Hatályba lépés: 2026. április 4. • 2.0 verzió
Effective Date: April 4, 2026 | Last Revised: April 4, 2026 | Version: 2.0. This policy supersedes all prior versions. Please review it carefully.
Aquarius Medical Spa, LLC ("Company," "we," "us," or "our") is committed to protecting the privacy and security of your personal and health information. This Privacy Policy and Notice of HIPAA Privacy Practices ("Policy") explains how we collect, use, disclose, and safeguard your information when you visit our website (aquariusmedicalspa.com) or use our services. By using our website or services, you acknowledge that you have read, understood, and agree to be bound by the terms of this Policy. This site may contain links to third-party websites. Aquarius Medical Spa, LLC is not responsible for the privacy practices or content of such third-party sites, and we encourage you to review their policies independently.
The content on this website is provided for general informational purposes only and does not constitute medical advice, diagnosis, or treatment. Always seek the advice of a qualified, licensed healthcare provider regarding any medical condition or treatment. Nothing on this website creates or implies a physician-patient or provider-patient relationship until a formal agreement is established in writing. Aquarius Medical Spa, LLC makes no warranties, express or implied, regarding the accuracy, completeness, or fitness for a particular purpose of any information on this website. Your reliance on any information provided on this site is solely at your own risk.
We collect information that you voluntarily provide to us when you use our website, register for an account, complete intake forms, schedule appointments, or request services. The categories of information we may collect include:
We do not sell, rent, or lease your personal or health information to third parties for their marketing purposes under any circumstances.
Aquarius Medical Spa, LLC uses the information we collect for the following lawful purposes:
All electronic communications you send to Aquarius Medical Spa, LLC that contain or may contain Protected Health Information are treated as strictly confidential and governed by HIPAA. We do not use patient communications for marketing, promotional, or commercial purposes without your separate, explicit written authorization as required under 45 C.F.R. § 164.508.
All Aquarius Medical Spa, LLC account holders are solely responsible for maintaining the confidentiality of their login credentials and passwords. You agree to notify us immediately of any unauthorized access to your account.
Aquarius Medical Spa, LLC is committed to protecting the privacy of your email communications. We only send emails to individuals who have (a) expressly opted in to receive communications from us, or (b) established an existing patient or business relationship with us. We will not share your email address with any third party for marketing purposes.
Please be aware that standard (unencrypted) email is not a fully secure medium and carries inherent privacy risks. By providing your email address and consenting to electronic communications, you acknowledge these risks. Sensitive clinical information is best communicated through our secure patient portal. We will not transmit detailed clinical information via standard email without your explicit consent.
To stop receiving marketing or promotional emails from us, use the unsubscribe link in any such email or contact us directly at [email protected]. Note that opting out of marketing emails does not affect administrative or treatment-related communications required for your care.
Aquarius Medical Spa, LLC works with select third-party service providers who may access, process, or store Protected Health Information on our behalf in the course of providing services to us. As required by HIPAA (45 C.F.R. § 164.308(b)), these providers are bound by written Business Associate Agreements (BAAs) that require them to implement appropriate safeguards to protect your PHI and to report any breaches or security incidents to us.
Current third-party service integrations may include, but are not limited to: electronic health record infrastructure and hosting providers, supplement prescribing platforms, laboratory data services, and payment processors. We require all Business Associates to maintain the confidentiality and security of PHI in accordance with HIPAA.
Please note that certain consumer wellness device integrations (e.g., wearable fitness trackers such as Fitbit, WHOOP, and Dexcom) are governed by the privacy policies of those respective companies, which may be consumer products not subject to HIPAA. We encourage you to review the privacy policies of any third-party applications you choose to connect to your care. Your connection of such devices to our platform is voluntary and constitutes your authorization for us to access the health data you share through those integrations.
Aquarius Medical Spa, LLC employs industry-standard administrative, physical, and technical safeguards to protect your personal information and PHI, including:
Despite our efforts, no method of electronic transmission or storage is 100% secure. While we strive to use commercially reasonable means to protect your information, we cannot guarantee absolute security. In the event of a breach of unsecured PHI, we will notify affected individuals as required by the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400–414) and Arizona Revised Statutes § 18-552 within the timeframes mandated by law.
In the event of a breach of unsecured Protected Health Information involving your data, Aquarius Medical Spa, LLC will notify you in writing within sixty (60) days of discovery of the breach, as required by the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400–414). Notification will be provided by first-class mail to your address on file, or by electronic means if you have expressly consented to electronic notice. We will also notify the U.S. Department of Health and Human Services Office for Civil Rights and, where required by law, prominent media outlets serving the affected area. For breaches involving personal information governed by Arizona Revised Statutes § 18-551 et seq., we will notify affected Arizona residents as required by state law.
Aquarius Medical Spa, LLC uses cookies and similar tracking technologies to improve your experience on our website. Cookies are small data files stored on your device. We use:
We do not use cookies to collect Protected Health Information. We do not sell cookie data to third parties. You may disable cookies in your browser settings at any time; however, certain features of our website and patient portal may not function properly without cookies.
Aquarius Medical Spa, LLC retains patient medical records for a minimum of seven (7) years from the date of last service, or as otherwise required by Arizona Revised Statutes § 12-2297 and applicable federal regulations. After the applicable retention period expires, records are securely destroyed using methods that render PHI unreadable and unrecoverable. Non-clinical personal information collected through our website is retained only as long as necessary to fulfill the purpose for which it was collected, unless a longer retention period is required or permitted by law.
You may opt out of receiving marketing or promotional communications from us at any time by: (a) clicking the “unsubscribe” link in any marketing email we send; or (b) contacting us directly at [email protected]. Please note that opting out of marketing communications will not affect administrative emails related to your appointments, treatment, or account.
To request removal of your information from our marketing database, or to request correction of your personal (non-PHI) information, please contact us using the information in the “How to Contact Us” section below. To protect your privacy and security, we will take reasonable steps to verify your identity before making any changes to your information.
Aquarius Medical Spa, LLC does not knowingly collect personal information from individuals under the age of 18 without verifiable parental or legal guardian consent, as required by the Children’s Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506. No portion of our website is directed toward or designed to attract individuals under 18 years of age. Minors seeking clinical services at our facility must be accompanied by a parent or legal guardian who must provide written consent for treatment and for the collection of the minor’s health information.
If we discover that we have inadvertently collected personal information from a child under the age of 18 without appropriate parental consent, we will delete that information immediately. If you believe we hold any information from or about an individual under 18, please contact us immediately at [email protected].
We understand that information about you and your health is personal and sensitive. We are committed to protecting your health information in compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act. We create and maintain a record of the care and services you receive at Aquarius Medical Spa, LLC in order to provide you with quality care and to comply with applicable legal requirements. This notice describes your rights and our obligations regarding the use and disclosure of your Protected Health Information (PHI).
This Notice describes the privacy practices of Aquarius Medical Spa, LLC and applies to all healthcare professionals authorized to enter information into your medical record, all clinical and administrative staff, employees, contractors, volunteers, and other personnel of Aquarius Medical Spa, LLC.
Treatment. Your PHI may be used by our staff and disclosed to other healthcare professionals involved in your care for the purpose of evaluating your health, diagnosing medical conditions, and providing treatment.
Payment. Your PHI may be used and disclosed as necessary to obtain payment for services rendered. For example, we may submit claims to your health insurer or provide information needed for billing verification and payment processing.
Healthcare Operations. Your PHI may be used for internal operations necessary to support the management of Aquarius Medical Spa, LLC, including quality assessment, staff training, compliance activities, and business planning — all on a minimum-necessary basis.
Law Enforcement & Government Activities. Your PHI may be disclosed to law enforcement agencies, government oversight bodies, or public health authorities without your prior authorization where required or permitted by law, including to support government audits and inspections, facilitate law-enforcement investigations, or comply with government-mandated reporting obligations.
Public Health Reporting. As required by law, we may disclose your PHI to public health authorities to: prevent or control disease, injury, or disability; report reactions to medications or product defects; notify persons exposed to a communicable disease; or report suspected abuse, neglect, or domestic violence to appropriate government authorities as required or permitted by law.
Military & Veterans. If you are a member of the armed forces, we may release your PHI as required by military command authorities or applicable federal law.
Judicial & Administrative Proceedings. We may disclose your PHI in response to a court order, administrative order, subpoena, discovery request, or other lawful legal process.
Occupational Exposure. In the event a healthcare worker is accidentally exposed to blood or bodily fluids during your treatment, your blood may be tested for the presence of certain communicable diseases as necessary to protect the health care worker. Results will be maintained as part of your medical record and will not be disclosed except with your prior written consent or as required by law.
Aquarius Medical Spa, LLC may communicate with patients via email, our secure patient portal, telephone, or other electronic means for appointment scheduling, treatment updates, and administrative purposes. While we implement reasonable technical safeguards, standard email is not an encrypted medium and carries inherent privacy risks. By providing your email address and consenting to electronic communications, you acknowledge and accept these risks. We strongly encourage sensitive clinical communications to be conducted through our secure patient portal. We will not transmit detailed clinical information via standard unencrypted email without your explicit consent.
Any use or disclosure of your PHI for purposes other than those described above — including most marketing activities, the sale of PHI, and psychotherapy notes — requires your specific prior written authorization (45 C.F.R. § 164.508). If you authorize a use or disclosure and later change your mind, you may submit a written revocation to us at any time. However, your revocation will not affect any actions we took in reliance on your authorization prior to receiving your revocation.
Aquarius Medical Spa, LLC is required by law to maintain the privacy of your Protected Health Information, to provide you with this Notice of Privacy Practices, and to abide by the terms of the notice currently in effect. We reserve the right to change our privacy practices and to make any revised Notice effective for PHI we already maintain as well as PHI we receive in the future. Any material changes to this Notice will be posted on this page with an updated effective date.
Under HIPAA and applicable Arizona law, you have the following rights with respect to your Protected Health Information:
To exercise any of these rights, please submit a written request to us using the contact information below. We will respond within the timeframe required by law.
Appointment Reminders. We may use your PHI to contact you with appointment reminders via phone, email, or our patient portal.
Treatment Alternatives & Health Benefits. We may use your PHI to inform you of treatment alternatives, recommended procedures, or health-related services that may be of clinical benefit to you.
Marketing Communications. We will not use or disclose your PHI for marketing purposes without your prior written authorization, except as expressly permitted by HIPAA (45 C.F.R. § 164.514(e)).
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, AQUARIUS MEDICAL SPA, LLC SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING OUT OF OR RELATED TO YOUR USE OF THIS WEBSITE, THE SERVICES PROVIDED, OR ANY BREACH OF THIS PRIVACY POLICY, EVEN IF AQUARIUS MEDICAL SPA, LLC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. IN NO EVENT SHALL THE TOTAL LIABILITY OF AQUARIUS MEDICAL SPA, LLC TO YOU FOR ALL CLAIMS ARISING OUT OF OR RELATED TO THIS PRIVACY POLICY EXCEED THE TOTAL AMOUNT YOU PAID TO AQUARIUS MEDICAL SPA, LLC IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
Nothing in this limitation of liability section shall limit or exclude liability for gross negligence, intentional misconduct, or any liability that cannot be excluded or limited under applicable federal or Arizona state law, including obligations arising under HIPAA.
This Privacy Policy shall be governed by and construed in accordance with the laws of the State of Arizona, without regard to its conflict of law provisions. Any disputes arising under or in connection with this Policy that are not resolved informally shall be subject to the exclusive jurisdiction of the state and federal courts located in Maricopa County, Arizona. You hereby consent to personal jurisdiction and venue in such courts.
Aquarius Medical Spa, LLC reserves the right to change this Privacy Policy at any time. Any revised Notice will be posted on this page with an updated effective date and version number. Material changes will be made effective for PHI we already maintain as well as PHI we receive in the future, as permitted by HIPAA. We encourage you to review this Policy periodically. Your continued use of our website or services following the posting of changes constitutes your acceptance of the revised Policy.
Complaints regarding our privacy practices may also be filed with the U.S. Department of Health and Human Services Office for Civil Rights at ocrportal.hhs.gov or by calling 1-800-368-1019. We will not retaliate against you for filing such a complaint.
For questions, concerns, or to exercise any of your rights under this Privacy Policy or HIPAA, please contact our Privacy Officer at:
Aquarius Medical Spa, LLC
Privacy Officer / Practice Manager
Phone: (480) 602-7772
Email: [email protected]
Purpose of Consent. By submitting your information to Aquarius Medical Spa, LLC online or in person, you consent to our use and disclosure of your Protected Health Information to carry out treatment, payment activities, and healthcare operations, including communications via our patient portal or email as described in this Policy.
Notice of Privacy Practices. You have the right to review this Notice of Privacy Practices in full before consenting. This Notice describes the uses and disclosures we may make of your PHI and your rights with respect to that information. We encourage you to read it carefully and completely.
Electronic Communication Consent. By providing your email address and submitting information to Aquarius Medical Spa, LLC online or by email, you consent to our use of electronic communications with you, including communications that may reference your protected health information as necessary for your care. You acknowledge that standard email is not fully encrypted and accept the associated risks.
Right to Revoke. You have the right to revoke your consent at any time by submitting a written notice of revocation to us. Please understand that revocation will not affect any actions we took in reliance on your consent prior to receiving your written revocation, and that in certain circumstances we may decline to provide or continue providing services if you revoke consent necessary for treatment or operations. To revoke, contact us at [email protected].
Policy Updates. We reserve the right to revise this Privacy Policy and our email practices. Any changes will be posted on this page. You may obtain a current copy of this Notice at any time by contacting us at the information provided above.
This Privacy Policy was last reviewed and updated on April 4, 2026. This document does not constitute legal advice. Aquarius Medical Spa, LLC recommends consultation with a licensed healthcare attorney for legal guidance specific to your situation.