Jacqueline Younesi Dentistry ("we", "our", "us") is a general, cosmetic, and family dental practice located at 2121 East Coast Hwy, Suite 230, Corona Del Mar, CA 92625. We respect the privacy of every patient and every visitor to this website. This Privacy Policy explains what information we collect through www.jyounesidentistry.com, why we collect it, who we share it with, how long we keep it, how we protect it, and the choices and legal rights you have over it.
Two different sets of rules apply to your information
It matters a great deal which category your information falls into, because different laws govern each one.
- Protected health information (PHI). We are a HIPAA covered entity. Information created or received in the course of your dental care, including your chart, treatment notes, radiographs, photographs, diagnoses, treatment plans, prescriptions, insurance claims, and billing records, is protected health information. It is governed by the federal Health Insurance Portability and Accountability Act and its implementing regulations, by the California Confidentiality of Medical Information Act, and by our Notice of Privacy Practices. It is not governed by this Privacy Policy. Where the two documents could be read to conflict, the Notice of Privacy Practices controls for PHI.
- Ordinary website information. Information collected because you visited this website, such as your IP address, the pages you viewed, the device and browser you used, and anything you type into a contact form before you are a patient of record, is not automatically PHI. That information is governed by this Privacy Policy and, for California residents, by the California Consumer Privacy Act as amended by the California Privacy Rights Act.
One practical consequence: please do not send us health details, insurance identifiers, Social Security numbers, or payment card numbers through the website contact form or through ordinary email. Neither channel is encrypted end to end, and neither is a substitute for the secure channels we use for patient communication. If you need to discuss something clinical or financial, call the office at (949) 409-9895 and we will move the conversation to a secure method.
Notice of Privacy Practices (HIPAA)
Our Notice of Privacy Practices is posted on this website and is available to you electronically, at any time, without asking anyone for it. You can read it at jyounesidentistry.com/notice-of-privacy-practices. A link to it also appears in the footer of every page of this site.
We post it here because federal law requires it. A covered entity that maintains a website providing information about its services must prominently post its notice on that site and make the notice available electronically through it. Handing the notice to patients at intake, which we also do, does not by itself satisfy that obligation.
The Notice of Privacy Practices describes, in full:
- How we may use and disclose your protected health information for treatment, payment, and health care operations.
- The uses and disclosures that require your written authorization, and your right to revoke that authorization.
- The uses and disclosures permitted or required by law without your authorization, including public health reporting and responses to lawful process.
- Your individual rights, including the right to inspect and obtain a copy of your records, to request an electronic copy, to request an amendment, to receive an accounting of certain disclosures, to request confidential communications at an alternative address or phone number, to request restrictions on certain uses and disclosures, and to require that we not disclose to a health plan a service you paid for in full out of pocket.
- Our duties, including our obligation to notify you following a breach of unsecured protected health information.
- How to complain to us and how to complain to the Secretary of the U.S. Department of Health and Human Services, and our commitment not to retaliate for either.
You may also request a paper copy of the Notice of Privacy Practices at any time, even if you have already read it online. Ask at the front desk, or call (949) 409-9895 and we will mail one to you at no charge.
Notice at collection
This section is our summary notice at collection for California residents. It tells you, at or before the point we collect anything, what we take and why. The sections that follow give the full detail.
- What we collect: identifiers, limited commercial and inquiry information, internet and device activity, coarse location inferred from IP address, and any information you choose to type into a form.
- Why: to answer you, to schedule and confirm appointments, to run and secure the website, to measure how the site performs, and to meet legal obligations.
- Sensitive personal information: we do not ask for it through this website and we do not use or disclose any that you volunteer for purposes beyond those permitted by California law.
- Sale: we do not sell personal information for money, and we never have.
- Sharing: we do not share personal information for cross-context behavioral advertising. This website does not use analytics cookies, advertising pixels, or similar tracking technologies. See Sale and sharing below.
- How long we keep it: see How long we keep information below.
Personal information we collect, and where it comes from
Over the twelve months preceding the effective date of this policy, we have collected the following categories of personal information through this website. The California statutory category name is given first, followed by what that actually means for us and the source it comes from.
- Identifiers. Your first and last name, email address, telephone number, and IP address. Source: directly from you when you complete a contact or appointment form, and automatically from your browser and our hosting provider when you load a page.
- Customer records information. Name, telephone number, and email address in association with an inquiry, which overlaps with the category above and is listed separately because California law enumerates it separately. Source: directly from you.
- Commercial information. The subject of your inquiry, such as which service you selected from the topic list, and any appointment you request. Source: directly from you, and from our appointment platform when you book.
- Internet or other electronic network activity information. The pages your browser requests, the referring page, browser type and version, operating system, and the date and time of each request, as recorded in standard server logs. Source: automatically from your browser, through the server logs kept by our hosting provider. This website does not use analytics or advertising cookies.
- Geolocation data, coarse only. An approximate city or region inferred from your IP address. We do not request or collect precise device location from this website. Source: automatically, by inference from your IP address.
- Audio, electronic, or visual information. The free-text content of any message you send us, and voicemail if you call the office. Source: directly from you.
- Inferences. Aggregate and de-identified conclusions about how visitors as a group use the site, for example which services draw the most interest. We do not build individual advertising profiles. Source: derived by us from the categories above.
Sensitive personal information. We do not ask you for sensitive personal information through this website. We do not request Social Security numbers, driver's license numbers, financial account numbers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic or biometric data, or the contents of your mail, email, or text messages. Health information you volunteer in a free-text message can qualify as sensitive personal information, which is why we ask you not to include it. To the extent you send it anyway, we use it only to respond to your inquiry and for other purposes that California law permits without a right to limit, and we never use it to infer characteristics about you.
Why we collect it: our business and commercial purposes
Each purpose below is tied to the categories of information it actually uses.
- Answering you. To read, route, and reply to inquiries, and to call or email you back. Uses identifiers, customer records, commercial information, and message content.
- Scheduling. To request, confirm, reschedule, and remind you about appointments. Uses identifiers, customer records, and commercial information.
- Providing and improving care and patient communications. Once you become a patient, this activity is governed by our Notice of Privacy Practices rather than this policy.
- Operating and securing the website. To serve pages, balance load, detect and block abuse, spam, and automated attacks, debug errors, and maintain availability. Uses internet activity, identifiers, and coarse geolocation.
- Measuring performance. To understand in aggregate, from server logs and hosting statistics, which pages are requested and whether the site is working properly, so we can improve it. Uses internet activity and inferences.
- Legal and regulatory compliance. To meet obligations under health care, tax, employment, consumer protection, and records retention law, to respond to lawful requests, and to establish, exercise, or defend legal claims. Uses any category, as required.
We do not use personal information collected through this website for any materially different, unrelated, or incompatible purpose without first providing you notice.
Who we disclose it to
We do not disclose personal information to third parties except as described here. Each recipient below is bound by contract, by its own published terms, or by a HIPAA business associate agreement where it handles protected health information on our behalf.
- Appointment scheduling: Dentrix Ascend, operated by Henry Schein One. Our "Request Appointment" links take you to a scheduling portal hosted by Dentrix Ascend at bookit.dentrixascend.com. Information you enter there is collected by that platform, is governed by its privacy terms in addition to this policy, and, where it constitutes protected health information, is handled by Dentrix Ascend as our business associate under a HIPAA business associate agreement. Categories disclosed: identifiers, customer records, commercial information.
- Map: OpenStreetMap Foundation. Our contact page embeds a map from openstreetmap.org. When the map loads, your browser requests map images directly from OpenStreetMap's servers, which receive your IP address and that request under the OpenStreetMap Foundation's own privacy policy. Categories disclosed: internet activity, identifiers limited to IP address.
- Website hosting and security: Cloudflare, Inc. This site is a static site served through Cloudflare Pages. Cloudflare processes request metadata and server logs to deliver pages and to protect the site from attack. Categories disclosed: internet activity, identifiers limited to IP address.
- Email and form delivery providers, which transmit and store the messages you send us. Categories disclosed: identifiers, customer records, message content.
- Professional advisors, such as our attorneys, accountants, and insurers, where reasonably necessary and under a duty of confidentiality.
- Government authorities and other parties where we are legally compelled, where necessary to comply with law or lawful process, to enforce our rights, or to protect the safety of any person.
- A successor entity, if the practice is ever sold, merged, or reorganized. Patient records would transfer subject to HIPAA and California law, and this policy would continue to apply to website information until replaced by a notice to you.
Each third party listed above is governed by its own privacy policy in addition to any agreement it has with us, and we encourage you to review those policies. We do not authorize any of them to use information received from us for their own independent marketing purposes.
Sale and sharing of personal information
We do not sell your personal information for money and we never have. We also do not sell or share the personal information of anyone we know to be under 16 years of age.
California law defines "sharing" broadly enough to capture disclosures for cross-context behavioral advertising even when no money changes hands. We do not share personal information for that purpose. This website does not use analytics services, tag managers, advertising pixels, or other third-party tracking technologies. If that ever changes, we will update this policy before the change takes effect and give you a way to opt out.
Global Privacy Control. We honor the Global Privacy Control browser signal. If your browser, extension, or device transmits a GPC signal, we treat it as a valid, verifiable request to opt out of the sale and sharing of personal information associated with that browser, and we act on it automatically. You do not need to contact us, we do not require you to create an account, and we do not ask you to confirm the request. Because a GPC signal is tied to the browser rather than to you, you will need to enable it in each browser and on each device you use.
You may also submit an opt-out request at any time by writing to office@jyounesidentistry.com, our designated request channel.
Cookies, analytics, and tracking technologies
This website does not use analytics services, advertising cookies, tracking pixels, or tag managers. Our fonts are hosted on our own website, so loading a page does not send your information to a font provider.
The site uses a small amount of storage in your own browser to make features work. For example, if you use the Accessibility options panel, your display choices (such as larger text or high contrast) are saved in your browser so they apply on every page. That information stays on your device, is not sent to us, and is not used to track you. You can clear it at any time with the panel's Reset button or your browser settings.
Embedded content. The map on our contact page is provided by OpenStreetMap, as described under Who we disclose it to. Links to our scheduling portal, Google Maps, and our profiles on review and social media websites send information to those companies only if you choose to follow them.
Your controls. You can block or delete cookies and site storage in your browser settings or use your browser's private mode. Blocking storage will not prevent you from reading any page on this site or from contacting the practice. Because there is no consistent industry standard for the older "Do Not Track" header, we do not respond to it, and we honor Global Privacy Control instead.
How long we keep information
We keep each category only as long as we need it, then delete it or de-identify it. Where an exact period depends on facts we cannot know in advance, the criteria we apply are stated instead.
- Dental records and other protected health information. Retained for at least seven years from the date of the last entry, and for patients who were minors at the time of treatment, until at least seven years after they reach the age of 18. Retention of PHI is governed by our Notice of Privacy Practices and by California dental record retention law, not by this policy.
- Website inquiries and contact form messages. Retained for up to 24 months from your last contact with us, so that we have context if you write again. Messages that become part of a patient record follow the PHI schedule above instead.
- Appointment requests made through Dentrix Ascend. Retained according to that platform's configured retention and our records obligations, and for patients, according to the PHI schedule above.
- Server and security logs. Retained for a short operational window, generally no more than 30 days, unless a specific log is preserved longer to investigate an incident.
- Records of privacy requests. Retained for at least 24 months, because California law requires us to keep a record of the requests we receive and how we responded.
- Anything under legal hold. Retained until the underlying claim, audit, investigation, or legal obligation is resolved, regardless of the periods above.
How we protect information
No method of transmission or storage is perfectly secure, and we will not tell you otherwise. What we can tell you is what we actually do. We maintain administrative, technical, and physical safeguards designed to be reasonable and appropriate to the sensitivity of the information we hold, including:
- Encryption in transit. The entire website is served exclusively over HTTPS with HTTP Strict Transport Security, so browsers refuse to connect insecurely.
- A Content Security Policy and related security headers that restrict which scripts, frames, and connections a page may load, limiting the damage a third-party compromise could do.
- A static site architecture. This website has no database and no application server behind it, which removes the most commonly exploited class of vulnerability entirely.
- Access controls and least privilege, so staff and vendors reach only the information their role requires.
- Business associate agreements with every vendor that handles protected health information on our behalf, as HIPAA requires.
- Workforce training on privacy and security, and a HIPAA Security Rule risk analysis and risk management process for systems that hold PHI.
- Vendor review before we adopt a service that will touch personal information.
- Breach response procedures, including the notifications required by HIPAA and by California law if unsecured information is ever compromised.
Children and minors
We welcome families and treat children as patients, but this website is written for adults. It is not directed to children, and we do not knowingly collect personal information online from a child under 13 without verifiable parental consent. We do not sell or share the personal information of any consumer we know to be under 16 years of age, and we have no actual knowledge of ever having done so. A parent or legal guardian who believes a child has provided personal information through this website may write to office@jyounesidentistry.com and we will delete it promptly. Information about a minor patient created during treatment is protected health information and is governed by our Notice of Privacy Practices and by California law on minors' health information.
Your California privacy rights
If you are a California resident, you have the rights described below over the personal information this policy covers. Remember that protected health information held by a HIPAA covered entity is generally exempt from these particular rights, but you hold parallel and in some respects stronger rights over it under HIPAA and California medical information law, and those are described in our Notice of Privacy Practices.
Right to know and to access
You may ask us to disclose the categories of personal information we collected about you, the categories of sources it came from, our business or commercial purpose for collecting, selling, or sharing it, the categories of third parties to whom we disclosed it, and the specific pieces of personal information we hold about you. You may request this information for the 12 months preceding your request, and you may request it for the period beyond 12 months unless doing so proves impossible or would involve disproportionate effort, in which case we will tell you why.
Right to delete
You may ask us to delete personal information we collected from you. We will do so, and direct our service providers to do the same, unless an exception applies. Exceptions include completing a transaction you asked for, detecting and resolving security incidents, complying with a legal obligation, and, importantly here, retaining records we are required by health care and dental practice law to keep.
Right to correct
You may ask us to correct inaccurate personal information we hold about you. Tell us what is wrong and what it should say, and provide any documentation that supports the correction. We will use commercially reasonable efforts to correct it, taking into account the nature of the information and the purpose of keeping it. Corrections to your dental record are handled as an amendment request under our Notice of Privacy Practices, which follows a separate HIPAA process.
Right to opt out of sale or sharing
You may direct us to stop selling or sharing your personal information at any time. As explained above, we do not sell or share personal information. You may still submit an opt-out request, either by enabling Global Privacy Control in your browser or by writing to our designated request channel, and we will honor it if our practices ever change. We will not ask you to reauthorize sharing for at least 12 months after you opt out.
Right to limit the use and disclosure of sensitive personal information
You may direct us to limit our use of any sensitive personal information to what is necessary to perform the services you asked for and to other uses California law permits without a right to limit. We do not request sensitive personal information through this website and we do not use it to infer characteristics about you, so in practice there is usually nothing to limit. Your right to make the request stands regardless, and we will honor it.
Right to non-discrimination
We will not discriminate against you for exercising any of these rights. We will not deny you dental care or any service, charge you a different price or rate, impose a penalty, provide you a different level or quality of care or service, or suggest that we might do any of those things, because you asked to know, delete, or correct your information, opted out of sharing, limited our use of sensitive information, or filed a complaint. We do not operate any financial incentive program tied to personal information.
Right to be free of retaliation
Separately from the above, we will never retaliate against you for filing a complaint about our privacy practices, whether you file it with us, with the California Attorney General, with the California Privacy Protection Agency, or with the U.S. Department of Health and Human Services Office for Civil Rights.
How to submit a privacy request
Our designated channel for every privacy request is email to office@jyounesidentistry.com. Please put the words "Privacy Request" in the subject line and tell us which right you are exercising. Using one channel keeps requests from being lost between the front desk and the inbox, and gives us a dated record of your request, which California law requires us to keep.
If you cannot use email, or need any accommodation to make a request, call the office at (949) 409-9895 during business hours and a team member will take your request down in writing on your behalf and log it in the same place. Calling is a fully equivalent route, not a lesser one. We will never require you to create an account in order to exercise a right.
How we verify who you are
Before we hand over or delete personal information, we have to be reasonably certain you are who you say you are, because giving your information to an impostor would itself be a privacy failure. We match the information in your request against information already in our records. For most requests we ask you to confirm two or three data points, such as the email address or phone number you used to contact us and the approximate date of that contact. For a request to disclose specific pieces of personal information, or for any request touching sensitive information, we apply a higher standard and may ask for additional verification or a signed declaration under penalty of perjury that you are the person you claim to be. We use information supplied for verification only for verification, and we delete it afterward unless we are required to retain it. If we cannot verify you, we will tell you so and explain why, and where possible we will treat a request to know as a request for category-level information only, which requires less verification.
Authorized agents
You may use an authorized agent to submit a request on your behalf. The agent should email our designated channel and include written permission signed by you authorizing that specific agent to act for you, or a valid power of attorney under the California Probate Code. Unless the agent holds a power of attorney, we may also contact you directly to confirm that you gave permission and to verify your identity ourselves. A business acting as an agent must be registered with the California Secretary of State if registration is required for its activity.
How quickly we respond
We confirm receipt of a request within 10 business days and tell you how we will handle it. We respond substantively within 45 calendar days. If we need more time, we may extend once by another 45 days, for a maximum of 90 days total, and we will tell you before the first 45 days run out and explain why. Responses are free. We may charge a reasonable fee or decline only if a request is manifestly unfounded or excessive, in which case we will explain that decision and tell you how to appeal it. Opt-out requests, including Global Privacy Control signals, take effect as soon as practicable and no later than 15 business days.
Third-party links
This website links to services we do not control, including our appointment portal at Dentrix Ascend, Google Maps, and our profiles on Google, Yelp, Facebook, and Instagram. Following one of those links takes you to an environment governed by that company's privacy policy, not ours. We are not responsible for their practices, and we encourage you to read their policies before providing information to them.
Changes to this policy
We review this policy at least once a year and update it whenever our practices change. When we make a material change, we will update the "Last updated" date at the top of this page and, where the change significantly affects your rights, provide a more prominent notice. Changes to our Notice of Privacy Practices are handled separately under HIPAA, which has its own notice requirements. Continuing to use the website after an update means the updated policy applies to your continued use, but it does not waive any right you already had.
Contact us
Questions, concerns, and complaints about privacy are welcome, and we would much rather hear them than not.
- Privacy requests and privacy questions, designated channel:office@jyounesidentistry.com
- By phone, including if you cannot use email:(949) 409-9895
- By mail: Jacqueline Younesi Dentistry, Attn: Privacy Officer, 2121 East Coast Hwy, Suite 230, Corona Del Mar, CA 92625
If you are not satisfied with our response, you may complain to the California Privacy Protection Agency or the California Attorney General about website privacy matters, or to the U.S. Department of Health and Human Services Office for Civil Rights about protected health information. We will not retaliate against you for filing any of those complaints.
If you need this policy in an alternative accessible format, call (949) 409-9895 and we will provide one. See also our Accessibility Statement.