PRIVACY POLICY

Precision Specialty Care, PLLC  |  doing business as Vanpoint Health

Effective Date: July 15, 2026  •  Last Updated: August 6, 2026

PLEASE READ THIS POLICY CAREFULLY. By accessing or using the Services, you acknowledge that you have received this Privacy Policy. Where consent or authorization is required by law, PSC will request it separately; use of the website alone does not constitute a HIPAA authorization.

1. Who We Are and Scope of This Policy

Precision Specialty Care, PLLC, a Texas professional limited liability company doing business as Vanpoint Health (collectively, “PSC,” “Vanpoint Health,” “we,” “our,” or “us”), operates the Vanpoint Health website, patient-facing digital services, and related care platform. Vanpoint Health is a trade name of PSC and is not a separate legal entity.

This Privacy Policy describes how PSC collects, uses, discloses, retains, and safeguards information when you visit www.vanpointhealth.com; communicate with us; request information; enroll in services; use our website, portal, forms, messaging, payment, or other online services; or otherwise interact with us (collectively, the “Services”). It is intended to be read together with our Terms of Use and Master Patient Services and Care Agreement.

This Policy does not apply to third-party websites or services that we do not control, even if linked from our Services. It also does not replace our HIPAA Notice of Privacy Practices (“NPP”), which governs PSC’s uses and disclosures of protected health information (“PHI”) as a HIPAA-covered health care provider. If this Policy conflicts with the NPP regarding PHI, the NPP and applicable law control.

2. Information We Collect

We may collect information directly from you, automatically from your device or use of the Services, and from authorized third parties.

Information you provide may include:

  • Identifiers and contact information, such as name, date of birth, email address, telephone number, mailing address, account username, and other identifiers.

  • Enrollment and account information, including authentication credentials, preferences, consents, attestations, and communications settings.

  • Health and care information, including medical history, symptoms, diagnoses, medications, allergies, treatment history, photographs, documents, questionnaire responses, patient-reported outcomes, location at the time of care, and communications with PSC.

  • Scheduling and service information, including appointment or case-review requests, deadlines, submissions, and participation in a care plan.

  • Payment and transaction information. Payment card information is generally collected and processed by a third-party payment processor; PSC may receive transaction confirmations, billing contact information, payment status, and limited payment-related details.

  • Communications and support information, including inquiries, messages, feedback, complaints, call or message metadata, and records of interactions with our team.

  • Information about a minor or another individual when submitted by a parent, legal guardian, personal representative, or other authorized person.

Information collected automatically may include:

  • Device and network data, such as IP address, browser and device type, operating system, language, approximate location derived from IP address, and unique device or session identifiers.

  • Usage data, such as pages viewed, referring and exit pages, dates and times of access, links selected, feature interactions, error logs, and performance information.

  • Cookies and similar technologies, such as first-party cookies, pixels, software development kits, local storage, and comparable technologies, subject to the limitations described below.

Information from authorized third parties may include information from health care providers, pharmacies, laboratories, insurers or benefit administrators, manufacturers’ assistance programs, technology vendors, payment processors, identity-verification services, or a person authorized by you, but only as permitted by law and applicable authorization or agreement.

3. How We Use Information

Depending on the context and applicable law, PSC may use information to:

  • Provide, coordinate, document, support, and improve medical care and the Services.

  • Establish and administer accounts, enrollment, identity verification, scheduling, structured reviews, messaging, and patient support.

  • Communicate about care plans, submissions, prescriptions, refills, monitoring, prior authorization support, safety issues, service changes, and administrative matters.

  • Process payments, prevent fraud, maintain transaction records, and enforce financial terms.

  • Operate, maintain, secure, troubleshoot, and improve our website, portal, workflows, and technology.

  • Perform quality assessment, compliance, auditing, analytics, training, and health care operations as permitted by law.

  • Comply with licensure, recordkeeping, public-health, legal, regulatory, and professional obligations; respond to lawful process; and protect patients, PSC, and others.

  • Create de-identified or aggregated information in accordance with applicable law for analytics, operations, service improvement, or research-related purposes.

  • Send educational materials, practice updates, or marketing communications when permitted by law and, when required, with your authorization or consent.

We do not sell PHI. We do not use or disclose PHI for marketing, a sale of PHI, or other purposes requiring a HIPAA authorization unless we first obtain a valid authorization or an exception under applicable law applies.

4. HIPAA and Protected Health Information

Once information is created, received, maintained, or transmitted by PSC in its capacity as a health care provider and is individually identifiable health information, it may constitute PHI under HIPAA. PHI is governed by HIPAA, other applicable health-privacy laws, and PSC’s NPP—not solely by this website Privacy Policy.

As described more fully in the NPP, PSC may generally use and disclose PHI without a separate written authorization for treatment, payment, and health care operations and for other purposes permitted or required by law. Examples may include coordinating care with another provider, obtaining payment, conducting quality and compliance activities, responding to certain public-health or health-oversight requirements, preventing or lessening a serious and imminent threat where legally permitted, and complying with legal process.

When HIPAA requires written authorization, PSC will request an authorization that satisfies applicable requirements. You may revoke an authorization in writing, except to the extent PSC has already acted in reliance on it or applicable law otherwise provides.

PSC applies the HIPAA minimum-necessary standard where required. The minimum-necessary rule generally does not apply to disclosures for treatment, disclosures to the individual, uses or disclosures made pursuant to a valid authorization, or other exceptions recognized by law.

5. Your HIPAA Rights

Subject to applicable law and the limitations described in PSC’s NPP, you may have the right to:

  • Inspect or obtain a copy of PHI in a designated record set, including an electronic copy when required.

  • Request an amendment of PHI you believe is inaccurate or incomplete. PSC may deny a request in circumstances permitted by law and will explain qualifying denials.

  • Request restrictions on certain uses or disclosures. PSC is generally not required to agree, except that HIPAA may require PSC to honor a request not to disclose information to a health plan for payment or operations when the disclosure concerns an item or service paid in full out of pocket and other requirements are met.

  • Request confidential communications by an alternative method or at an alternative location when the request is reasonable.

  • Receive an accounting of certain disclosures of PHI.

  • Obtain a paper or electronic copy of PSC’s NPP.

  • Choose a personal representative, subject to verification of that person’s authority and applicable law.

  • File a privacy complaint with PSC or the U.S. Department of Health and Human Services, Office for Civil Rights, without retaliation.

These rights apply to PHI and are subject to HIPAA’s requirements, exceptions, identity-verification rules, response periods, and permitted fees. Instructions for exercising these rights appear in PSC’s NPP or may be obtained using the contact information below.

6. When We Disclose Information

PSC may disclose information in the following circumstances, subject to HIPAA and other applicable law:

  • To treating providers and care participants for treatment and care coordination.

  • To health plans, payment partners, pharmacies, laboratories, manufacturers’ programs, and other entities involved in payment, access, or fulfillment, when permitted and appropriate.

  • To service providers and business associates that perform functions for PSC, such as hosting, secure communications, electronic health records, scheduling, payment processing, analytics, cybersecurity, document management, support, or professional services. Business associates that handle PHI for PSC must be bound by a HIPAA-compliant business associate agreement when required.

  • To government agencies, regulators, licensing boards, courts, law enforcement, public-health authorities, or other persons when required or permitted by law.

  • To prevent fraud, address security events, enforce our agreements, protect rights and safety, or establish, exercise, or defend legal claims.

  • In connection with a merger, financing, reorganization, sale, or transfer involving PSC, subject to applicable confidentiality, HIPAA, professional, and legal restrictions.

  • At your direction, with your consent, or pursuant to a valid authorization.

Vendors are permitted to access information only for authorized services and applicable legal purposes. A vendor’s independent collection or use, if any, is governed by its own role, contract, and legal obligations.

7. Cookies, Analytics, and Online Tracking Technologies

We may use cookies and similar technologies for functions such as authentication, security, fraud prevention, preferences, performance measurement, and understanding how the public portions of our website are used. These technologies may collect device, network, and usage information.

Health information and browsing activity can be sensitive. PSC will not knowingly configure a tracking technology to disclose PHI to a third party unless the disclosure is permitted by HIPAA and other applicable law and any required business associate agreement or authorization is in place. We do not treat a website banner’s acceptance of cookies as a HIPAA authorization.

We may use analytics tools, including Google Analytics or a comparable service, on public-facing pages only as configured and permitted by applicable law. We seek to limit or disable advertising-oriented tracking and do not intend to place third-party advertising pixels or session-replay technology on authenticated patient-portal pages, medical intake forms, clinical messaging areas, or payment pages in a manner that impermissibly discloses PHI.

You may manage cookies through available website controls or browser settings. Blocking cookies may impair authentication, security, preferences, or other functionality. Browser-based “Do Not Track” signals are not uniformly standardized; where legally required, we will respond to recognized opt-out preference signals as applicable.

Important implementation requirement: this section describes PSC’s intended practices and must remain consistent with the website’s actual cookie, analytics, advertising, and portal configuration.

8. Communications, Email, and Text Messages

PSC may communicate with you through the portal, email, telephone, or text message for administrative, care-related, security, and service purposes, consistent with your preferences and applicable law. Standard email and text messaging may not be fully secure, and message previews may be visible to anyone with access to your device or account.

You are responsible for providing accurate contact information and promptly notifying PSC of changes. You may opt out of nonessential marketing emails using the unsubscribe mechanism and may opt out of nonessential text messages as instructed in the message. Opting out of marketing does not prevent PSC from sending nonmarketing communications about care, transactions, safety, security, legal notices, or the Services when permitted by law.

Do not use ordinary email, text messaging, website contact forms, or portal messaging for emergencies or urgent concerns. The Services are not continuously monitored.

9. Artificial Intelligence and Automated Tools

PSC may use software, automation, and artificial intelligence tools to assist with organization, summarization, documentation, routing, administrative processing, operational analytics, and clinical workflow support. These tools do not independently diagnose, prescribe, or replace the treating physician’s professional judgment.

When PHI is processed by a technology vendor on PSC’s behalf, PSC will address the vendor’s HIPAA role and contractual obligations as required. PSC uses administrative, technical, and contractual controls designed to limit access and use to authorized purposes. Information will not be used to train a third party’s general-purpose model when such use would be inconsistent with PSC’s agreement, HIPAA, or applicable law.

10. Data Security

PSC maintains reasonable and appropriate administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of information, including electronic PHI. Measures may include access controls, authentication, encryption where appropriate, workforce training, vendor management, monitoring, backups, incident response, and risk-management processes.

No website, network, transmission, or storage system can be guaranteed completely secure. You are responsible for safeguarding your credentials, using secure devices and networks, signing out of shared devices, and promptly reporting suspected unauthorized access.

11. Security Incidents and Breach Notification

PSC investigates suspected privacy and security incidents and takes response and mitigation measures appropriate to the circumstances. If an incident constitutes a breach requiring notice, PSC will provide notifications to affected individuals, the U.S. Department of Health and Human Services, and, when applicable, the media or other regulators in the manner and time required by the HIPAA Breach Notification Rule and other applicable law.

Not every security incident constitutes a legally reportable breach. PSC will conduct any assessment required by law and will not delay legally required notice beyond an applicable deadline.

12. Data Retention and Disposal

PSC retains information for as long as reasonably necessary to provide the Services, maintain medical and business records, meet legal and professional obligations, resolve disputes, enforce agreements, support security and auditing, and fulfill the purposes described in this Policy. Retention periods vary based on the type of information, patient age, applicable record-retention law, limitation periods, contractual requirements, and operational need.

When information is no longer required, PSC may delete, destroy, de-identify, or archive it using methods appropriate to its sensitivity and applicable law. A request to delete general personal information does not require PSC to delete medical records or other information it must or is permitted to retain.

13. Children and Minors

The public website is directed to adults and is not intended for independent use by children under 13. PSC may provide care to minors when a parent, legal guardian, or other person authorized by law participates and provides required information and consent.

Rights to a minor’s health information depend on who may consent to care, the nature of the care, the minor’s status, and applicable federal and state law. PSC may verify identity, parental status, guardianship, or other legal authority before granting access or acting on a request.

14. Your General Privacy Choices

Depending on the information and applicable law, you may ask to review or correct account information, update communication preferences, opt out of marketing, manage cookies, or request information about our privacy practices. HIPAA rights must be exercised through the processes described in the NPP.

We may need to verify your identity and authority before acting on a request. We may deny or limit a request when permitted or required by law, including where information is part of a medical record, must be retained, relates to another person, is subject to legal privilege, or is needed for security, fraud prevention, compliance, or legal claims.

We do not discriminate or retaliate against an individual for exercising a privacy right protected by law.

15. External Links and Third-Party Services

The Services may link to or integrate with third-party websites, pharmacies, laboratories, payment services, scheduling tools, or other resources. When a third party acts for PSC and handles PHI, HIPAA and a business associate agreement may apply. When you independently visit or use a third party’s service, that party’s privacy policy and terms may govern. PSC is not responsible for the independent privacy or security practices of third parties it does not control.

16. Changes to This Privacy Policy

PSC may revise this Policy to reflect changes in law, technology, vendors, or practices. The revised Policy will be posted with an updated effective date. Material changes will apply prospectively unless otherwise permitted by law, and PSC will provide additional notice or obtain consent when legally required.

Changes to PSC’s HIPAA privacy practices will be addressed through the NPP as required by HIPAA.

17. Contact Us and Privacy Complaints

For privacy questions, requests, suspected unauthorized access, or complaints, contact:

Privacy Officer
Precision Specialty Care, PLLC
doing business as Vanpoint Health
Email: [email protected]
Phone: (972) 910-2682
Website: www.vanpointhealth.com

3541 cedar cottage circle, Frisco Texas 75033

PSC will not retaliate against you for filing a good-faith privacy complaint or exercising a right protected by law.

Ready to Get Started?

Choose the path that's right for you. Take our eligibility quiz for personalized guidance, or sign up now if you're ready to begin.

Specialized eczema care from board-certified allergist Dr. John Van Wagoner.

Personalized treatment plans.

Ongoing support. Long-term results.

Specialist-led. Patient-focused. Evidence-based.

follow us

Questions?

We're here to help.

Copyright 2026. All Rights Reserved.

Precision Specialty Care, PLLC DBA Vanpoint Health