or legal guardian, consistent with HIPAA and the Children's Online Privacy Protection Act (COPPA).
8. Changes to This Privacy Policy
We reserve the right to change this Privacy Policy and our privacy practices at any time. Material changes will be posted on this page with a revised effective date. The revised policy will apply to all PHI we maintain at the time of the change. A paper copy of our current Notice of Privacy Practices is available at our office upon request.
9. How to File a Complaint
If you believe your privacy rights have been violated, you may:
-
Contact our Privacy Officer: Dr. Nicholas Romans, DMD, MSD — (623) 320-1222 or hello@romansorthodontics.com
-
File a complaint with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights: hhs.gov/ocr or by calling 1-800-368-1019
-
File a complaint with the Arizona Board of Dental Examiners: (602) 242-1492
We will not retaliate against you in any way for filing a complaint in good faith.
10. Contact — Privacy Officer
Romans Orthodontics — Privacy Officer
Dr. Nicholas Romans, DMD, MSD
3618 W. Anthem Way, Suite D120
Anthem, AZ 85086
Phone: (623) 320-1222
Email: hello@romansorthodontics.com
