Skip to main content

HIPAA Notice of Privacy Practices

Effective Date: July 18, 2026 · Last updated: July 18, 2026

Our Commitment to Your Privacy

OpenChair, Inc. ("OpenChair", "we", "us") is committed to protecting the privacy of your health information. This Notice describes how medical information about you may be used and disclosed, and how you can get access to this information. Please review it carefully.

What Information We Collect

We collect Protected Health Information (PHI) that you provide during the triage and appointment booking process, including chief complaints, symptom descriptions, urgency assessments, dental history, and contact information. We also collect information shared by the dental professionals you interact with on our platform.

How We Use Your Information

  • Treatment: To facilitate care by connecting you with dental providers.
  • Operations: To operate and improve the OpenChair platform.
  • Payment: To process appointment deposits and facilitate billing.
  • Communications: To send appointment confirmations and follow-ups.

Disclosures We May Make

We may disclose your PHI to dental professionals participating in your care, as required by law (e.g., public health reporting, law enforcement), and to business associates who assist us in operating OpenChair under appropriate data protection agreements. We will not sell your PHI to third parties for marketing purposes.

Your Rights

  • Right to Access: You may request a copy of your health records.
  • Right to Amend: You may request corrections to your information.
  • Right to Restrict: You may request limits on how we use your PHI.
  • Right to Accounting: You may request a list of disclosures we have made.
  • Right to Complain: You may file a complaint with us or the U.S. Department of Health and Human Services if you believe your privacy rights have been violated.

Data Security

We implement administrative, physical, and technical safeguards to protect your PHI in accordance with HIPAA Security Rule requirements, including encryption in transit and at rest, access controls, and audit logging.

Session Timeout

To protect your PHI, your session automatically expires after 30 minutes of inactivity. You will be prompted before logout and can extend your session.

Breach Notification

If a breach of your unsecured PHI occurs, we will notify you as required by the HIPAA Breach Notification Rule and applicable state law, without unreasonable delay and in no case later than 60 days after discovery.

Text Messaging and PHI

Transactional appointment and booking text messages you opt into may reference that you have an appointment but are designed to minimize Protected Health Information. We do not share your mobile number or messaging opt-in with third parties for marketing. See our Messaging Terms and Privacy Policy.

Changes to This Notice

We reserve the right to change this Notice and to make the revised Notice effective for PHI we already have as well as any information we receive in the future. The current Notice is always posted on our website with its effective date.

Contact Us

If you have questions about this Notice or wish to exercise your rights, contact our Privacy Officer at: privacy@openchair247.com