Effective date / Last updated: August 13, 2026
1. Introduction
Access Multi-Specialty Medical Clinic, Inc. (“Access Multi-Specialty,” “the Practice,” “we,” “us,” or “our”) operates the website located at accessmultispecialty.com (the “Website”). This Privacy Policy explains how we collect, use, share, and protect information gathered through the Website, including the online appointment request form hosted on Microsoft 365 Forms (forms.cloud.microsoft) and any contact or inquiry features on the site.
This Privacy Policy is separate from our Notice of Privacy Practices. As a HIPAA-covered health care provider, we maintain a separate Notice of Privacy Practices that governs Protected Health Information (“PHI”). The use and disclosure of PHI — and, for substance use disorder records, information protected by 42 CFR Part 2 — are governed by that Notice, HIPAA, and applicable California law, not by this Privacy Policy. To the extent any information you submit through this Website is PHI, including information on the appointment request form, the Notice of Privacy Practices controls.
2. Information We Collect
We collect the following categories of information through the Website:
- Contact information. When you use our contact features, you may provide your name, email address, telephone number, and any details you include in a message.
- Appointment request data. Through our secure Microsoft 365 Form, you may provide demographic, insurance, and health-related information to request an appointment. Health-related information you submit is treated as PHI (see Section 1).
- Site analytics and cookies. When you visit the Website, our hosting provider and any analytics or security tools we use may collect standard technical information such as your IP address, browser type and version, device type, referring pages, pages viewed, and the dates and times of your visit, using cookies or similar technologies.
- Third-party embed data. Features embedded in the Website, such as Google Maps on our Contact page and the Microsoft 365 form, may collect information about you independently. See Section 6.
3. How We Use Information
We use information collected through the Website to:
- Receive, review, schedule, and confirm appointment requests;
- Verify insurance coverage, benefits, and eligibility, and process billing;
- Respond to your questions, messages, and requests;
- Operate, maintain, secure, and improve the Website; and
- Comply with our legal, regulatory, and professional obligations.
We use and disclose PHI only as described in our Notice of Privacy Practices. We do not use information collected through this Website for targeted advertising, and we do not use it to make automated decisions that produce legal or similarly significant effects about you.
Text messages, reminders, and telehealth
With your consent — whether verbal or written — we may send appointment reminders and related communications by telephone, text message (SMS), or email through our electronic health record and practice-management system. Message and data rates may apply, and you may opt out at any time by contacting our office or, for text messages, by replying STOP where supported. If we provide care by telehealth (by video or by telephone), we do so using means intended to protect your privacy and consistent with HIPAA and California law, and any third-party telehealth platform we use operates under a Business Associate Agreement.
4. How We Share Information
We share information only in the following limited circumstances:
- Service providers and business associates. We use vendors that perform services on our behalf, such as Microsoft Corporation for our Microsoft 365 email and appointment form, our electronic health record and practice-management provider, and our website hosting provider. Where these vendors handle PHI, they do so under a HIPAA Business Associate Agreement that requires them to safeguard the information to the same standards we follow.
- When required by law. We may disclose information where required by applicable law, legal process, or a governmental request.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
5. California Privacy Rights (CCPA/CPRA)
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”), gives California residents certain rights regarding their personal information. Much of the information we handle is exempt from the CCPA because it is PHI governed by HIPAA or medical information governed by the California Confidentiality of Medical Information Act (“CMIA”); that information is addressed by our Notice of Privacy Practices. The disclosures below apply to personal information collected through the Website that is not otherwise exempt.
Categories collected and disclosed in the past 12 months
Identifiers (such as name, email address, telephone number, and IP address); California customer records information (such as contact and insurance details you provide); internet or other electronic network activity (such as pages viewed and interactions with the Website); and approximate geolocation (inferred from IP address or map interactions). Where you choose to provide it, health-related information is generally exempt as PHI or medical information. We collect this information directly from you, automatically from your device, and from third-party embeds, and we disclose it, as needed, to the service providers described in Section 4 for the business purposes described in this Policy.
Your rights
- Right to know / access the categories and specific pieces of personal information we have collected about you.
- Right to delete personal information we have collected, subject to legal exceptions. State and federal medical-record retention laws override this right for medical records, which we must retain for the periods described in Section 7.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising, so no opt-out is necessary.
- Right to limit the use of sensitive personal information. To the extent we hold non-exempt sensitive personal information, we use it only for permitted business purposes such as providing and administering care.
- Right to non-discrimination for exercising any of these rights.
To exercise your rights, email info@accessmultispecialty.com or call (415) 857-1151. We will verify your identity, honor authorized-agent requests subject to verification, and respond within the timeframes required by the CCPA (generally within 45 days, with the possibility of a further extension).
6. Third-Party Embeds and Cookies
The Website includes services provided by third parties, which may independently collect information such as your IP address, device and browser data, and cookie identifiers, subject to their own privacy policies, over which we have no control:
- Google Maps (provided by Google LLC), embedded on our Contact page to display our location. See Google’s Privacy Policy at policies.google.com/privacy.
- Microsoft 365 Forms (provided by Microsoft Corporation), used for our appointment request form under a HIPAA Business Associate Agreement. See the Microsoft Privacy Statement at privacy.microsoft.com/privacystatement.
Cookies
Cookies are small files placed on your device. The Website does not use cookies to serve advertising or to track you across other websites. The cookies used support core functionality, security, and basic analytics, and the third-party embeds above may set their own cookies. You can control or delete cookies through your browser settings; disabling some cookies may affect how parts of the Website function.
7. Data Retention
- Website (non-PHI) data. We retain website analytics and general contact inquiries for up to two (2) years, after which they are deleted or de-identified, unless a longer period is required for security or legal reasons.
- Medical records and PHI. We retain patient medical records in accordance with applicable California and federal law — generally at least seven (7) years following the last date of service for adult patients, and for minor patients until at least one (1) year after the minor reaches age eighteen (18) and in no event less than seven (7) years. Documentation required by HIPAA is retained for at least six (6) years. Substance use disorder records are retained and handled in accordance with 42 CFR Part 2.
8. Security
We maintain reasonable administrative, physical, and technical safeguards designed to protect the information we collect, including encryption of data in transit (HTTPS), access controls, and Business Associate Agreements with vendors that handle PHI. However, no method of transmitting or storing information is completely secure, and we cannot guarantee absolute security.
Please do not send Protected Health Information or other sensitive details by unencrypted email. To share such information, please use our secure appointment request form or call us at (415) 857-1151.
9. Children’s Privacy
The Website is not directed to children under 13, and we do not knowingly collect personal information from children under 13 through the Website without parental consent. In accordance with California law, minors aged 12 and older may independently consent to certain mental health and substance use disorder services; in those cases, the minor’s privacy rights regarding that specific care are honored in accordance with state and federal law. PHI relating to minor patients is handled under our Notice of Privacy Practices. If we learn that we have collected a child’s information through the Website without required consent, we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the revised Policy on this page and update the date above. Material changes will be communicated by reasonable means, and your continued use of the Website after changes take effect constitutes acceptance of the revised Policy.
11. Contact Us
For questions about this Privacy Policy or to exercise your privacy rights, please contact our Privacy Officer:
Privacy Officer
Access Multi-Specialty Medical Clinic, Inc.
P.O. Box 351, Burlingame, CA 94011-0351
Phone: (415) 857-1151 | Fax: (650) 727-0551
General inquiries: info@accessmultispecialty.com
Billing questions: billing@accessmultispecialty.com
Insurance questions: insurance@accessmultispecialty.com