Legal

HIPAA Notice of Privacy Practices

This Notice describes how medical information about you may be used and disclosed by Arora Health and Aesthetics, LLC and its engaged providers, and how you can get access to this information. It is the standalone, printable version of the Notice that is also published inside the Privacy Policy.

Effective:
2026-09-02
Version:
1.2
Last reviewed:
2026-09-02

1.Who this Notice covers

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Arora Health and Aesthetics, LLC (the “Group”) and the Group's engaged providers (your “Provider”) deliver the clinical services described in this Notice. The Group is the covered entity under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) for the records of your care. This Notice applies to all records relating to your care that are created or retained by the Group and its engaged providers, in electronic or paper form, including information collected through the patient portal.

The Pep Club Inc. does not provide clinical services. It is the management services organization for the Group: it performs administrative, payment, technology, marketing, and other supportive activities for the Group and its Providers, and it acts as a business associate of the Group for the protected health information (“PHI”) it handles on the Group's behalf.

In this Notice, “we,” “us,” and “our” mean the Group and its engaged providers, together with The Pep Club Inc. acting on the Group's behalf.

This is version 1.2 of the Notice, effective 2026-09-02. It replaces every earlier version.

2.Our duties

We are required by law to:

  • Maintain the privacy and security of PHI about you;
  • Give you this Notice of our legal duties and privacy practices with respect to PHI;
  • Notify you, without unreasonable delay and no later than sixty (60) calendar days after discovery, in the event of a breach of unsecured PHI that involves you; and
  • Follow the terms of the Notice currently in effect.

We reserve the right to change the terms of this Notice and to make the new terms effective for all PHI that we maintain, including PHI created or received before the change. When we make a material change, we will post the revised Notice at thepepclub.com/hipaa-notice, raise the version number, update the Last reviewed date, and make a copy available on request.

3.Permissible uses and disclosures without your written authorization

We may use and disclose your PHI without a separate written authorization for the following purposes:

  • Treatment: to provide, coordinate, or manage your healthcare, including disclosure to the Group's engaged providers, the affiliated compounding pharmacy that dispenses your prescriptions, the reference laboratory that processes your biomarker samples, and other providers involved in your care.
  • Payment: the services are offered on a cash-pay basis, so we generally do not use or disclose PHI for insurance billing. We may use PHI to process your payment, verify your billing information, and send you billing communications. If you choose to seek reimbursement from your insurer independently, we may provide you with documentation of the services rendered at your request.
  • Healthcare operations: to run the Group's practice and the patient platform, including quality assessment and improvement, reviewing provider performance, licensing and accreditation activities, training, audit, and general administrative activities.
  • Public health activities: to public-health authorities authorized by law to collect information for preventing or controlling disease, injury, or disability; reporting medication-related adverse events to public-health authorities authorized by law to receive such reports; and reporting child abuse or neglect to authorized agencies.
  • Victims of abuse, neglect, or domestic violence: to a governmental authority authorized by law to receive such reports, where we reasonably believe abuse has occurred.
  • Health-oversight activities: to agencies overseeing the healthcare system, government benefits, or regulatory programs (for example, state pharmacy boards, state medical boards, the HHS Office for Civil Rights), including audits, investigations, inspections, and licensure.
  • Judicial and administrative proceedings: in response to a valid subpoena, court order, or other lawful process.
  • Law enforcement: in limited circumstances permitted by HIPAA, including court orders, certain identification requests, and reports of crime victims.
  • Decedents: to coroners, medical examiners, and funeral directors as necessary.
  • Research: if approved by an Institutional Review Board (IRB) with appropriate privacy protections in place.
  • Health or safety threats: to prevent a serious and imminent threat to the health or safety of you or another person, where the disclosure is to someone reasonably able to prevent or lessen the threat.
  • Specialized government functions: for military and veterans' activities, national security, protective services for the President, or correctional institutions as permitted by law.
  • Workers' compensation: as required by applicable state workers' compensation laws.
  • As required by law: any other use or disclosure required by federal, state, or local law, including disclosures to state licensing boards and mandatory reporting obligations.

4.Appointment reminders and treatment alternatives

We may use and disclose PHI to contact you as a reminder about appointments or follow-up consultations, by email, by text message, or by a message in the patient portal. We may also use your PHI to tell you about treatment alternatives or other health-related benefits and services that may be of interest to you.

If you would prefer that we contact you by a particular method or at a particular address, tell us and we will accommodate reasonable requests. Communications that constitute “marketing” under HIPAA are covered by the authorization section below, not by this one.

5.Business associates

We may disclose PHI to third-party “business associates” that perform services on our behalf, such as data storage, platform infrastructure, identity and authentication, email delivery, error monitoring, and payment processing.

HIPAA requires a written business associate agreement with each provider that creates, receives, maintains, or transmits PHI on our behalf, obliging that provider to protect the privacy and security of your PHI. We maintain an internal register of these providers and the status of each agreement, and we publish the current provider list in the Privacy Policy so that you can see exactly which vendors are in our information supply chain.

6.Uses and disclosures requiring your written authorization

For uses and disclosures of PHI not described above, we will obtain your written authorization. The following always require your written authorization, except in the narrow exceptions HIPAA itself recognizes:

  • Marketing communications that constitute “marketing” under HIPAA;
  • Any sale of PHI;
  • Any use or disclosure of psychotherapy notes;
  • Most uses and disclosures of PHI for research purposes, other than research approved by an Institutional Review Board as described above; and
  • Outreach from the affiliated pharmacy to its existing patients about The Pep Club services, which requires the patient's separate written authorization under 45 CFR 164.508(a)(3). Outreach without that specific authorization is prohibited.

You may revoke any written authorization at any time by writing to privacy@thepepclub.com. Revocation is effective from the time we receive it and does not affect uses or disclosures we already made in reliance on the authorization.

7.Your individual rights under HIPAA

You have the following rights with respect to PHI about you. To exercise any of them, write to the Privacy Officer at privacy@thepepclub.com.

  • Right to request restrictions. You may ask us to restrict how we use or disclose your PHI for treatment, payment, or healthcare operations. We are not required to agree to every request; if we agree, we will comply with the restriction except in an emergency. You may also direct us not to disclose to a health plan information about a service you paid for in full out of pocket, and we will honor that direction except where disclosure is required by law.
  • Right to confidential communications. You may ask us to communicate with you about your PHI by alternative means or at alternative locations (for example, secure email, an alternate phone, or a P.O. box). We will accommodate reasonable requests.
  • Right to inspect and copy your records. You may inspect and obtain a copy of the medical record and billing record we maintain for you. We will respond to a written request within thirty (30) days. A reasonable, cost-based fee may apply for copies in accordance with HIPAA and applicable state law. We will provide an electronic copy where you request one and our systems can produce it.
  • Right to amend your records. If you believe information in your record is incorrect or incomplete, you may submit a written amendment request. We may deny the request if the information was not created by us, is not part of the record we keep, is not part of the information you would be permitted to inspect, or is accurate and complete. If we deny the request, we will explain in writing, and you may submit a statement of disagreement to be filed with your record.
  • Right to an accounting of disclosures. You may request an accounting of disclosures of your PHI made by us in the six (6) years prior to your request, with the exceptions HIPAA recognizes (disclosures for treatment, payment, or healthcare operations; disclosures made to you; and disclosures made pursuant to a valid authorization). The first accounting in any twelve-month period is free; a reasonable, cost-based fee may apply to additional requests.
  • Right to breach notification. You have the right to be notified of any breach of unsecured PHI that involves you, as required by the HIPAA Breach Notification Rule (45 CFR 164.400 to 164.414) and applicable state law. The section below describes how we do that.
  • Right to a paper copy of this Notice. You may request a paper copy of this Notice at any time, even if you have agreed to receive it electronically.

8.Breach notification

If we discover a breach of unsecured PHI, we will notify you without unreasonable delay and no later than sixty (60) calendar days after discovery, in accordance with 45 CFR 164.404. Notice will be sent to the email address or postal address on file with your account and will describe what happened, the types of PHI involved, the steps you can take to protect yourself, what we are doing in response, and how to contact us for more information.

Where a breach involves the unsecured PHI of more than five hundred (500) individuals, we will also notify the Secretary of the U.S. Department of Health and Human Services and, where required by 45 CFR 164.406, prominent media. Where a breach involves fewer than five hundred (500) individuals, we will report it to the Secretary on the HHS Breach Portal at the close of the calendar year.

9.How to file a complaint

If you believe your privacy rights have been violated, you may file a complaint with us by writing to the Privacy Officer at privacy@thepepclub.com. Include your name, your account email, and a description of the concern. We will investigate and respond.

You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at 200 Independence Avenue SW, Washington, DC 20201, by phone at 1-877-696-6775, or online at www.hhs.gov/ocr/privacy/hipaa/complaints. We will not retaliate against you for filing a complaint.

10.Privacy Officer and contact

The Privacy Officer is responsible for the privacy and security of PHI handled by the Group and by The Pep Club Inc. on the Group's behalf. Direct privacy questions, data-subject requests, and HIPAA-rights requests to the Privacy Officer at privacy@thepepclub.com.

You may also reach the Privacy Officer by telephone at 1-888-737-0567.

Written privacy requests may also be directed to the Privacy Officer using the contact options on the Contact page.

11.State-specific privacy addenda

The complete consumer-privacy framework that incorporates this Notice and adds state-specific addenda (California CCPA, Washington MHMDA, Texas TDPSA, Nevada SB220), together with the published list of service providers and subprocessors, is at the Privacy Policy.

Questions about this document? privacy@thepepclub.com

Last reviewed: 2026-09-02

Notice version 1.2, last reviewed 2026-09-02. The full consumer-privacy framework, including state-specific addenda for California, Washington, Texas, and Nevada, is in the Privacy Policy.