Privacy Policy
This policy covers the hipaaops.com website. Plain language, no surprises.
Who we are
This website is operated by Fivefold Symmetry Inc. (doing business as “HIPAA Ops”), a healthcare IT consultancy based in Orange County, California. We are the controller of the information described below. You can reach us any time at [email protected].
This policy applies to hipaaops.com only. Client engagements and the HIPAA Ops Platform are covered by separate agreements — see About the HIPAA Ops Platform below. Your use of this site is also subject to our Terms & Conditions.
What we collect — and why
- Contact form submissions — if you use the form on this site, we receive the name, organization, email address, and message you type. We use them for exactly one purpose: responding to your inquiry. Submissions are stored in our own self-hosted systems in the United States — not in a third-party CRM.
- Spam protection (Cloudflare Turnstile) — the contact form is protected by Cloudflare Turnstile, which analyzes limited browser and network signals to tell humans from bots. This processing is performed by Cloudflare, which also serves this website’s traffic. See Cloudflare’s privacy policy.
- Server logs — like virtually every website, basic technical request data (IP address, page requested, timestamp) may appear in short-lived server and network logs used for security and troubleshooting.
- Theme preference — your light/dark mode choice is saved in your own browser’s local storage. It never leaves your device and identifies nothing about you.
We never ask for protected health information on this website. Please don’t include patient details in a contact form message — if you need to share something sensitive, tell us and we’ll set up a secure channel.
Cookies and local storage
We use the minimum set of browser storage needed for the site to work and stay secure. There are no advertising or analytics cookies on this site, so there is nothing to “opt in” to beyond the essentials below.
- Security / anti-bot — Cloudflare may set a short-lived cookie or token to verify that form submissions and page requests come from a human and to protect the site from abuse. This is strictly necessary and cannot be disabled while using the form.
- Theme preference — a local storage entry recording your light/dark mode choice.
- Cookie notice choice — a local storage entry recording that you dismissed the cookie notice, so we don’t show it on every page.
You can clear these at any time from your browser’s settings, and blocking them only affects convenience and spam protection — not your ability to read the site. Because we run no tracking technologies, we honor Global Privacy Control and Do Not Track signals by default.
What we don't do
- No analytics or ad trackers. — This site runs no Google Analytics, no advertising pixels, no fingerprinting, no cross-site tracking of any kind.
- No selling or sharing. — We never sell, rent, or trade your information, and we don’t share it with third parties for their own marketing. We have not sold or shared personal information in the preceding twelve months.
- No marketing lists. — Contacting us does not sign you up for a newsletter or automated email sequences.
- No payment or credential collection. — This website never asks for passwords, payment card details, or health information.
- No automated decision-making. — Nothing you submit is used for profiling or automated decisions about you.
Who we share information with
We keep the list of parties that touch this website’s data deliberately short:
- Cloudflare — content delivery, network security, and Turnstile spam protection for site traffic.
- Our email provider — delivery of the reply we send to your inquiry.
- Legal and safety — we may disclose information if required by law, subpoena, or to protect the rights and safety of people or systems.
If our company is ever involved in a merger or acquisition, information may transfer as part of that transaction, subject to this policy.
How we protect information
Traffic to this site is encrypted in transit with TLS. Contact submissions are stored on access-controlled, self-hosted systems in the United States, backed up on an encrypted schedule, and available only to the small team that responds to inquiries. No system is perfectly secure, but we apply the same infrastructure practices to our own site that we build for clients.
Retention and your choices
- We keep contact inquiries only as long as needed to handle the conversation and any business relationship that follows — typically no more than 24 months for inquiries that don’t become engagements.
- Server and security logs are short-lived and rotate automatically.
- You can ask us at any time to show you or delete the information you’ve submitted, correct anything inaccurate, or receive a copy of it — email [email protected] and we’ll take care of it, normally within 30 days. California residents have these rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them; we extend the same courtesy to everyone.
Children's privacy
This site is intended for healthcare operators and administrators. We do not knowingly collect information from anyone under 18 through this website. If you believe a minor has submitted information, email us and we’ll delete it.
Visitors outside the United States
Our services are offered to organizations in California, and this website and its data are hosted in the United States. If you visit from another country, your information is processed in the U.S. under this policy.
About the HIPAA Ops Platform
Our client software (the HIPAA Ops Platform) runs on separate systems and is governed by written agreements with each client organization, including Business Associate Agreements where protected health information is involved. This website neither collects nor stores any patient data.
Changes
If this policy changes, we’ll update this page and its effective date; material changes will be called out at the top. Questions? [email protected].