HIPAA · HITECH · CTIA SMS Compliant · DCA 7103

Privacy Policy

Sigma Orthopedics is committed to protecting your health information in full compliance with the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.

Last Updated: June 2025  |  Effective Date: June 1, 2025

Important Notice: This Privacy Policy describes how Sigma Orthopedics ("we," "us," or "our") collects, uses, discloses, and safeguards your Protected Health Information (PHI) and other personal data in connection with our website (sigmaorthopedics.com) and the medical services provided by Dr. Frank McCormick and the Sigma Orthopedics care team. By using our website or services, you acknowledge that you have read and understood this Privacy Policy.

Mobile Opt-In Data — We Do Not Share With Third Parties

Mobile opt-in data and consent, including phone numbers collected for SMS appointment reminders and care notifications, will not be shared with, sold to, or used by any third party for their own marketing or commercial purposes. This policy is in accordance with DCA Rejection Code 7103 requirements and applicable carrier compliance standards. See Section 5 for complete mobile communications and data sharing disclosures.

Table of Contents

  1. 1Information We Collect
  2. 2How We Use Your Information
  3. 3Sharing of Information
  4. 4Data Security
  5. 5SMS / Text Messaging, Terms & Conditions & Opt-Out Instructions
  6. 6Your Patient Rights Under HIPAA
  7. 7Data Retention & Disposal
  8. 8Breach Notification
  9. 9Contact Us
Section 1

Information We Collect

Sigma Orthopedics collects personal information, including Protected Health Information (PHI), to deliver safe and effective orthopedic care. PHI is any individually identifiable health information related to your past, present, or future physical or mental health, the provision of health care, or payment for health care services.

Information You Provide Directly

  • Appointment & Intake Forms: Name, date of birth, address, phone number, email address, insurance information, and chief complaint when you complete our appointment request, patient intake, or contact forms.
  • Medical History: Diagnoses, symptoms, surgical histories, medication lists, and prior imaging results that you disclose during consultations or intake.
  • Billing Information: Insurance policy details, member IDs, and payment information necessary to process claims or self-pay transactions.
  • Mobile Phone Number: When provided with opt-in consent for SMS appointment reminders or care notifications (see Section 5).

Information From Other Sources

  • Referring Providers: Referral letters, prior imaging and diagnostic results, operative reports, and medication lists shared by referring physicians or specialists.
  • Health Plans & Payers: Insurance eligibility, authorization decisions, and coordination-of-benefits information provided by your health plan or clearinghouse.
  • Laboratories & Imaging Centers: Test results and radiology reports ordered as part of your care.

Information Collected Automatically (Non-PHI)

  • Technical Data: IP address, browser type and version, operating system, pages visited, session duration, and referring URLs collected through cookies and similar technologies.
  • Analytics Data: Aggregated, non-identifiable usage patterns used to improve website functionality and user experience.

Website analytics data is non-PHI and is handled separately from your medical records. You may disable cookies through your browser settings, though doing so may affect certain site features.

Section 2

How We Use Your Information

We use the information we collect solely for purposes that are necessary, lawful, and directly related to providing you with high-quality orthopedic care. Under HIPAA, we are permitted to use your PHI for Treatment, Payment, and Healthcare Operations without requiring additional authorization.

Treatment

To provide, coordinate, and manage your orthopedic care — including consultations, preoperative planning, surgical procedures, post-operative monitoring, physical therapy coordination, and follow-up visits. This includes sharing relevant PHI with other treating providers directly involved in your care.

Payment

To verify insurance coverage, obtain prior authorizations, submit and adjudicate claims, process payments, and resolve billing inquiries. We share only the minimum necessary PHI required to complete payment transactions with your health plan and authorized billing partners.

Healthcare Operations

  • Quality assurance and patient safety review
  • Outcomes measurement and Six Sigma protocol improvement
  • Staff training and competency assessment
  • Compliance auditing and accreditation activities
  • Risk management and legal defense

Communications & Appointment Management

  • Sending appointment reminders, scheduling confirmations, and pre-operative instructions via phone, email, or SMS (when opted in).
  • Post-operative care follow-up and recovery milestone check-ins.
  • Responding to inquiries and requests you submit through our website or by phone.

Legal & Regulatory Compliance

To comply with applicable federal and New York State legal requirements, including mandatory public health reporting, court orders, law enforcement obligations, and government audits. We disclose only the minimum necessary PHI in these circumstances.

With Your Written Authorization

For any use or disclosure not described above — including marketing, research, or sharing with family members not directly involved in your care — we will obtain your explicit written authorization before proceeding. You may revoke that authorization at any time in writing, except to the extent we have already acted in reliance on it.

We do not use your PHI or personal information for advertising, data brokering, or any commercial purpose unrelated to your direct care.

Section 3

Sharing of Information

Sigma Orthopedics shares your personal information only in limited, clearly defined circumstances. We never sell, rent, or trade your PHI or personal data to any third party for marketing or commercial purposes.

Permitted Disclosures

  • Treatment Coordination: With other treating physicians, specialists, hospitals, physical therapists, laboratories, or imaging centers directly involved in your orthopedic care — limited to the minimum necessary PHI required for that care.
  • Payment Processing: With your insurance plan, clearinghouses, and authorized billing services to the extent required to submit and adjudicate claims on your behalf.
  • Business Associates: With HIPAA-compliant vendors and contractors who perform services on our behalf (e.g., EHR platforms, scheduling systems, billing services), under executed Business Associate Agreements (BAAs) that restrict their use of your PHI.
  • Legal Obligations: When required by law, court order, regulatory authority, or government agency — including mandatory public health reporting and law enforcement requests where legally compelled.
  • With Your Written Authorization: For any disclosure not described above — such as marketing, research, or sharing with individuals not directly involved in your care — we require your explicit written consent first.

What We Do Not Share

  • We do not sell or disclose PHI to data brokers, advertisers, or analytics companies.
  • We do not share your information with insurance underwriters for eligibility or risk assessment beyond your own claims processing.
  • We do not share mobile opt-in data or phone numbers with any third party for marketing or promotional purposes (see Section 5).
  • We do not permit our Business Associates to use your PHI for their own independent marketing or commercial purposes.

SMS Consent & Phone Number Non-Sharing Statement

SMS consent and phone numbers collected for SMS communication purposes will not be shared with any third party or affiliates for marketing purposes. This applies to all mobile phone numbers and associated opt-in consent records collected through our website forms, patient intake, or verbal agreement — regardless of whether the recipient is a Business Associate, affiliate, technology vendor, or unrelated entity. The sole permitted use of SMS opt-in data is to deliver care-related communications directly from Sigma Orthopedics to the consenting patient.

Summary Table

Data TypeShared WithPurposeSold / Marketed?
PHI (Medical Records)Treating providers, labs, payersTreatment & paymentNo
Mobile Opt-In NumberNo third partiesCare notifications onlyNo
Insurance InformationYour insurance plan & clearinghouseClaims processingNo
Website Analytics (non-PHI)Analytics vendors (BAA required)Site improvementNo
Email AddressCare team communication toolsAppointment & care follow-upNo
Section 4

Data Security

Sigma Orthopedics implements comprehensive administrative, physical, and technical safeguards consistent with HIPAA Security Rule requirements and HITECH Act provisions to protect the confidentiality, integrity, and availability of your electronic PHI (ePHI).

Administrative Safeguards

  • Formal HIPAA Privacy and Security Officer designation with defined responsibilities.
  • Workforce training on HIPAA privacy rights and data security practices completed annually.
  • Role-based access controls limiting PHI access to workforce members whose job functions require it.
  • Documented policies and procedures covering PHI use, disclosure, breach response, and sanctions for non-compliance.

Physical Safeguards

  • Secured facility access with controlled entry protocols for areas housing PHI.
  • Workstation security policies requiring locked screens when unattended.
  • Device and media disposal procedures that render PHI unrecoverable prior to equipment reuse or destruction.

Technical Safeguards

  • AES-256 encryption for ePHI at rest and TLS 1.2+ encryption for ePHI in transit.
  • Multi-factor authentication (MFA) required for all systems containing ePHI.
  • Automatic logoff and audit log controls on electronic health record (EHR) systems.
  • Regular vulnerability assessments and penetration testing of network infrastructure.
  • HITECH-compliant Business Associate Agreements (BAAs) executed with all technology vendors who access ePHI.

Breach Notification

Sigma Orthopedics maintains a formal Breach Notification Policy in accordance with the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D) and the HITECH Act. In the event of a breach affecting your PHI, we will notify you without unreasonable delay and in no case later than 60 calendar days from discovery. Breaches affecting 500 or more individuals are also reported to the HHS Secretary and, where applicable, to prominent New York State media outlets.

Limitations

No security measure is 100% impenetrable. While we apply industry-leading safeguards, we cannot guarantee absolute security of information transmitted over the internet. If you have concerns about the security of your information, please contact our Privacy Officer using the information in Section 9.

Section 5

SMS / Text Messaging, Terms & Conditions & Opt-Out Instructions

DCA Rejection Code 7103 Compliance: Mobile opt-in data and consent — including any phone number provided to receive SMS messages from Sigma Orthopedics — will not be shared with third parties for marketing or promotional purposes. This disclosure satisfies the requirements of DCA (Direct Carrier Aggregator) Rejection Code 7103 and applicable CTIA Messaging Guidelines.

5A. How We Collect Your Phone Number

Sigma Orthopedics collects mobile phone numbers in two ways:

  • Voluntary Submission: When you enter your mobile number into our appointment request form, contact form, or patient intake form and explicitly check the SMS opt-in consent box (see Section 5C for full opt-in language).
  • Verbal Consent During Scheduling: When you provide your mobile number to our scheduling team by phone and verbally agree to receive text message communications. A written record of that verbal consent is retained in your patient file.

Provision of a mobile phone number and opt-in consent is entirely voluntary. You may receive care from Sigma Orthopedics without consenting to SMS communications.

5B. How We Use Your Mobile Number

Mobile numbers collected through opt-in are used only for the following care-related purposes:

  • Appointment reminders and scheduling confirmations
  • Post-operative care follow-up notifications and recovery check-ins
  • Urgent care coordination messages initiated by your care team
  • Responses to inquiries you initiate via text message
  • Pre-operative preparation instructions from Dr. McCormick's care team

Mobile opt-in data — including your mobile phone number, opt-in consent record, and any associated preferences — will not be shared with, sold to, leased to, or otherwise disclosed to any third-party company for marketing, promotional, commercial, or any other purpose. This restriction applies regardless of whether such a third party is a Business Associate, affiliate, or unrelated entity.

5C. SMS Opt-In Consent — RingCentral Checkbox Language

When you submit an appointment request or contact form on our website, you will see the following opt-in checkbox. Checking this box constitutes your express written consent to receive automated text messages from Sigma Orthopedics via RingCentral:

"By checking this box, I consent to receive automated text messages from Sigma Orthopedics at the mobile number provided above, powered by RingCentral. These messages may include appointment reminders, scheduling confirmations, post-operative care notifications, and responses to my inquiries. Message frequency varies. Message and data rates may apply. Consent is not a condition of receiving care or making any purchase. Reply STOP to unsubscribe at any time. Reply HELP for assistance. View our Privacy Policy for full details."

↑ Verbatim opt-in checkbox text displayed on all Sigma Orthopedics web forms collecting mobile numbers.

Consent is not a condition of purchase or care. Checking or declining this box does not affect your ability to schedule an appointment, receive treatment, or access any service offered by Sigma Orthopedics. You may receive care without providing SMS consent.

5D. SMS Terms & Conditions

The following terms govern your participation in Sigma Orthopedics' SMS messaging program, operated via RingCentral as our messaging service provider:

TermDetail
Program NameSigma Orthopedics Patient Care Messaging
Message SenderSigma Orthopedics, P.C. via RingCentral
Message TypesAppointment reminders, scheduling confirmations, post-operative care follow-ups, pre-operative instructions, responses to patient-initiated inquiries
Message FrequencyMessage frequency varies based on your appointment schedule and care milestones. You may receive up to 4–6 messages per month during active care periods. No unsolicited promotional messages will be sent.
Message & Data RatesStandard message and data rates may apply depending on your mobile carrier and plan. Sigma Orthopedics does not charge a fee for its messaging program.
Supported CarriersAT&T, Verizon, T-Mobile, Sprint, Boost Mobile, U.S. Cellular, and most major U.S. carriers. Carrier availability may vary.
Opt-Out (STOP)Reply STOP to any message to unsubscribe immediately. You will receive one final confirmation message and no further messages will be sent.
Help (HELP)Reply HELP to any message to receive contact information and a link to this Privacy Policy.
Carrier LiabilityMobile carriers are not liable for delayed or undelivered messages. Sigma Orthopedics is not responsible for delivery failures caused by carrier networks.
Data SharingMobile opt-in data will NOT be shared with or sold to any third party for marketing purposes (DCA Code 7103 compliant).

5E. How to Opt Out of SMS Communications

You may opt out of SMS communications at any time using any of the following methods:

  • Reply STOP to any SMS message you receive from us. You will receive a one-time confirmation that your opt-out has been processed, and no further messages will be sent to that number.
  • Reply HELP to any SMS message to receive our support contact information and a direct link to this Privacy Policy.
  • Contact our Privacy Officer by phone at (332) 267-8918 or by email at privacy@sigmaorthopedics.com and request removal from our SMS contact list.

Opting out of SMS will not affect your ability to receive care or use any of our services. Standard message and data rates may apply.

Section 6

Your Patient Rights Under HIPAA

As our patient, you have the following rights regarding your PHI under the HIPAA Privacy Rule (45 CFR Part 164, Subpart E):

  • Right to Access: You may request and receive a copy of your medical records and other PHI we maintain. We will provide access within 30 days (or up to 60 days with one extension).
  • Right to Request Amendment: If you believe your PHI is inaccurate or incomplete, you may request a correction. We will respond within 60 days.
  • Right to an Accounting of Disclosures: You may request a list of disclosures of your PHI made by us (other than for treatment, payment, or operations) within the past six years.
  • Right to Request Restrictions: You may request restrictions on how we use or disclose your PHI for treatment, payment, or operations purposes. We are required to honor restrictions on disclosures to health plans for services you have paid for in full out-of-pocket.
  • Right to Confidential Communications: You may request that we contact you through alternative means or at alternative locations (e.g., call you at work rather than home).
  • Right to a Notice of Privacy Practices: You are entitled to receive a paper copy of our Notice of Privacy Practices upon request.
  • Right to File a Complaint: If you believe your privacy rights have been violated, you may file a complaint with us or with the U.S. Department of Health and Human Services, Office for Civil Rights at hhs.gov/hipaa/filing-a-complaint. We will not retaliate against you for filing a complaint.
  • Right to Opt Out of Fundraising: You may opt out of receiving fundraising communications from us at any time.

To exercise any of these rights, please submit a written request to our Privacy Officer using the contact information in Section 9 of this Policy.

Section 7

Data Retention & Disposal

Sigma Orthopedics retains PHI and other personal data for the minimum period necessary to fulfill the purposes for which it was collected and to comply with applicable federal and New York State legal requirements.

Retention Periods

  • Adult Patient Medical Records: Retained for a minimum of six (6) years from the date of creation or the date when the information was last in effect, whichever is later, in accordance with HIPAA (45 CFR §164.530(j)) and New York State Education Law §6530(23).
  • Minor Patient Records: Retained until the patient reaches the age of 21, or for a minimum of six years from the date of the last entry, whichever is longer.
  • Billing & Financial Records: Retained for seven (7) years to comply with Medicare and Medicaid requirements.
  • Website & Analytics Data: Non-PHI website usage data is retained for up to 24 months.
  • SMS Opt-In Records: Retained for the duration of the patient relationship plus six (6) years to support compliance audits.

Secure Disposal

When PHI is no longer needed and has met its required retention period, we dispose of it securely:

  • Paper Records: Cross-cut shredding or incineration by a certified records destruction vendor.
  • Electronic Records & Media: NIST SP 800-88 compliant data sanitization, including cryptographic erasure, degaussing, or physical destruction of storage media.
  • Certificates of destruction are maintained for all PHI disposal activities.
Section 8

Breach Notification

Sigma Orthopedics maintains a formal Breach Notification Policy in accordance with the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D) and the HITECH Act (42 U.S.C. §17932).

What Constitutes a Breach

A "breach" is any impermissible use or disclosure of PHI that compromises its security or privacy — unless we can demonstrate a low probability that the PHI has been compromised based on a four-factor risk assessment.

Notification Timelines

  • Individual Notification: Affected individuals will be notified without unreasonable delay and in no case later than 60 calendar days following the discovery of a breach.
  • HHS Notification: Breaches affecting fewer than 500 individuals will be reported within 60 days after the close of the calendar year. Breaches affecting 500 or more individuals will be reported concurrently with individual notification.
  • Media Notification: Breaches affecting 500 or more residents of New York State will be reported to prominent media outlets within 60 days.
Section 9

Contact Us

For any questions, concerns, or requests related to this Privacy Policy or your rights under HIPAA, please contact our designated Privacy Officer:

Sigma Orthopedics — Privacy Officer

To exercise your HIPAA rights (access, amendment, restrictions, etc.), please submit your request in writing to the Privacy Officer. We will acknowledge your request within five (5) business days and respond within the timeframes required by HIPAA.

Filing a Complaint with HHS

You also have the right to file a complaint directly with the U.S. Department of Health and Human Services, Office for Civil Rights:

We will not retaliate against you in any way for filing a complaint with HHS or with us.

Updates to This Policy

Sigma Orthopedics reserves the right to update this Privacy Policy at any time to reflect changes in our practices or applicable law. Material changes will be communicated by posting the revised policy on our website with an updated effective date. We encourage you to review this Policy periodically. Continued use of our services following the posting of changes constitutes your acceptance of those changes.