PRIVACY POLICY
Plymouth Urgent Care
Effective Date: August 25, 2026 Last Updated: August 25, 2026
1. INTRODUCTION
Plymouth Urgent Care ("Company," "we," "us," "our") is committed to protecting your privacy and ensuring you have a positive experience on our website and when using our services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services, including our patient portal, online scheduling system, telehealth platform, and online payment systems.
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our website or services.
2. SCOPE AND APPLICABILITY
This Privacy Policy applies to:
- Our website and all associated web pages
- Patient portal and login systems
- Online scheduling and appointment management
- Telehealth services and virtual consultations
- Online payment processing
- All information collected through contact forms and inquiries
Business Location: Plymouth Urgent Care 41424 Ann Arbor Rd Plymouth, MI 48170
Contact for Privacy Inquiries: Email: plymouthcare@plymouthurgentcare.com or bloomfieldurgentcare@gmail.com
Governing Law: This Privacy Policy is governed by the laws of the State of Michigan and complies with federal healthcare privacy regulations.
3. LEGAL FRAMEWORK & COMPLIANCE
3.1 HIPAA and HITECH Act Compliance
Plymouth Urgent Care is a Covered Entity under the Health Insurance Portability and Accountability Act (HIPAA) and HITECH Act. We are required to comply with:
- HIPAA Privacy Rule (45 CFR §§ 164.100-164.534) — Protects the privacy of Protected Health Information (PHI)
- HIPAA Security Rule (45 CFR §§ 164.300-164.318) — Establishes standards for electronic PHI (ePHI) security
- HIPAA Breach Notification Rule (45 CFR §§ 164.400-414) — Requires notification of unauthorized access to PHI
- HITECH Act (42 U.S.C. §§ 17921-17954) — Enhances privacy and security protections
Our practices align with these regulations to protect your Protected Health Information.
3.2 Michigan State Privacy Laws
We comply with Michigan's healthcare privacy and data protection laws, including:
- Michigan Medical Records Act (MCL 333.26201 et seq.)
- Michigan Data Breach Notification Act (MCL 445.72)
- All applicable state breach notification requirements
3.3 Federal Compliance
We comply with:
- State breach notification laws (Michigan requires notification within a reasonable time, typically 60 days)
- FTC Standards for Safeguarding Patient Information
- CMS requirements for Medicare/Medicaid beneficiaries
4. INFORMATION WE COLLECT
4.1 Information You Directly Provide
We collect information you voluntarily provide when you:
Patient Registration & Medical Records:
- Full legal name, date of birth, gender
- Medical and surgical history
- Current medications and allergies
- Medical conditions and diagnoses
- Vital signs and clinical notes
- Laboratory results and imaging reports
- Prescription information
Contact Information:
- Phone number(s)
- Email address
- Mailing address
- Emergency contact names and information
Insurance Information:
- Insurance provider name and plan details
- Policy/member ID numbers
- Group numbers
- Insurance company contact information
Payment Information:
- Credit card, debit card, or ACH details (processed securely; we do not store full card numbers)
- Billing address
- Payment history
Appointment Information:
- Scheduled appointment dates and times
- Reason for visit
- Preferred communication methods
- Insurance verification details
Telehealth Services:
- Video call participation records
- Audio/visual data transmitted during telehealth sessions
- Device information used for telehealth access
Website Communication:
- Information submitted through contact forms
- Email inquiries
- Patient portal messages
- Feedback and survey responses
4.2 Information Collected Automatically
Website Analytics & Cookies:
- We use essential cookies to maintain your login sessions and site functionality
- IP address and device identifiers
- Browser type and version
- Operating system
- Pages visited and time spent on each page
- Referring website URLs
- General geographic location (city/state level, not exact address)
Patient Portal & Systems:
- Login dates and times
- Documents accessed
- Features used within the portal
- Session duration and activities
Telehealth Platform:
- Connection logs and quality metrics
- Session start/end times
- Technical issues or dropped connections
- Device type and internet connectivity information
4.3 Information from Third Parties
We may receive information about you from:
- Insurance companies (verification, eligibility, claims)
- Referring physicians or healthcare providers
- Labs and imaging centers (test results)
- Pharmacies (medication information)
- Business associates providing services on our behalf
- Public health authorities (for reporting requirements)
5. HOW WE USE YOUR INFORMATION
5.1 Primary Uses (Treatment, Payment, Operations)
We use your information to:
Direct Healthcare:
- Diagnose and treat your medical conditions
- Provide urgent care services and consultations
- Conduct telehealth appointments and video consultations
- Monitor your health and treatment outcomes
- Communicate with you about your care and health status
- Manage prescriptions and medication information
Billing & Payment:
- Process insurance claims and payments
- Generate invoices and billing statements
- Verify insurance coverage and eligibility
- Manage accounts receivable
- Process payment transactions securely
- Resolve billing disputes
Operations & Administration:
- Schedule and confirm appointments
- Maintain medical records
- Verify your identity for security purposes
- Respond to your inquiries and requests
- Comply with legal and regulatory obligations
- Improve our services and operational efficiency
- Train staff on patient care and privacy practices
- Conduct quality assurance and peer review
5.2 Secondary Uses
Business & Clinical Functions:
- De-identified research (with appropriate controls)
- Clinical audits and utilization review
- Credentialing and privileging activities
- Licensing and accreditation compliance
- Required public health reporting
- Fraud and abuse prevention and detection
Communication:
- Appointment reminders (email, text, phone)
- Lab result notifications
- Prescription refill reminders
- Clinical updates related to your care
- Administrative communications
Patient Portal & Technology:
- Enhancing website functionality
- Troubleshooting technical issues
- Improving user experience (essential analytics only)
- Maintaining system security and performance
5.3 Marketing & Promotional Communications
Opt-In Requirement: We will only send you promotional emails, newsletters, or marketing materials about our services if you explicitly opt-in to receive them.
- You may opt-in at registration or any time through your patient portal
- You may withdraw consent at any time by clicking "unsubscribe" in emails or contacting us
- Marketing communications will never include your full medical information
- We will not sell or rent your email address for marketing purposes
5.3a SMS / Text Messaging
If you provide your mobile number and opt in through our website chat widget, you consent to receive text messages from BEST CARE PLLC (Plymouth Urgent Care). The widget collects consent separately for two message types: (1) customer-care messages, such as visit-related notifications, appointment coordination, and requests to review your experience; and (2) promotional messages, such as special offers, discounts, and service announcements.
Each consent is independent — you may opt into either or both, and promotional consent is never combined with customer-care consent. Message frequency varies. Message and data rates may apply. You can reply STOP at any time to opt out, or HELP for assistance.
Consent to receive text messages is not a condition of any purchase or of receiving care.
Your mobile information is never shared. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors strictly to support our services (such as customer service or message delivery) is permitted. All other categories of data exclude text-messaging originator opt-in data and consent; this information will not be shared with any third parties.
5.4 Uses We Do NOT Permit
We will not use your information for:
- Selling or renting your personal data to third parties for profit
- Marketing unrelated products or services (without prior explicit consent)
- Discriminatory practices
- Any use that violates HIPAA, HITECH, or applicable state laws
6. HOW WE SHARE YOUR INFORMATION
6.1 Permitted Disclosures (Treatment, Payment, Operations)
We share your Protected Health Information with the following without additional authorization:
Healthcare Providers:
- Physicians and clinicians treating you
- Specialists and consultants you're referred to
- Other healthcare facilities for continuity of care
- Emergency services and first responders (in emergencies)
Insurance & Payment:
- Your insurance company for claims processing and coverage verification
- Pharmacy benefit managers for prescription authorization
- Payment processors and financial institutions (payment information only)
Business Associates:
- Electronic Health Record (EHR) system vendors (legally bound by Business Associate Agreements)
- Laboratory and imaging centers
- Pharmacy networks
- Telehealth platform providers
- IT service providers and cloud storage providers
- Billing and collection agencies
Public Health & Legal:
- Public health authorities (disease reporting, epidemiology)
- Law enforcement (with valid court orders)
- Judicial or administrative proceedings (with subpoena or court order)
- Workers' compensation authorities
- Department of Health and Human Services for HIPAA enforcement
6.2 Prohibited Disclosures
We will NOT disclose your Protected Health Information for:
- Marketing purposes (beyond treatment-related communications) without your written consent
- Sale or rental to third parties
- Non-emergency law enforcement without court order
- Employer reporting (except workers' comp)
- Insurance underwriting or employment decisions (with limited exceptions)
6.3 Your Right to Restrict Sharing
You have the right to request restrictions on our use and disclosure of your health information. To request restrictions, contact our Privacy Officer at the email addresses above.
7. DATA RETENTION & DESTRUCTION
7.1 Medical Records Retention
Plymouth Urgent Care retains patient medical records in accordance with:
- Federal Requirements: Minimum 6 years from date of treatment (CMS requirement)
- Michigan Law: Minimum 7 years from the date of treatment
- Pediatric Records: Until the patient reaches age of majority plus 7 years (or per state law, whichever is longer)
7.2 Record Destruction
After the retention period expires, we will:
- Securely destroy or de-identify physical records (shredding, incineration)
- Permanently delete electronic records (through secure data wiping or destruction)
- Ensure destruction is documented
7.3 Operational Records
Other information (logs, analytics, contact forms) is retained for:
- 3 years for administrative and operational purposes
- Longer if required by law or for legal proceedings
8. DATA SECURITY & SAFEGUARDS
8.1 Security Measures
We implement comprehensive administrative, physical, and technical safeguards to protect your information:
Administrative:
- HIPAA-compliant policies and procedures
- Regular employee privacy and security training
- Access controls and minimum necessary standards
- Incident response and breach notification procedures
- Regular risk assessments and audits
- Business Associate Agreements with all vendors
- Background checks for employees with PHI access
Physical:
- Restricted access to facilities and medical records
- Locked storage for paper records
- Alarm systems and surveillance where appropriate
- Environmental controls (fire suppression, climate control)
Technical:
- Encryption of data in transit (SSL/TLS) and at rest
- Secure authentication (passwords, multi-factor authentication)
- Firewalls and intrusion detection systems
- Regular security updates and patch management
- Secure disposal of devices and data
- Audit logs and system monitoring
- Secure backup and disaster recovery procedures
8.2 Patient Portal Security
Your patient portal login is protected by:
- Encrypted password transmission
- Session timeout for inactivity
- Secure communication protocols
- Authentication verification
8.3 Limitations on Security
While we implement industry-standard security practices, no system is completely secure. We cannot guarantee absolute security of information transmitted over the internet. By using our services, you acknowledge this inherent risk.
9. DATA BREACH NOTIFICATION
9.1 Our Breach Response Protocol
In the event of a breach of unsecured PHI, we will:
- Investigate and Assess:
- Determine what information was accessed
- Identify affected individuals
- Assess whether the breach poses significant risk of harm
- Notify Affected Individuals:
- Provide written notification without unreasonable delay (within 60 days per Michigan law)
- Include description of breach, information involved, steps we're taking
- Provide guidance on protective steps individuals can take
- Offer free credit monitoring if appropriate
- Notify Media:
- If breach affects 500+ Michigan residents, we will notify major media outlets
- Notify HHS (Breach Notification Rule):
- For breaches affecting 500+ individuals, notify Department of Health & Human Services
- For smaller breaches, maintain documentation for HHS review
- Document & Report:
- Maintain incident documentation
- Implement corrective actions to prevent future breaches
- Report to regulatory authorities as required
9.2 Breach Definition
A breach is an unauthorized acquisition, access, use, or disclosure of PHI that compromises its security or privacy. We consider whether reasonable safeguards were in place and whether the unauthorized person likely acquired or accessed information.
9.3 Your Notification Rights
You will receive notification containing:
- Date and nature of the breach
- Types of information involved
- Likely timing of notification process
- Steps we're taking to investigate, mitigate, and prevent recurrence
- Contact information and resources for affected individuals
10. YOUR PRIVACY RIGHTS
10.1 Right to Access Your Records
You have the right to access, inspect, and obtain a copy of your medical records and health information in our possession.
How to Request:
- Submit a written request to: plymouthcare@plymouthurgentcare.com or bloomfieldurgentcare@gmail.com
- Include sufficient information to identify your records
- We will respond within 30 days (or provide status update)
Format:
- We will provide records in the format you request, if readily producible
- Electronic format available upon request
- Portable format available (per patient rights)
Fees:
- We may charge reasonable fees for copying and mailing
10.2 Right to Amend or Correct Records
You may request amendment of health information you believe is inaccurate or incomplete.
How to Request:
- Submit a written amendment request to our Privacy Officer
- Include reason for amendment
- We will review and respond within 30 days
Our Review:
- We may deny amendment if we determine the information is accurate, complete, and from an authorized source
- If denied, you have the right to file a statement of disagreement
10.3 Right to an Accounting of Disclosures
You may request an accounting of disclosures—a list of entities to whom we've disclosed your PHI.
Limitation:
- Accounting is limited to disclosures made in the past 6 years
- Does not include disclosures for treatment, payment, or operations
- Does not include disclosures you authorized in writing
How to Request:
- Contact our Privacy Officer at the emails listed above
- We will provide within 30 days
10.4 Right to Opt-Out of Sharing
You may request restrictions on our use and disclosure of your health information for treatment, payment, and operations (with some limitations).
How to Request:
- Submit a written request to our Privacy Officer
- Specify which uses or disclosures you wish to restrict
- Note: We may not restrict disclosures required by law
10.5 Right to Delete Information (Where Applicable)
You may request deletion of your health information in certain circumstances, particularly:
- Information created after you request deletion
- For marketing lists and opt-out requests
- Subject to legal retention requirements
How to Request:
- Contact our Privacy Officer
- Note: We cannot delete information required to be retained by law
10.6 Right to Confidential Communications
You may request that we contact you using alternative methods or locations (e.g., email instead of phone, work address instead of home).
How to Request:
- Submit a written request through your patient portal or to our Privacy Officer
- We will honor reasonable requests without asking for reason
10.7 Right to Revoke Authorization
Any authorization you provide can be revoked in writing at any time, except to the extent we have already relied upon that authorization.
11. COOKIES, ANALYTICS & WEBSITE TRACKING
11.1 Cookie Policy
Our website uses essential cookies only to:
- Maintain your login session
- Remember your portal preferences
- Provide basic website functionality
- Ensure security
Essential Cookies:
- Session ID cookies (expire when you close your browser)
- Security/authentication cookies
- Functionality cookies (language preference, accessibility settings)
Non-Essential Cookies:
- We do NOT use marketing, tracking, or non-essential analytics cookies
- We do NOT use third-party tracking pixels or cookies
- We do NOT use cookies for profiling or behavioral advertising
11.2 Your Cookie Choices
- You may disable non-essential cookies in your browser settings
- Essential cookies cannot be disabled as they are necessary for website function
- Disabling essential cookies may prevent you from using the patient portal
11.3 Website Analytics
We use minimal analytics to understand:
- Pages visited (not personal activity)
- General performance metrics
- User experience improvements
No Personal Tracking:
- We do not track individual user behavior
- We do not create user profiles for marketing
- We do not share analytics data with third parties
12. THIRD-PARTY SERVICES & LINKS
12.1 Business Associates
Our Business Associates (vendors providing services on our behalf) are required to:
- Sign a Business Associate Agreement (BAA)
- Comply with HIPAA and HITECH requirements
- Implement similar security and privacy protections
- Use your information only as directed by us
- Maintain confidentiality of your information
Current Business Associates:
- EHR system vendor
- Telehealth platform provider
- Billing and payment processors
- Cloud storage and IT service providers
- Laboratory and imaging partners
- Pharmacy networks
12.2 Third-Party Websites & Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of external sites. When visiting third-party sites:
- Review their privacy policies
- Understand their practices and protections
- We are not liable for their data handling
12.3 Social Media
If we maintain social media accounts, we will:
- Not require you to connect through social media to use our services
- Not collect personal information from your social media profiles
- Request that you not post sensitive health information in comments
13. SPECIAL POPULATIONS
13.1 Pediatric Patients
For patients under 18:
- Parents/guardians have access to medical records (with legal exceptions)
- We comply with state law regarding consent for treatment
- Information is treated with same privacy protections as adult patients
- Records retained until age of majority plus 7 years
13.2 Deceased Patients
For deceased patients:
- We follow HIPAA regulations regarding access to health information
- Family members may access records through authorized representative
- Information is retained per legal requirements
14. CONTACT & COMPLAINTS
14.1 Privacy Officer Contact
For privacy questions, requests, or concerns:
Email: plymouthcare@plymouthurgentcare.com or bloomfieldurgentcare@gmail.com
Response Time:
- We will acknowledge receipt within 5 business days
- We will respond or provide status update within 30 days
14.2 Filing a Complaint
You may file a complaint if you believe we've violated your privacy rights.
File with Us:
- Submit a written complaint to our Privacy Officer
- We will investigate and respond within 30 days
- We will not retaliate against you for filing a complaint
File with HHS:
- File with the Office for Civil Rights (OCR):
- Website: www.hhs.gov/ocr
- Mail: U.S. Department of Health & Human Services Office for Civil Rights 200 Independence Avenue, S.W. Washington, D.C. 20201
- Phone: 1-800-368-1019
- Email: ocrmail@hhs.gov
- Filing Deadline: Within 180 days of the violation (extendable in certain circumstances)
15. POLICY CHANGES & UPDATES
15.1 Changes to This Policy
We reserve the right to update this Privacy Policy as our practices evolve or when required by law.
Notice of Changes:
- We will post updated policy on our website
- We will highlight changes and update the "Last Updated" date
- Material changes will be communicated via email to registered users
- Continued use of our services constitutes acceptance of updated terms
15.2 Effective Date
This policy is effective as of August 25, 2026.
16. ACKNOWLEDGMENT & CONSENT
By registering for our patient portal or receiving care, you acknowledge:
- You have read this Privacy Policy
- You understand how your information is used and protected
- You consent to our collection and use of information as described
- You understand your rights regarding your health information
You may revoke this acknowledgment in writing at any time.
APPENDIX A: GLOSSARY OF TERMS
- Breach: Unauthorized acquisition, access, use, or disclosure of PHI
- Business Associate: Third party that creates, uses, or discloses PHI on behalf of a covered entity
- Covered Entity: Healthcare provider (like Plymouth Urgent Care) subject to HIPAA
- De-identified Information: Information from which personally identifiable elements have been removed
- Electronic Health Record (EHR): Digital version of patient's medical record
- HIPAA: Health Insurance Portability and Accountability Act
- HITECH Act: Health Information Technology for Economic and Clinical Health Act
- PHI: Protected Health Information—any information that identifies a patient
- ePHI: Electronic PHI—PHI in electronic format
- Minimum Necessary: Using/disclosing only the minimum amount of PHI needed for a specific purpose
APPENDIX B: STATE-SPECIFIC NOTICES
Michigan Notice
Michigan Data Breach Notification Law (MCL 445.72):
- Plymouth Urgent Care will notify individuals of unauthorized access to personal information without unreasonable delay
- Notification will include nature of breach and steps to protect against identity theft
- We will also notify media if breach affects 500+ Michigan residents
- We maintain reasonable security standards as defined by Michigan law
Michigan Medical Records Act (MCL 333.26201 et seq.):
- You may request copy of your medical records
- You may authorize release to other providers
- You may request amendment of inaccurate records
- We retain records for minimum 7 years per Michigan requirements
Document Version: 1.0 Prepared by: Legal Compliance Last Reviewed: August 25, 2026
This Privacy Policy is provided for informational purposes. If there are any conflicts between this policy and HIPAA regulations or Michigan law, the regulatory requirements will prevail.