Hamilton Facial Plastic Surgery, Inc Privacy Policy & Notice of Privacy Practices
I. OUR COMMITMENT TO YOUR PRIVACY
This Privacy Policy and Notice of Privacy Practices describes how Hamilton Facial Plastic Surgery, Inc., the office of Dr. Jason S. Hamilton, MD, (referred to as “we,” “us,” or “our”) protects the privacy of your Protected Health Information (PHI) and other personal information. We are required by law to maintain the privacy of PHI and to provide you with notice of our legal duties and privacy practices with respect to PHI.
As a healthcare entity, we comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and all related federal and state laws.
II. INFORMATION WE COLLECT
When you use our websites, particularly through our contact forms and patient intake processes, we collect information that may include:
A. Protected Health Information (PHI)
This includes individually identifiable health information created, received, maintained, or transmitted by us, and may include, but is not limited to:
- Demographic Information: Your name, address, phone number, email address, date of birth.
- Health Information: Information related to your past, present, or future physical or mental health or condition; the provision of healthcare to you; or the past, present, or future payment for the provision of health care to you.
- Appointment Information: Requests for consultations or expert second opinions.
- Any information you choose to provide
B. Non-PHI and Technical Data
This includes information that does not identify you as an individual, such as:
- Website usage data, IP addresses, browser type, and time spent on pages.
- Note: If technical data (like an IP address) is connected to your PHI, we treat it as PHI and protect it accordingly.
III. HOW WE USE AND DISCLOSE YOUR PHI
We may use and disclose your PHI without your written authorization for the following purposes, as permitted by HIPAA:
- Treatment: We may use and disclose your PHI to provide, coordinate, or manage your health care and related services.
Example: PHI collected via a contact form is used to create your patient intake record and schedule an appointment with a provider.
- Payment: We may use and disclose your PHI to obtain payment for the health care services we provide.
Example: Sharing PHI with your health plan to determine eligibility or to obtain payment for treatment.
- Health Care Operations (HCO): We may use and disclose your PHI for our own health care operations, such as business planning, quality assessment activities, and staff training.
Example: Using PHI to review our treatment and services and to evaluate the performance of our staff.
Uses and Disclosures That Require Your Written Authorization
We will not use or disclose your PHI for any purpose not listed above, or as otherwise permitted or required by law, without your specific written authorization. This includes, but is not limited to:
- Marketing (other than face-to-face communications or promotional gifts of nominal value).
- Sale of PHI.
IV. ELECTRONIC COMMUNICATION CONSENT (Text Messages and Email)
Your privacy and preferences for communication are very important to us.
A. Text Message (SMS) Consent
By providing your mobile number through our website contact or intake forms and checking the corresponding consent box, you are providing explicit written consent to receive recurring text messages from Hamilton Facial Plastic Surgery, Inc regarding your healthcare, including but not limited to:
- Appointment reminders and confirmations.
- Billing and payment information.
- Follow-up instructions or general health information related to your care.
By consenting, you acknowledge and agree that:
- Data Security Risk: Standard text messages are not encrypted and may not be inherently secure. General appointment reminders are sent via standard text message. We use a HIPAA-compliant text messaging service with a Business Associate Agreement in place for personalized messages. There is an inherent risk that a third party could view the content of an unencrypted text message if your phone is compromised or viewed by others.
- To STOP: You can reply STOP at any time to any message to discontinue text communications. Message and data rates may apply.
- No Condition of Treatment: Your decision to consent to or revoke text messaging is NOT a condition of receiving treatment from us.
- Frequency: Message frequency will vary based on your appointment schedule and care needs.
B. Email Consent
By filling out the contact form on our website, you consent to receive email communications from Hamilton Facial Plastic Surgery, Inc regarding your healthcare, including but limited to:
- Appointment confirmations and reminders.
- Responses to your inquiries.
- General health information or updates.
By consenting, you acknowledge and agree that:
- Data Security Risk: Email, unless fully encrypted, carries a risk of being intercepted or accessed by unauthorized third parties. We use a HIPAA-compliant, encryptedemail platforms to send and receive your PHI, and we will apply all reasonable safeguards to protect your information.
- Opt-Out: You can opt-out of marketing or non-essential emails at any time using the “unsubscribe” link in the email footer. You may not be able to opt out of essential treatment or billing-related emails.
V. OUR SECURITY MEASURES AND BUSINESS ASSOCIATES
- HIPAA Compliant Server: We utilize a HIPAA-compliant, secured server to store, process, and transmit all electronic PHI collected via our website forms and intake processes. This includes employing technical safeguards like encryption for data both in transit and at rest, access controls, and regular audit trails.
- Business Associate Agreements (BAAs): We enter into Business Associate Agreements with any third-party vendor (such as our server host, text messaging service, or practice management software) who has access to your PHI. These agreements legally require our vendors to protect your PHI with the same rigor we are required to follow under HIPAA.
VI. YOUR RIGHTS REGARDING YOUR PHI
You have the following rights regarding the PHI we maintain about you:
- Right to Inspect and Copy: You have the right to inspect and obtain a copy of PHI contained in your medical and billing records for as long as we maintain the PHI.
- Right to Request Amendment: If you feel that PHI we have about you is incorrect or incomplete, you may ask us to amend the information.
- Right to an Accounting of Disclosures: You have the right to request a list of certain disclosures of your PHI we have made.
- Right to Request Restrictions: You have the right to request a restriction or limitation on the PHI we use or disclose for treatment, payment, or health care operations.
- Right to Request Confidential Communications: You have the right to request that we communicate with you about medical matters in a certain way or at a certain location (e.g., mail to a specific address, rather than call your work number).
- Right to a Paper Copy of This Notice: You have the right to a paper copy of this notice at any time, even if you have agreed to receive it electronically.
VII. OUR DUTIES
We are required by law to:
- Maintain the privacy and security of your PHI.
- Provide you with this Notice of our legal duties and privacy practices.
- Notify you if a breach occurs that may have compromised the privacy or security of your PHI.
- Abide by the terms of this Notice currently in effect.
VIII. CHANGES TO THIS PRIVACY POLICY
We reserve the right to change this Notice. We reserve the right to make the revised Notice effective for all PHI we already have about you as well as any information we receive in the future. We will post a copy of the current Notice on our website with a new effective date.
IX. COMPLAINTS AND CONTACT INFORMATION
If you believe your privacy rights have been violated, you may file a complaint with us or with the Secretary of the Department of Health and Human Services.
To file a complaint with us or ask a question about this policy, please contact:
hipaaprivacyofficer@drjasonhamilton.com or call 310-759-6409 and ask to speak to the Privacy Officer.
We will not retaliate against you for filing a complaint.
Effective Date: 10/20/2025 Last Updated: 4/26/2026
Effective Date: 15-May-2024
COOKIE POLICY
This Cookie Policy explains what cookies are and how we use them, the types of cookies we use i.e, the information we collect using cookies and how that information is used, and how to manage the cookie settings.
Cookies are small text files that are used to store small pieces of information. They are stored on your device when the website is loaded on your browser.These cookies help us make the website function properly, make it more secure, provide better user experience, and understand how the website performs and to analyze what works and where it needs improvement.
How do we use cookies?
As most of the online services, our website uses first-party and third-party cookies for several purposes. First-party cookies are mostly necessary for the website to function the right way, and they do not collect any of your personally identifiable data.
The third-party cookies used on our website are mainly for understanding how the website performs, how you interact with our website, keeping our services secure, providing advertisements that are relevant to you, and all in all providing you with a better and improved user experience and help speed up your future interactions with our website.
Necessary
Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.
| Cookie | Duration | Description |
|---|---|---|
| wt_consent | 1 year | The WebToffee GDPR Cookie Consent plugin sets this cookie to store the user’s consent preferences, allowing the website to recognise those choices on future visits. The cookie does not collect or store any personal or identifiable information about the visitor. |
| rc::a | never | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| wpEmojiSettingsSupports | session | WordPress sets this cookie when a user interacts with emojis on a WordPress site. It helps determine if the user's browser can display emojis properly. |
| rc::c | session | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| VISITOR_PRIVACY_METADATA | 6 months | YouTube sets this cookie to store the user's cookie consent state for the current domain. |
| _cfuvid | session | Cloudflare sets this cookie to track users across sessions to optimize user experience by maintaining session consistency and providing personalized services |
| __cf_bm | 1 hour | This cookie, set by Cloudflare, is used to support Cloudflare Bot Management. |
Functional
Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.
| Cookie | Duration | Description |
|---|---|---|
| VISITOR_INFO1_LIVE | 6 months | A cookie set by YouTube to measure bandwidth that determines whether the user gets the new or old player interface. |
| ytidb::LAST_RESULT_ENTRY_KEY | never | The cookie ytidb::LAST_RESULT_ENTRY_KEY is used by YouTube to store the last search result entry that was clicked by the user. This information is used to improve the user experience by providing more relevant search results in the future. |
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.
| Cookie | Duration | Description |
|---|---|---|
| _ga | 1 year 1 month 4 days | Google Analytics sets this cookie to calculate visitor, session and campaign data and track site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors. |
| _ga_* | 1 year 1 month 4 days | Google Analytics sets this cookie to store and count page views. |
| YSC | session | YSC cookie is set by Youtube and is used to track the views of embedded videos on Youtube pages. |
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
| Cookie | Duration | Description |
|---|---|---|
| No cookies to display. | ||
Advertisement
Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.
| Cookie | Duration | Description |
|---|---|---|
| _gcl_au | 3 months | Google Tag Manager sets this cookie to experiment advertisement efficiency of websites using their services. |
| test_cookie | 15 minutes | doubleclick.net sets this cookie to determine if the user's browser supports cookies. |
| __Secure-YNID | 6 months | YouTube cookie used to protect user security and prevent fraud, especially during the login process. |
| __Secure-ROLLOUT_TOKEN | 6 months | YouTube sets this cookie to manage feature rollout and experimentation. It helps Google control which new features or interface changes are shown to users as part of testing and staged rollouts, ensuring consistent experience for a given user during an experiment. |
| __Secure-YEC | past | Description is currently not available. |
Others
Other cookies are those that are being identified and have not been classified into any category as yet.
| Cookie | Duration | Description |
|---|---|---|
| No cookies to display. | ||
Manage cookie preferences
You can change your cookie preferences any time by clicking the Consent Preferences button. This will let you revisit the cookie consent banner and change your preferences or withdraw your consent right away. In addition to this, different browsers provide different methods to block and delete cookies used by websites. You can change the settings of your browser to block/delete the cookies. Listed below are the links to the support documents on how to manage and delete cookies from the major web browsers.
Chrome: https://support.google.com/accounts/answer/32050
Safari: https://support.apple.com/en-in/guide/safari/sfri11471/mac
Microsoft Edge: Delete cookies in Microsoft Edge – Microsoft Support
If you are using any other web browser, please visit your browser’s official support documents.
