Notice of Privacy Practices & Privacy Policy

Triad Pediatrics, PC

2754 NC-68, High Point, NC 27265

www.triadpediatrics.com

(336) 802-1111

Chad Cooke  chad@triadpediatrics.com

Effective Date: August 28, 2026  |  Last Updated: August 28, 2026

1. Introduction

Triad Pediatrics, PC (“Triad Pediatrics,” “we,” “us,” or “our”) is committed to protecting the privacy and security of the personal and health information of our patients and the users of our mobile application (the “App”) and website (together, the “Services”). This Privacy Policy explains what information we collect, how we use and share it, how long we retain it, how you can request deletion of it, and the choices and rights available to you.

This Privacy Policy applies to information collected through the App, our website located at www.triadpediatrics.com, and any related services we operate that link to this policy. It does not apply to third-party websites, applications, or services that we do not own or control, even if accessible through our Services.

2. Notice of Privacy Practices (HIPAA)

Because Triad Pediatrics provides healthcare services, certain information we collect qualifies as Protected Health Information (“PHI”) under the Health Insurance Portability and Accountability Act (“HIPAA”). Our full HIPAA Notice of Privacy Practices, which describes how we may use and disclose PHI and your rights regarding your medical records, is available at www.triadpediatrics.com (see “Privacy Policy” / Notice of Privacy Practices) and is incorporated into this Privacy Policy by reference. Where this Privacy Policy and our HIPAA Notice of Privacy Practices conflict with respect to PHI, the HIPAA Notice of Privacy Practices controls.

3. Information We Collect

3.1 Information You Provide to Us

  • Contact information, such as name, mailing address, email address, and phone number.
  • Patient and account information, such as date of birth, guardian/parent information, insurance information, and appointment history.
  • Health information, such as medical history, symptoms, diagnoses, treatment notes, immunization records, and prescriptions.
  • Payment information, such as billing address and payment card details (processed by our third-party payment processor).
  • Communications you send us, including messages through patient portals, secure messaging, customer support, and surveys.

3.2 Information Collected Automatically

  • Device information, such as device type, operating system, unique device identifiers, and mobile network information.
  • Usage data, such as app interactions, pages viewed, features used, and timestamps.
  • Location information, such as approximate location derived from your IP address, or precise location if you grant permission.
  • Log and diagnostic data, such as crash reports and performance data.

3.3 Information from Third Parties

  • Information from healthcare providers, laboratories, pharmacies, and insurance companies involved in your care.
  • Information from identity verification or authentication service providers.

4. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Services, including scheduling appointments and facilitating care.
  • Communicate with you about appointments, treatment, billing, and customer support.
  • Process payments and manage insurance claims.
  • Comply with legal, regulatory, and medical recordkeeping obligations.
  • Improve and secure our Services, including diagnosing technical issues.
  • Send administrative information, service updates, and, where you have consented, marketing communications.
  • Protect against fraud, unauthorized transactions, and other liability.

5. How We Share Your Information

We do not sell your personal information. We may share information with:

  • Healthcare providers and care teams involved in providing your treatment.
  • Service providers and business associates who perform services on our behalf (e.g., hosting, billing, analytics, customer support) under HIPAA-compliant Business Associate Agreements where applicable.
  • Insurance companies and payers to process claims and verify coverage.
  • Legal and regulatory authorities where required by law, subpoena, court order, or to protect health and safety.
  • Business transfers, such as a merger, acquisition, or sale of assets, subject to confidentiality obligations.
  • With your consent, for any other purpose disclosed to you at the time of collection.

6. Data Retention

We retain personal information for as long as necessary to provide our Services and fulfill the purposes described in this policy, including maintaining medical records, complying with legal and regulatory recordkeeping requirements, resolving disputes, and enforcing our agreements. Specifically:

  • Account and profile information is retained for as long as your account is active and for a reasonable period afterward, and is then deleted or de-identified unless a longer retention period is required by law.
  • Medical and health records are retained for the minimum period required by HIPAA and applicable North Carolina medical recordkeeping requirements. Because Triad Pediatrics serves pediatric patients, records for minors are generally retained until the patient reaches the age of majority plus the applicable limitations period under North Carolina law.
  • Billing and payment records are retained as required for tax and financial recordkeeping purposes (generally at least seven years).
  • App usage and diagnostic data is retained for up to 24 months, after which it is deleted or aggregated into anonymous statistics.

When retention is no longer necessary or legally required, we securely delete, destroy, or anonymize the information in accordance with our data disposal procedures.

7. Your Rights and Choices

7.1 Requesting Deletion of Your Data

You may request deletion of your personal information at any time by contacting us at chad@triadpediatrics.com or (336) 802-1111 (see Section 11). When we receive a verified deletion request, we will delete or de-identify your personal information within 30 days, except where we are required or permitted to retain it, including:

  • Where retention is required by law, including HIPAA and North Carolina medical recordkeeping requirements for treatment records.
  • Where data is needed to complete a transaction, resolve a dispute, or enforce our agreements.
  • Where data is contained in backup systems, in which case it will be deleted according to our regular backup deletion schedule.

We will notify you once your deletion request has been processed, or explain why we are unable to fulfill it in whole or in part. Please note that federal and state law generally require healthcare providers to retain medical records for a minimum period even after a deletion request; in that case, we will restrict use of the record to purposes required by law rather than deleting it.

7.2 Access and Correction

You may request access to, or correction of, your personal or health information by contacting us using the information in Section 11. Requests relating to medical records will be handled in accordance with HIPAA and our Notice of Privacy Practices.

7.3 Marketing Communications

You may opt out of marketing communications at any time by following the unsubscribe instructions in those communications or by contacting us directly.

7.4 State Privacy Rights

Depending on your state of residence, you may have additional rights under applicable state privacy laws, including the right to know, delete, and correct personal information, and to opt out of certain data sharing. To exercise these rights, contact us using the information in Section 11.

8. Children's Privacy

Our Services involve the collection of health information about minor patients as part of providing pediatric care, which is provided by parents or legal guardians on the child's behalf. We do not knowingly collect personal information directly from children through the App outside of this care context without parental or guardian involvement. If you believe a child has provided us with information other than through the ordinary course of receiving care, please contact us using the information in Section 11.

9. Data Security

We implement administrative, technical, and physical safeguards designed to protect your information, consistent with HIPAA Security Rule requirements, including encryption of data in transit, access controls, and staff training. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated policy with a new “Last Updated” date, and, where required by law, provide additional notice of material changes.

11. Contact Us

If you have questions about this Privacy Policy, or wish to exercise any of the rights described above, please contact us at:

Triad Pediatrics, PC
2754 NC-68, High Point, NC 27265
Email: chad@triadpediatrics.com
Phone: (336) 802-1111
Privacy Contact: Chad Cooke