Privacy Policy

PRIVACY POLICY

Effective Date: August 26, 2026
Last Updated: August 26, 2026

Sigla Health, operated by Mitchell Advanced Practice Nursing & Wellness Inc. (“Sigla Health,” “we,” “us,” or “our”), respects your privacy and is committed to protecting personal information entrusted to us.

This Privacy Policy explains how we may collect, use, disclose, retain, and protect information when you:

  • visit www.siglahealth.com;

  • contact Sigla Health;

  • submit a Website form;

  • request or schedule an appointment;

  • communicate with us electronically;

  • interact with our online services; or

  • otherwise provide information to us outside the context of a medical record.

Because Sigla Health is a healthcare provider, certain medical information may be subject to additional protections under federal and California healthcare privacy laws.

Please read this Privacy Policy carefully.

1. IMPORTANT DISTINCTION: WEBSITE PRIVACY POLICY AND MEDICAL PRIVACY NOTICE

This Privacy Policy describes Sigla Health's general Website and consumer privacy practices.

It does not replace Sigla Health's Notice of Privacy Practices (“NPP”), which describes how protected health information maintained in connection with healthcare may be used and disclosed and explains patients' rights concerning that information.

Protected health information may be governed by laws including, where applicable:

  • the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”);

  • the HIPAA Privacy, Security, and Breach Notification Rules;

  • the California Confidentiality of Medical Information Act (“CMIA”); and

  • other federal and state medical-privacy laws.

If a provision of this general Privacy Policy conflicts with a legal requirement applicable to protected medical information, the applicable healthcare privacy law and Sigla Health's Notice of Privacy Practices will control.

2. INFORMATION WE MAY COLLECT

The information Sigla Health collects depends on how you interact with us.

A. Identifiers and Contact Information

We may collect information such as:

  • name;

  • email address;

  • telephone number;

  • mailing address;

  • date of birth when appropriate;

  • account or patient identifiers where applicable; and

  • other information you voluntarily provide.

B. Appointment and Service Information

When you request information or schedule services, we may collect:

  • requested service;

  • preferred appointment date or time;

  • appointment status;

  • communication preferences;

  • provider selection when applicable; and

  • related scheduling information.

C. Health and Medical Information

If you provide health-related information through an authorized patient process, we may collect information concerning:

  • medical history;

  • symptoms;

  • medications;

  • allergies;

  • health conditions;

  • laboratory information;

  • treatment history;

  • demographic information;

  • photographs used for clinical purposes;

  • insurance information when applicable;

  • prescriptions;

  • treatment plans; and

  • other information needed to provide healthcare.

Health information used or maintained in connection with patient care is handled according to applicable medical-privacy requirements.

D. Payment and Transaction Information

When you pay for services or products, information associated with the transaction may include:

  • billing name;

  • billing address;

  • transaction amount;

  • payment status;

  • transaction identifier;

  • purchased service; and

  • limited payment-method information.

Payment-card information may be processed directly by third-party payment processors.

Sigla Health does not necessarily receive or store complete payment-card numbers, security codes, or other full payment credentials when those details are processed directly by a payment provider.

E. Financing Information

If you choose to apply for a third-party financing or installment-payment service, information required for that application may be collected directly by the financing provider.

The financing provider's collection and use of your information will be governed by its own privacy policy and contractual terms.

Sigla Health generally does not control the financing provider's underwriting, credit decision, or independent data practices.

F. Communications

We may collect information contained in:

  • emails;

  • Website inquiries;

  • telephone communications;

  • voicemail;

  • text messages;

  • appointment communications;

  • customer-service inquiries; and

  • other communications you voluntarily send to us.

G. Website and Device Information

When you access the Website, certain information may be collected automatically, including:

  • Internet Protocol (“IP”) address;

  • browser type;

  • device type;

  • operating system;

  • pages viewed;

  • referring pages;

  • general geographic region derived from an IP address;

  • access dates and times;

  • Website interactions;

  • cookie identifiers; and

  • similar technical information.

This information may be collected through the Website itself or by service providers that support Website hosting, security, analytics, functionality, or performance.

3. HOW WE COLLECT INFORMATION

We may collect personal information:

Directly From You

For example, when you:

  • submit a Website form;

  • contact us;

  • schedule an appointment;

  • register as a patient;

  • complete patient forms;

  • purchase a service;

  • communicate with our team;

  • participate in a promotion; or

  • otherwise voluntarily provide information.

Automatically

Certain technical information may be collected automatically when you interact with the Website through cookies, server logs, security technologies, and similar tools.

From Service Providers

We may receive information from organizations that assist us with:

  • scheduling;

  • electronic health records;

  • patient portals;

  • payment processing;

  • communications;

  • laboratory services;

  • pharmacy services;

  • Website hosting;

  • analytics;

  • security; or

  • other business functions.

From Healthcare or Business Partners

When permitted by law, we may receive information from laboratories, pharmacies, referring healthcare professionals, insurers, healthcare organizations, or other entities involved in your care or requested services.

4. HOW WE USE PERSONAL INFORMATION

Depending on the type of information and our relationship with you, we may use personal information to:

  • respond to inquiries;

  • schedule and manage appointments;

  • provide healthcare or requested services;

  • communicate with patients and prospective patients;

  • process transactions;

  • administer accounts;

  • maintain records;

  • coordinate laboratory, pharmacy, or other services;

  • provide patient support;

  • send appointment reminders;

  • provide requested information;

  • operate and improve our Website;

  • maintain Website security;

  • prevent fraud or misuse;

  • conduct internal business operations;

  • comply with legal and regulatory requirements;

  • protect patients, Sigla Health, or others;

  • establish, exercise, or defend legal rights;

  • evaluate Website performance;

  • maintain quality and operational standards; and

  • carry out other purposes disclosed when information is collected.

Health information will be used and disclosed as permitted or required under applicable medical-privacy laws and our Notice of Privacy Practices.

5. MARKETING COMMUNICATIONS

With appropriate permission or as otherwise permitted by law, Sigla Health may use contact information to communicate about:

  • Sigla Health services;

  • educational information;

  • events;

  • promotions;

  • new offerings; or

  • other practice-related information.

You may unsubscribe from promotional email communications through the unsubscribe link contained in the communication.

Where applicable, recipients may opt out of promotional SMS communications by replying STOP.

Opting out of marketing does not prevent us from sending non-promotional communications, such as appointment, patient-care, billing, safety, transactional, or administrative messages.

We do not use protected health information for marketing in a manner prohibited by applicable healthcare privacy law.

6. WHEN WE MAY DISCLOSE INFORMATION

Sigla Health does not sell patient medical information.

We may disclose information to the following categories of recipients when reasonably necessary and legally permitted.

A. Healthcare Service Providers

Information may be shared with healthcare professionals and organizations involved in treatment, including:

  • laboratories;

  • pharmacies;

  • imaging providers;

  • specialists;

  • referring providers; and

  • other healthcare entities.

B. Service Providers and Business Associates

We may use organizations that provide services such as:

  • Website hosting;

  • scheduling;

  • electronic health records;

  • secure patient portals;

  • payment processing;

  • communications;

  • data storage;

  • cybersecurity;

  • technical support;

  • document management;

  • analytics;

  • accounting; and

  • other operational support.

Where required by HIPAA, vendors receiving protected health information on our behalf are expected to enter into appropriate Business Associate Agreements and safeguard that information as required by law.

C. Payment and Financing Providers

Information reasonably necessary to complete a payment or a financing transaction may be provided to the applicable payment processor or financing provider.

D. Legal and Regulatory Purposes

We may disclose information when reasonably necessary to:

  • comply with applicable law;

  • comply with a court order, subpoena, or legal process;

  • respond to a lawful government request;

  • meet professional licensing or regulatory obligations;

  • investigate fraud;

  • protect patient safety;

  • protect our legal rights;

  • enforce agreements; or

  • address security threats.

Healthcare information will be disclosed only as permitted or required by applicable healthcare privacy law.

E. Business Transactions

If Sigla Health or its operating entity undergoes a merger, acquisition, restructuring, financing, sale of assets, or similar business transaction, information may be disclosed as part of that transaction subject to applicable confidentiality and healthcare privacy requirements.

7. WE DO NOT SELL MEDICAL INFORMATION

Sigla Health does not sell medical information to data brokers or advertisers.

We do not exchange protected health information for advertising revenue in a manner prohibited by applicable healthcare privacy laws.

If our practices concerning the sale or sharing of personal information materially change, this Privacy Policy will be updated and any legally required privacy choices will be provided.

8. COOKIES AND SIMILAR TECHNOLOGIES

Our Website may use cookies and similar technologies to support:

  • essential Website operation;

  • Website security;

  • user preferences;

  • fraud prevention;

  • Website performance; and

  • analytics.

Cookies are small data files stored on a device or browser.

Some Website functions may not operate correctly if certain cookies are disabled.

You can generally control cookies through your browser settings and, where made available, Website privacy controls.

9. WEBSITE ANALYTICS AND HEALTH INFORMATION

Healthcare websites require particular care when using tracking and analytics technologies.

Sigla Health endeavors to configure Website services and vendors so that protected health information is not impermissibly disclosed to analytics providers, advertising platforms, social media platforms, or other third parties.

We do not authorize third-party analytics or advertising providers to use protected health information for their independent advertising purposes in violation of applicable healthcare privacy laws.

Website technology may change over time, and we periodically may evaluate the technologies and vendors used on our Website.

10. DO NOT TRACK AND GLOBAL PRIVACY SIGNALS

Some internet browsers offer a “Do Not Track” (“DNT”) setting.

Because there is not a universally adopted technical standard governing all DNT signals, Website responses to traditional DNT signals may vary depending upon the technologies used.

Where applicable law requires recognition of a legally valid browser-based opt-out preference signal, such as a supported Global Privacy Control (“GPC”), Sigla Health will endeavor to honor the signal as required.

You may also manage cookies and similar technologies through browser settings and any privacy controls made available through our Website.

11. THIRD-PARTY TRACKING

Certain third-party technologies that support Website functionality may collect information when you interact with the Website.

Such parties may include Website-hosting, security, performance, mapping, embedded-content, or analytics providers.

Sigla Health does not authorize third parties to use protected medical information obtained through our Website for their independent advertising purposes in violation of applicable law.

12. THIRD-PARTY WEBSITES

Our Website may provide links to independent third-party websites and services.

Examples may include:

  • scheduling platforms;

  • patient portals;

  • financing services;

  • pharmacies;

  • laboratories;

  • payment services;

  • maps;

  • social media websites; and

  • other external resources.

Once you leave the Sigla Health Website, the third party's privacy practices may apply.

We encourage you to review the privacy policy of each service before providing personal information.

13. SQUARESPACE AND WEBSITE HOSTING

The Sigla Health Website may use third-party Website hosting and infrastructure services, including services provided through the Website platform on which Sigla Health operates.

Those providers may process technical information necessary to host, secure, deliver, or maintain the Website.

Their processing of information may be governed by applicable contractual terms and their own privacy practices.

14. ELECTRONIC HEALTH RECORDS AND PATIENT PORTALS

Sigla Health may utilize electronic health record systems, secure portals, telehealth technologies, scheduling platforms, and related healthcare technology services.

Information entered into or transmitted through those systems may be subject to both Sigla Health's privacy obligations and the applicable service provider's contractual safeguards.

Patients should use designated secure patient systems for sensitive medical communications whenever instructed.

15. TELEHEALTH PRIVACY

Telehealth involves electronic transmission of health information and may present privacy and security risks associated with internet connectivity, devices, software, and the patient's physical environment.

Sigla Health takes reasonable measures to use telehealth technology consistent with applicable healthcare privacy requirements.

Patients can also help protect their privacy by:

  • participating from a private location;

  • using secure internet connections where possible;

  • preventing unauthorized people from viewing or hearing the appointment;

  • safeguarding passwords and devices; and

  • avoiding unnecessary use of public Wi-Fi for sensitive healthcare communications.

16. EMAIL AND SMS PRIVACY

Ordinary email and SMS text messaging may not provide the same privacy protections as a secure healthcare portal.

Unless otherwise specifically directed, patients should avoid transmitting highly sensitive medical information through unsecured email, general Website contact forms, or ordinary text messaging.

Electronic communications can potentially be delayed, intercepted, misdirected, or accessed by someone with access to the recipient's device or account.

17. DATA SECURITY

Sigla Health takes reasonable administrative, physical, and technical measures designed to protect personal information against unauthorized:

  • access;

  • acquisition;

  • disclosure;

  • alteration;

  • destruction; and

  • misuse.

Depending upon the information and system involved, safeguards may include access controls, password protections, encryption, secure service providers, staff training, confidentiality obligations, and other security measures.

However, no internet transmission, information system, electronic storage method, or cybersecurity measure can be guaranteed to be completely secure.

Accordingly, we cannot promise absolute security.

18. DATA BREACHES

If Sigla Health discovers a breach involving protected or personal information, we will investigate and provide notifications to affected individuals, regulators, or others when required by applicable federal or state law.

19. DATA RETENTION

We retain information for the period reasonably necessary to:

  • provide services;

  • maintain appropriate business and medical records;

  • comply with legal, regulatory, tax, insurance, and professional obligations;

  • resolve disputes;

  • enforce agreements; and

  • protect legitimate business and patient interests.

Medical records may be subject to specific legal and professional retention requirements and therefore may not be eligible for deletion simply upon request.

Different categories of information may be retained for different periods.

20. CALIFORNIA PRIVACY RIGHTS

California residents may have privacy rights under one or more California laws depending on the nature of the information and whether a particular law applies to Sigla Health.

These rights can include, where applicable, the right to request:

  • information about personal information collected;

  • access to personal information;

  • correction of inaccurate personal information;

  • deletion of certain personal information;

  • information about disclosures;

  • limitation of certain uses of sensitive personal information;

  • opt-out from certain sales or sharing of personal information; and

  • freedom from unlawful discrimination for exercising privacy rights.

Not every privacy law or right applies to every organization or every category of information.

For example, certain medical information governed by healthcare privacy laws may be exempt from portions of general consumer privacy statutes and governed instead by HIPAA, CMIA, or other healthcare laws.

Sigla Health will evaluate privacy requests according to the law applicable to the information involved.

21. CCPA/CPRA APPLICABILITY

The California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), applies only to businesses meeting specified statutory criteria.

Sigla Health does not represent in this Privacy Policy that it necessarily meets every statutory threshold for CCPA applicability.

However, Sigla Health is committed to reasonable transparency and protection of personal information regardless of whether a particular CCPA provision currently applies to the practice.

If Sigla Health becomes subject to additional requirements because of growth, changes in business operations, changes in law, transaction volume, revenue, data practices, or other circumstances, we may update this Privacy Policy and implement additional legally required consumer-rights mechanisms.

22. MEDICAL RECORD RIGHTS

Patients may have rights under HIPAA, CMIA, and other applicable laws concerning their health information.

Depending upon applicable law, rights may include the right to:

  • inspect or obtain copies of medical records;

  • request correction or amendment of certain information;

  • request confidential communications;

  • request certain restrictions on uses or disclosures;

  • obtain information about certain disclosures;

  • receive a copy of Sigla Health's Notice of Privacy Practices;

  • authorize another individual to act on their behalf; and

  • file a privacy complaint.

Specific rights, limitations, procedures, and response periods are described in Sigla Health's Notice of Privacy Practices and applicable law.

23. REQUESTS TO ACCESS OR CORRECT INFORMATION

To request access to or correction of personal information maintained outside the ordinary patient portal or medical-record process, you may contact:

info@siglahealth.com

We may need to verify your identity before fulfilling certain requests.

Medical-record requests may be handled through a separate process appropriate to healthcare records.

We will not unlawfully discriminate or retaliate against an individual for exercising a privacy right.

24. DELETION REQUESTS

Individuals may request deletion of certain personal information where applicable law provides that right.

We may be unable or legally prohibited from deleting information when retention is necessary or permitted for reasons including:

  • medical-record obligations;

  • treatment;

  • patient safety;

  • legal compliance;

  • billing;

  • fraud prevention;

  • tax obligations;

  • professional licensing;

  • legal claims;

  • security;

  • recordkeeping; or

  • other legally permitted purposes.

A deletion request relating to medical information will be evaluated under applicable healthcare and record-retention laws.

25. PRIVACY OF CHILDREN

The public Website is not directed toward children under 13 for independent use.

We do not knowingly solicit personal information directly from children under 13 through the general Website in violation of applicable law.

Where Sigla Health provides healthcare services to minors, information concerning those services will be handled in accordance with applicable healthcare consent, parental-access, minor-consent, and confidentiality laws.

26. SOCIAL MEDIA

Information that you voluntarily post publicly on Sigla Health social media pages may become publicly visible.

Do not post private medical information in public comments.

Social media direct messages should not be considered a substitute for secure clinical communication or emergency services.

The social media platform independently processes information according to its own privacy policy.

27. PHOTOGRAPHS AND MARKETING

Sigla Health will not use identifiable patient photographs, protected health information, or patient information for marketing when authorization is legally required unless the appropriate authorization has been obtained.

Patients may decline marketing authorizations where permitted by law without affecting their ability to receive medically appropriate care.

28. INFORMATION ABOUT OTHER PEOPLE

If you submit information about another person, you represent that you are authorized to provide the information or otherwise have a lawful basis for doing so.

Do not use Website forms to submit another person's medical information unless you are legally authorized or instructed to do so.

29. BUSINESS TRANSFERS

If Sigla Health undergoes a corporate restructuring, merger, acquisition, ownership transition, sale, or similar transaction, information may be transferred as permitted by law.

Medical information will remain subject to applicable healthcare confidentiality and record-retention requirements.

30. CHANGES TO THIS PRIVACY POLICY

We may revise this Privacy Policy periodically to reflect:

  • changes in our services;

  • new technology;

  • new vendors;

  • regulatory developments;

  • changes in privacy law;

  • new Website features; or

  • changes in our information practices.

The current Privacy Policy will be posted on the Website with an updated “Last Updated” date.

We encourage users to review this Policy periodically.

31. CONTACT US REGARDING PRIVACY

Questions, concerns, or requests regarding this Privacy Policy may be directed to:

Sigla Health
Mitchell Advanced Practice Nursing & Wellness Inc.
2060 Otay Lakes Road, Suite 220
Chula Vista, California 91913

Email: info@siglahealth.com
Website: www.siglahealth.com

Patients with concerns specifically involving protected health information should also consult Sigla Health's Notice of Privacy Practices for information regarding privacy complaints and applicable patient rights.

© 2026 Sigla Health. All Rights Reserved.