Privacy & HIPAA Policy

Effective date: January 1, 2026  ·  Last updated: May 2026

1. Who We Are

SmileBridge Dental ("SmileBridge," "we," "us") is a licensed dental practice providing family dentistry and orthodontic care. This Privacy Policy describes how we collect, use, and protect information submitted through this website. This site operates as part of the Ascend Web Platform drill program for development and demonstration purposes.

2. Two Data Environments

SmileBridge operates two distinct data environments:

These environments are technically separate. PHI should never be submitted through this website's appointment request form.

3. What This Website Collects

Appointment Request Submissions

When you submit an appointment request, we collect: your name, date of birth (if provided), phone number, email address, insurance plan name (not member ID), patient type, visit type, urgency level, preferred appointment time, primary reason for visit, and the brief description you provide.

What This Website Does NOT Collect

This form is not designed to receive and should not be used to transmit: health diagnoses, medications, allergies, dental X-ray findings, insurance member IDs, clinical history, or any other PHI as defined under HIPAA.

Automatically Collected Data

We collect standard server logs and page-level analytics events (page views, form submission attempts). We do not use third-party tracking pixels, behavioral advertising, or fingerprinting.

4. Governed Intake & Legal Screening

All appointment request submissions are screened for content outside the scope of scheduling services — including requests for clinical diagnoses, medical treatment, prescription information, and insurance claim disputes. Submissions containing such content are flagged and routed to appropriate clinical or administrative staff. This is a safety control, not a clinical determination.

5. How We Use Scheduling Information

Scheduling decisions are made by human staff — not automated systems. Appointment requests are not clinical consultations.

6. HIPAA Compliance

SmileBridge Dental is a HIPAA-covered entity. All clinical records, health history, and PHI are handled in our HIPAA-compliant patient portal under our Notice of Privacy Practices (NPP). Staff receive annual HIPAA training. Our NPP is provided at your first visit and available upon request.

If you believe your HIPAA rights have been violated, you may file a complaint with the U.S. Department of Health and Human Services at hhs.gov/hipaa.

7. Insurance Information Handling

This website collects only the name of your dental insurance plan for scheduling context. Insurance member IDs, group numbers, and benefit details are collected by our billing team directly — not through this web form. Insurance coverage is determined by your plan. We provide benefit estimates before treatment, but coverage amounts are not guaranteed by our practice.

8. No Clinical Guarantees

This website does not provide diagnoses, treatment recommendations, or coverage guarantees. Treatment outcomes vary by individual. All clinical decisions are made by a licensed dentist following an examination. Marketing descriptions of procedures are reviewed by our clinical director and do not constitute promises of outcome.

9. Data Retention

Appointment request submissions are retained under a short retention / human review label for scheduling coordination. Once a patient relationship is established, records are governed by applicable dental practice record-keeping requirements (typically 7–10 years depending on state law). Pediatric records have extended retention requirements.

10. Data Sharing

We do not sell your information. We may share scheduling data with: (a) our scheduling and billing staff; (b) the Ascend Nexus platform for intake routing and audit logging; (c) clinical staff after appointment confirmation for scheduling context only; (d) regulators when required by law. Clinical records are shared per our HIPAA NPP.

11. Your Rights

You may request access to, correction of, or deletion of your scheduling data by contacting us. Rights regarding PHI in our clinical system are governed by our HIPAA NPP. California residents have additional rights under CCPA.

12. Security

This site is served over HTTPS with Cloudflare security headers. Submissions are transmitted over TLS. Sensitive content patterns (clinical diagnoses, PHI) are screened at intake before human review.

13. Emergency Information

This website is not a medical emergency channel. For dental emergencies, contact our office by phone. For life-threatening emergencies, call 911.

14. Changes to This Policy

We may update this policy periodically. Material changes will be noted with an updated effective date.

15. Contact

Privacy questions may be directed to our office via the Appointment Request page. For HIPAA-specific concerns, contact our Privacy Officer. This is a demonstration property of the Ascend Web Platform, Drill 015.