Privacy Policy & Notice of Privacy Practices
Effective Date: February 11, 2026
This Privacy Policy (this “Policy”) applies to Dana G. Negoi, MD / Ithaca Medical Aesthetics (the “Company,” “we,” or “us”) and the personal information we collect, use, and disclose in connection with your use of our Services and other business interactions you have with us.
At Dana G. Negoi, MD / Ithaca Medical Aesthetics, we are committed to protecting your privacy and your health information. This document outlines how we handle your data in our clinical practice and on our digital platforms.
This Privacy Policy describes our practices in connection with personal information that we collect through our “Services,” which together include:
-
Our websites and mobile applications (each, an “App”) and any healthcare services you receive through the same (together, the “Platform”);
-
Email and text messages that we send to you or other communications with you; and
-
Offline business interactions you have with us.
Please read this Policy carefully. This Policy may be updated from time to time and will be made available on our website. Your continued use of our Services constitutes acceptance of any updated terms.
1. Clinical Evaluation & Medical Risks
By using this website to research or book services, you acknowledge:
-
Professional Exam Required: All aesthetic procedures (including neurotoxins, fillers, and medical-grade peels) require an in-person physical examination by our licensed medical staff to determine candidacy.
-
Inherent Risks: All medical procedures carry inherent risks (including bruising, infection, or allergic reaction). Detailed informed consent documents will be provided and must be signed prior to treatment.
-
No Doctor–Patient Relationship: Use of this website or our contact forms does not establish a doctor–patient relationship until you have been formally evaluated in person.
2. Information We Collect About You
We collect personal information directly from you, automatically through your use of our Platform, and from third parties.
This may include:
-
Name, email address, phone number, mailing address
-
Date of birth, age, sex
-
Billing and payment information
-
Medical history and health information
-
Photographs, videos, and images
-
User account information
-
Device and browser data
-
IP address and usage data
-
Location data (where permitted by device settings)
-
Any other information you voluntarily provide
We collect this information through account creation, appointment booking, cookies, analytics tools, and communications with us.
3. How We Use Your Information
We use your information to:
-
Provide medical and aesthetic services
-
Schedule appointments and send reminders
-
Communicate with you
-
Process payments
-
Improve our Platform and Services
-
Comply with legal obligations
-
Send marketing communications only when you have explicitly opted in
4. 2026 HIPAA & Substance Use Disorder (SUD) Protections
As required by February 16, 2026 HIPAA and 42 CFR Part 2 alignment:
-
SUD records will not be disclosed in legal proceedings without your written consent or court order.
-
With your written consent, SUD records may be used for Treatment, Payment, and Healthcare Operations (TPO).
-
Disclosed information may be subject to redisclosure.
-
We will never use SUD records for fundraising without providing a clear opt-out opportunity.
5. New York Health Information Privacy Act (NY HIPPA)
In accordance with New York’s Regulated Health Information standards:
-
We will not share regulated health data (including geolocation or payment data linked to health) for marketing without explicit written authorization.
-
A 24-hour cooling-off period applies before requesting authorization for non-essential processing.
-
You may request access to or deletion of non-clinical personal information within 30 days.
6. Email & Digital Marketing Compliance
-
Promotional communications require explicit opt-in consent.
-
Marketing platforms used by us are HIPAA-compliant and operate under Business Associate Agreements (BAAs).
-
We do not use third-party tracking pixels on pages where health information is submitted or appointments are booked.
-
You may unsubscribe from marketing at any time. Requests are processed within 10 business days. Appointment reminders will still be sent.
7. Data Security & Breach Notification (NY SHIELD Act)
We maintain administrative, technical, and physical safeguards to protect your information.
-
PHI is stored on encrypted HIPAA-compliant servers.
-
In the event of a data breach, affected individuals will be notified within 30 days of discovery.
8. When We Share Information
We may share information:
-
With authorized employees on a need-to-know basis
-
With service providers under contractual confidentiality obligations
-
With third parties with your consent
-
As required by law
-
In connection with business transfers
-
To protect safety or prevent fraud
We do not sell your personal information.
9. Messaging Terms & Consent
By providing your mobile number, you consent to receive appointment reminders and service-related messages. Message and data rates may apply. You may opt out anytime by replying STOP.
Mobile opt-in data will never be sold or shared for marketing purposes.
10. Your Rights
You have the right to:
-
Request copies of medical and billing records
-
Request restrictions on certain disclosures
-
Revoke authorizations
-
Request an accounting of disclosures from the past three years
-
Access and correct your information
11. Retention
We retain information as long as your account is active and as necessary to comply with legal obligations.
12. Security
While no system is 100% secure, we use reasonable safeguards to protect your information. If you believe your data has been compromised, please contact us immediately.
13. Contact Our Privacy Officer
For all privacy-related requests:
Attention: Privacy Compliance Officer
Entity: Dana G. Negoi, MD / Ithaca Medical Aesthetics
Email: info@ithacamedicalaesthetics.com
Mailing Address: 108 North Cayuga Street, Suite 6, Ithaca, NY 14850
Phone: 607-603-7002
We will respond to verifiable requests under NY HIPA and HIPAA within thirty (30) days.
.png)



.png)