Vivier Health & Longevity, LLC (“Vivier”, “we”, “us”) is a clinician-led medical practice in Fair Lawn, New Jersey, and a covered entity under the Health Insurance Portability and Accountability Act (HIPAA). This policy explains what we collect through this website, how we use it, and what you can ask us to do about it.
It is written to be read. Where a section has a legal term behind it, the term is named so you can look it up, but the sentence is meant to make sense without doing so.
This policy, and the Notice of Privacy Practices
Two different documents govern two different relationships, and which one applies to you depends on whether you are a patient.
- This privacy policy covers everyone who uses this website — what the pages collect, what our analytics sees, and what happens to a waitlist inquiry.
- Our [Notice of Privacy Practices](/privacy/notice) covers your health information once you are a patient of the practice. Its contents are prescribed by HIPAA (45 CFR 164.520), and you are asked to review and acknowledge it when you enrol.
The two overlap for one group of people: someone who submits the waitlist form and describes a health concern in it. From the moment that form reaches us, the information in it is protected health information and the Notice governs how we treat it — before that person is a patient and whether or not they ever become one.
What this website collects
If you only read
Browsing this site requires no account and collects no information that identifies you by name. Our analytics records the page you viewed, the site that referred you, your approximate region, your device type and language, and a randomly generated identifier stored in a first-party cookie. That is described in full under cookies and analytics.
If you use the waitlist form
The form on our home page asks for, and stores, exactly these fields:
- Your first name, and your last name if you give one
- Your email address
- Your phone number, if you give one
- Which membership tier you are interested in, or that you are not sure yet
- Anything you write in the free-text field, which is optional
We also record the IP address the submission came from and your browser's user-agent string. Those exist so we can investigate abuse of the form — spam, automated submissions — and for no other purpose. They are not used to build a profile of you, and they are not shared with our analytics.
The free-text field is the one to be deliberate about. People use it to describe symptoms, conditions, and medications, and that is a reasonable thing to do — but it means the field collects health information attached to your name and contact details. We treat everything written there as protected health information from the moment it arrives. Nothing in it is ever logged, sent to analytics, or transmitted to any service not bound by an agreement to protect it. If you would rather not put a health concern in a web form, call the practice on (201) 475-4091 instead — the form deliberately works with the field left empty.
If you become a patient
Enrolment collects your date of birth, your acknowledgement of the consent documents you are shown, and the sign-in credentials for your account. Your clinical record — visits, assessments, results, correspondence — is created and held by the practice, and is governed by the Notice of Privacy Practices rather than by this policy.
How we use what we collect
HIPAA permits a practice to use health information for treatment, payment, and health care operations without asking separately each time — that is the ordinary business of providing care, arranging to be paid for it, and running the practice. Everything below falls within that, or is something you asked us to do.
- To answer you. A waitlist inquiry is used to contact you about becoming a patient, and to have an informed first conversation.
- To provide care. Scheduling, clinical assessment, treatment planning, monitoring, and communication with your care team.
- To arrange payment. Membership billing, and the records that go with it.
- To run the practice. Quality review, staff training, security monitoring, and the audit records HIPAA requires us to keep.
- To meet legal obligations. Where a law, subpoena, or public-health authority requires a disclosure.
- To understand the website. Aggregate measurement of which pages are read — never tied to a patient, and never to anything clinical.
We do not sell your information. We do not disclose it to data brokers, and we do not exchange it for anything of value. HIPAA independently prohibits the sale of protected health information without your written authorization (45 CFR 164.508(a)(4)), and we do not do it for anything else either.
We do not use your health information for marketing without a separate written authorization from you. That includes testimonials, case studies, before-and-after photographs, and named success stories — none of which appear on this site. A review you left somewhere public is not an authorization, and we do not treat it as one.
How it is protected
The HIPAA Security Rule requires administrative, physical, and technical safeguards. These are the technical ones, stated plainly because a claim of “industry-standard security” tells you nothing.
- Encrypted in transit. Every connection uses TLS 1.2 or better — your browser to us, our systems to each other, and our application to its database.
- Encrypted at rest. The database, its backups, file storage, and message queues are encrypted with keys we manage.
- Held inside a private network. The systems holding health information are not reachable from the internet. Requests reach them through a single controlled entry point.
- Access is checked on every request, against your identity and your role, on the server. The application never relies on the browser or the app to decide what you are allowed to see.
- Minimum necessary. Screens and interfaces are built to return only the fields they need. Our staff dashboards show counts and status rather than clinical detail, so an open screen on a shared monitor discloses nothing.
- Every access is audited. Reads and writes of health information produce a permanent record of who, what, when, and from where. That record is append-only — the application has no ability to alter or delete it, enforced by database permission rather than by convention.
- Sessions are short and revocable, with multi-factor authentication, automatic timeout after inactivity, and immediate server-side revocation.
- Health information never appears in logs, error reports, or web addresses. It is stripped before anything is recorded, and it travels in the body of a request rather than in a URL, because addresses end up in server logs, browser history, and proxies.
- Test and development systems contain no real patient data, ever. Development uses synthetic data generated for the purpose.
No system is perfect, and any claim otherwise should be treated with suspicion. What we can commit to is that the safeguards above are how the software is actually built, and that we will tell you if they fail — see breach notification.
How long we keep it
We keep information for as long as we need it for the purpose it was collected for, and for as long as the law requires. Patient records are retained for the period New Jersey law requires of a medical practice. A waitlist inquiry that does not become a patient record is deleted 24 months after it is submitted — the whole of it, including the health information written in it and the IP address recorded with it.
Some records are deliberately permanent. Our audit trail cannot be edited or deleted by design, because an audit trail that can be altered is not one, and billing history is kept as the record of what was charged. Neither contains clinical detail.
You can ask us what we hold about you and ask us to delete it — see your rights. Where the law requires us to keep something, we will tell you that rather than quietly declining.
Your rights
If you are a patient
HIPAA gives you the following rights over your health information. You can exercise any of them by writing to us at support@vivierhealth.com, and we will not treat you differently for doing so.
- See and get a copy of your record — electronically if you prefer, and we will send it to someone else if you direct us to in writing (45 CFR 164.524).
- Ask us to correct it if you believe something is wrong or incomplete. If we disagree, you may file a statement of disagreement that becomes part of the record (164.526).
- Get a list of certain disclosures we have made of your information (164.528).
- Ask us to restrict how we use or share it. We are not required to agree to every request — with one exception: if you pay for a service in full yourself, you can require us not to disclose that service to a health plan, and we must honor it (164.522(a)).
- Ask us to contact you a particular way — a specific phone number, address, or method. We will accommodate reasonable requests without asking why (164.522(b)).
- Get a paper copy of the Notice of Privacy Practices, even if you have already received it electronically (164.520(c)).
- Withdraw an authorization you previously gave, in writing, at any time (164.508(b)(5)).
- Complain — to us, or directly to the U.S. Department of Health and Human Services. See complaints.
If you are a website visitor
You can ask us what we hold about you, ask us to correct it, and ask us to delete it. If you submitted the waitlist form and would rather we did not keep it, email support@vivierhealth.com and say so — we will delete the inquiry and confirm that we have.
New Jersey residents have rights under the New Jersey Data Privacy Act, and residents of other states may have rights under their own laws. Most of these laws exclude information already covered by HIPAA, precisely because HIPAA's protections are stronger — so for anything clinical, the rights listed above are the ones that apply and they are broader.
If something goes wrong
If your unsecured health information is breached, HIPAA requires us to notify you without unreasonable delay and within 60 days of discovering it (45 CFR 164.404), to notify the Secretary of Health and Human Services, and — for a breach affecting 500 or more people in a state or jurisdiction — to notify prominent media there. New Jersey law imposes its own notification duties, which run alongside these rather than replacing them.
We will tell you what happened, what information was involved, what we are doing about it, and what you can do to protect yourself.
How we contact you
We will contact you about your inquiry, your care, your appointments, and your membership. You can ask us to use a particular method or number at any time.
Ordinary email and text messages are not secure. They pass through systems we do not control and can be read by anyone with access to the account or the device. We keep anything clinical out of them — a message will tell you that something is waiting for you and ask you to sign in, rather than containing it. If you email us health information yourself, we will receive and protect it, but the journey to us was not encrypted end to end and we cannot make it retroactively so.
You can opt out of non-essential messages at any time. We will still send the ones that are part of your care or required for your account — appointment details, billing notices, and security alerts — because those are not marketing.
Children
This practice treats adults. The site is not directed at children, and we do not knowingly collect information from anyone under 18. If you believe a child has submitted information to us, email support@vivierhealth.com and we will delete it.
Other websites
Where this site links to somewhere else — a manufacturer, a professional body, a mapping service — that site has its own privacy policy and we are not responsible for it. Following such a link takes you out of this policy's scope.
Which document wins
If anything in this policy conflicts with our Notice of Privacy Practices, the Notice governs for health information. Its contents are prescribed by HIPAA and it is the document you acknowledge as a patient. This policy is the website's account of the same commitments, written for a wider audience.
Changes to this policy
We may revise this policy. The effective date at the top changes when we do, and the revised version applies from that date. If a change is material, we will make it noticeable rather than relying on you to check — and where the change affects the Notice of Privacy Practices, patients are asked to review and acknowledge the new version at their next sign-in.
Questions and complaints
Questions about this policy, or about how your information was handled, go to our Privacy Officer at support@vivierhealth.com, or by post or phone at:
Vivier Health & Longevity, LLC · 19–21 Fair Lawn Ave, Fair Lawn, NJ 07410 · (201) 475-4091 · support@vivierhealth.com
If you believe your privacy rights have been violated, you may also complain directly to the U.S. Department of Health and Human Services, Office for Civil Rights — at hhs.gov/ocr/privacy/hipaa/complaints, or by post to 200 Independence Avenue SW, Washington, D.C. 20201. Complaints must generally be filed within 180 days.
We will not retaliate against you for filing a complaint, and doing so will not affect your care.