Skip to content
VIVIERHEALTH & LONGEVITY

Loading…

Searches this site only · nothing you type is sent anywhere

LEGAL

Privacy
policy

What this website collects, how health information is handled, who it is shared with, and the rights you have over it.

Effective August 7, 2026

Vivier Health & Longevity, LLC (“Vivier”, “we”, “us”) is a clinician-led medical practice in Fair Lawn, New Jersey, and a covered entity under the Health Insurance Portability and Accountability Act (HIPAA). This policy explains what we collect through this website, how we use it, and what you can ask us to do about it.

It is written to be read. Where a section has a legal term behind it, the term is named so you can look it up, but the sentence is meant to make sense without doing so.

This policy, and the Notice of Privacy Practices

Two different documents govern two different relationships, and which one applies to you depends on whether you are a patient.

  • This privacy policy covers everyone who uses this website — what the pages collect, what our analytics sees, and what happens to a waitlist inquiry.
  • Our [Notice of Privacy Practices](/privacy/notice) covers your health information once you are a patient of the practice. Its contents are prescribed by HIPAA (45 CFR 164.520), and you are asked to review and acknowledge it when you enrol.

The two overlap for one group of people: someone who submits the waitlist form and describes a health concern in it. From the moment that form reaches us, the information in it is protected health information and the Notice governs how we treat it — before that person is a patient and whether or not they ever become one.

What this website collects

If you only read

Browsing this site requires no account and collects no information that identifies you by name. Our analytics records the page you viewed, the site that referred you, your approximate region, your device type and language, and a randomly generated identifier stored in a first-party cookie. That is described in full under cookies and analytics.

If you use the waitlist form

The form on our home page asks for, and stores, exactly these fields:

  • Your first name, and your last name if you give one
  • Your email address
  • Your phone number, if you give one
  • Which membership tier you are interested in, or that you are not sure yet
  • Anything you write in the free-text field, which is optional

We also record the IP address the submission came from and your browser's user-agent string. Those exist so we can investigate abuse of the form — spam, automated submissions — and for no other purpose. They are not used to build a profile of you, and they are not shared with our analytics.

The free-text field is the one to be deliberate about. People use it to describe symptoms, conditions, and medications, and that is a reasonable thing to do — but it means the field collects health information attached to your name and contact details. We treat everything written there as protected health information from the moment it arrives. Nothing in it is ever logged, sent to analytics, or transmitted to any service not bound by an agreement to protect it. If you would rather not put a health concern in a web form, call the practice on (201) 475-4091 instead — the form deliberately works with the field left empty.

If you become a patient

Enrolment collects your date of birth, your acknowledgement of the consent documents you are shown, and the sign-in credentials for your account. Your clinical record — visits, assessments, results, correspondence — is created and held by the practice, and is governed by the Notice of Privacy Practices rather than by this policy.

How we use what we collect

HIPAA permits a practice to use health information for treatment, payment, and health care operations without asking separately each time — that is the ordinary business of providing care, arranging to be paid for it, and running the practice. Everything below falls within that, or is something you asked us to do.

  • To answer you. A waitlist inquiry is used to contact you about becoming a patient, and to have an informed first conversation.
  • To provide care. Scheduling, clinical assessment, treatment planning, monitoring, and communication with your care team.
  • To arrange payment. Membership billing, and the records that go with it.
  • To run the practice. Quality review, staff training, security monitoring, and the audit records HIPAA requires us to keep.
  • To meet legal obligations. Where a law, subpoena, or public-health authority requires a disclosure.
  • To understand the website. Aggregate measurement of which pages are read — never tied to a patient, and never to anything clinical.

We do not sell your information. We do not disclose it to data brokers, and we do not exchange it for anything of value. HIPAA independently prohibits the sale of protected health information without your written authorization (45 CFR 164.508(a)(4)), and we do not do it for anything else either.

We do not use your health information for marketing without a separate written authorization from you. That includes testimonials, case studies, before-and-after photographs, and named success stories — none of which appear on this site. A review you left somewhere public is not an authorization, and we do not treat it as one.

Who we share it with

A short list, and it is the whole list.

Clinicians and services involved in your care

Other clinicians treating you, laboratories processing your samples, pharmacies dispensing what you are prescribed, and any facility where a procedure is performed.

Vendors who work on our behalf

The services that host our systems and support the practice can, in the course of doing that, come into contact with health information. HIPAA calls them business associates, and every one of them has signed a Business Associate Agreement obliging them to protect that information, to use it only for the work we have asked them to do, and to report any breach to us. We do not send health information to a vendor that has not signed one — this is a hard rule in how the software is built, not a policy someone has to remember.

In practice this means our cloud infrastructure provider, which hosts the application and the database, and the services that deliver secure messages and support the clinical workflow.

Our payment processor

Membership payments are processed by Stripe. Stripe receives your name, email address, billing address, card details, the amount charged, the name of the membership tier, and our internal identifier for your account.

Stripe never receives anything clinical. Not a diagnosis, a symptom, a medication, a therapy name, a lab result, or the reason for an appointment — not in a product name, a description, an invoice line, or a hidden field. Payment processing is specifically excluded from HIPAA's definition of a business associate, and that exclusion holds only for as long as the processor sees money rather than medicine. Keeping it that way is a deliberate constraint on how the billing integration is built. The descriptor on your bank or card statement names the practice and never a service, because a statement is read by whoever sees that account.

When the law requires it

We disclose information where we are legally required to — for example to public-health authorities, in response to a valid court order or subpoena, to report suspected abuse or neglect, for certain law-enforcement purposes, or to health-oversight agencies conducting an audit or investigation. The Notice of Privacy Practices sets these out in the detail HIPAA requires.

Anything else needs your permission

Any use or disclosure not described above requires your written authorization, which you can withdraw at any time. Withdrawing it stops anything further; it cannot undo something already done while the authorization was in force.

Cookies, analytics, and what is not here

This site runs a deliberately small amount of third-party code, and where it runs is a boundary rather than a preference.

What runs on the public pages

The public pages — everything you can read without signing in — run Google Analytics 4. It sets a first-party cookie containing a random identifier, and reports the page address, the referring site, your device, screen size and language, and an approximate location derived from your IP address. Google discards the address itself rather than storing it.

Two things about that measurement are configured off, and both matter: Google Signals and advertising personalization. That keeps it a page-counting tool rather than something that can feed a reader's visit into an advertising profile. The site's content security policy blocks the advertising endpoints outright, so this holds even if the setting is ever changed by mistake.

We accept one real cost in exchange: on a site like this, a page address is itself a clue about your interests. Google is told that someone read a particular guide. It is not told who, it is never told what you wrote in a form, and it is never told anything from a patient's record.

What does not run anywhere on this site

  • No session recording or heatmaps. Those tools capture what you type into forms by default, which would turn a marketing tool into an unauthorized processor of health information.
  • No advertising or conversion pixels, and no tag manager.
  • No chat widget.
  • No third-party analytics of any kind on the patient or administrative pages. The measurement above is structurally prevented from loading there — it is not a matter of remembering to exclude it.
  • No sharing of health information with any advertising platform, in any form, ever.

The cookies we set ourselves

  • A session cookie, once you sign in. It is `httpOnly` (unreadable by scripts in your browser), `Secure` (sent only over an encrypted connection), and `SameSite=Strict` (not sent when another site links to us). It holds no health information and expires.
  • The analytics cookie described above, on public pages only.

You can block or delete cookies in your browser. Blocking the analytics cookie has no effect on the site; blocking the session cookie will prevent you from signing in.

Do Not Track. Browsers send this signal inconsistently and there is no agreed standard for honouring it, so we do not represent that we respond to it. Nothing described on this page changes based on it, and nothing described on this page tracks you across other websites.

How it is protected

The HIPAA Security Rule requires administrative, physical, and technical safeguards. These are the technical ones, stated plainly because a claim of “industry-standard security” tells you nothing.

  • Encrypted in transit. Every connection uses TLS 1.2 or better — your browser to us, our systems to each other, and our application to its database.
  • Encrypted at rest. The database, its backups, file storage, and message queues are encrypted with keys we manage.
  • Held inside a private network. The systems holding health information are not reachable from the internet. Requests reach them through a single controlled entry point.
  • Access is checked on every request, against your identity and your role, on the server. The application never relies on the browser or the app to decide what you are allowed to see.
  • Minimum necessary. Screens and interfaces are built to return only the fields they need. Our staff dashboards show counts and status rather than clinical detail, so an open screen on a shared monitor discloses nothing.
  • Every access is audited. Reads and writes of health information produce a permanent record of who, what, when, and from where. That record is append-only — the application has no ability to alter or delete it, enforced by database permission rather than by convention.
  • Sessions are short and revocable, with multi-factor authentication, automatic timeout after inactivity, and immediate server-side revocation.
  • Health information never appears in logs, error reports, or web addresses. It is stripped before anything is recorded, and it travels in the body of a request rather than in a URL, because addresses end up in server logs, browser history, and proxies.
  • Test and development systems contain no real patient data, ever. Development uses synthetic data generated for the purpose.

No system is perfect, and any claim otherwise should be treated with suspicion. What we can commit to is that the safeguards above are how the software is actually built, and that we will tell you if they fail — see breach notification.

How long we keep it

We keep information for as long as we need it for the purpose it was collected for, and for as long as the law requires. Patient records are retained for the period New Jersey law requires of a medical practice. A waitlist inquiry that does not become a patient record is deleted 24 months after it is submitted — the whole of it, including the health information written in it and the IP address recorded with it.

Some records are deliberately permanent. Our audit trail cannot be edited or deleted by design, because an audit trail that can be altered is not one, and billing history is kept as the record of what was charged. Neither contains clinical detail.

You can ask us what we hold about you and ask us to delete it — see your rights. Where the law requires us to keep something, we will tell you that rather than quietly declining.

Your rights

If you are a patient

HIPAA gives you the following rights over your health information. You can exercise any of them by writing to us at support@vivierhealth.com, and we will not treat you differently for doing so.

  • See and get a copy of your record — electronically if you prefer, and we will send it to someone else if you direct us to in writing (45 CFR 164.524).
  • Ask us to correct it if you believe something is wrong or incomplete. If we disagree, you may file a statement of disagreement that becomes part of the record (164.526).
  • Get a list of certain disclosures we have made of your information (164.528).
  • Ask us to restrict how we use or share it. We are not required to agree to every request — with one exception: if you pay for a service in full yourself, you can require us not to disclose that service to a health plan, and we must honor it (164.522(a)).
  • Ask us to contact you a particular way — a specific phone number, address, or method. We will accommodate reasonable requests without asking why (164.522(b)).
  • Get a paper copy of the Notice of Privacy Practices, even if you have already received it electronically (164.520(c)).
  • Withdraw an authorization you previously gave, in writing, at any time (164.508(b)(5)).
  • Complain — to us, or directly to the U.S. Department of Health and Human Services. See complaints.

If you are a website visitor

You can ask us what we hold about you, ask us to correct it, and ask us to delete it. If you submitted the waitlist form and would rather we did not keep it, email support@vivierhealth.com and say so — we will delete the inquiry and confirm that we have.

New Jersey residents have rights under the New Jersey Data Privacy Act, and residents of other states may have rights under their own laws. Most of these laws exclude information already covered by HIPAA, precisely because HIPAA's protections are stronger — so for anything clinical, the rights listed above are the ones that apply and they are broader.

If something goes wrong

If your unsecured health information is breached, HIPAA requires us to notify you without unreasonable delay and within 60 days of discovering it (45 CFR 164.404), to notify the Secretary of Health and Human Services, and — for a breach affecting 500 or more people in a state or jurisdiction — to notify prominent media there. New Jersey law imposes its own notification duties, which run alongside these rather than replacing them.

We will tell you what happened, what information was involved, what we are doing about it, and what you can do to protect yourself.

How we contact you

We will contact you about your inquiry, your care, your appointments, and your membership. You can ask us to use a particular method or number at any time.

Ordinary email and text messages are not secure. They pass through systems we do not control and can be read by anyone with access to the account or the device. We keep anything clinical out of them — a message will tell you that something is waiting for you and ask you to sign in, rather than containing it. If you email us health information yourself, we will receive and protect it, but the journey to us was not encrypted end to end and we cannot make it retroactively so.

You can opt out of non-essential messages at any time. We will still send the ones that are part of your care or required for your account — appointment details, billing notices, and security alerts — because those are not marketing.

Children

This practice treats adults. The site is not directed at children, and we do not knowingly collect information from anyone under 18. If you believe a child has submitted information to us, email support@vivierhealth.com and we will delete it.

Other websites

Where this site links to somewhere else — a manufacturer, a professional body, a mapping service — that site has its own privacy policy and we are not responsible for it. Following such a link takes you out of this policy's scope.

Which document wins

If anything in this policy conflicts with our Notice of Privacy Practices, the Notice governs for health information. Its contents are prescribed by HIPAA and it is the document you acknowledge as a patient. This policy is the website's account of the same commitments, written for a wider audience.

Changes to this policy

We may revise this policy. The effective date at the top changes when we do, and the revised version applies from that date. If a change is material, we will make it noticeable rather than relying on you to check — and where the change affects the Notice of Privacy Practices, patients are asked to review and acknowledge the new version at their next sign-in.

Questions and complaints

Questions about this policy, or about how your information was handled, go to our Privacy Officer at support@vivierhealth.com, or by post or phone at:

Vivier Health & Longevity, LLC · 19–21 Fair Lawn Ave, Fair Lawn, NJ 07410 · (201) 475-4091 · support@vivierhealth.com

If you believe your privacy rights have been violated, you may also complain directly to the U.S. Department of Health and Human Services, Office for Civil Rights — at hhs.gov/ocr/privacy/hipaa/complaints, or by post to 200 Independence Avenue SW, Washington, D.C. 20201. Complaints must generally be filed within 180 days.

We will not retaliate against you for filing a complaint, and doing so will not affect your care.