Overview

This Cookie Policy explains how Nivano Physicians uses tracking technologies on our website in compliance with HIPAA Privacy and Security Rules, OCR guidance on tracking technologies (updated March 2024), GDPR, and the California Consumer Privacy Act (CCPA/CPRA). We are committed to protecting your privacy while providing you with the best possible online experience.

What Are Cookies and Tracking Technologies?

Types of Tracking Technologies We Use

Authentication Distinctions

We distinguish between two types of website interactions:

HIPAA Compliance and PHI Protection

When Tracking May Collect PHI

Under OCR guidance, tracking technologies may collect Protected Health Information (PHI) when:

Business Associate Agreements (BAAs)

We maintain Business Associate Agreements with tracking technology vendors who may have access to PHI:

Vendors with BAAs:

Non-BAA Vendors (Limited Data):

Encryption and Data Protection

All PHI transmitted through tracking technologies must be encrypted using industry-standard protocols:

GDPR and International Compliance

European Users

For users accessing our website from the European Union:

Essential Cookies

Performance Cookies

Functional Cookies

Marketing Cookies (Restricted)

CCPA/CPRA Compliance

California Consumer Rights

Under the California Consumer Privacy Act and California Privacy Rights Act:

Right to Know

Right to Delete

Right to Opt-Out

User Controls

You can manage tracking technologies through multiple methods:

Browser Settings

Mobile App Controls

Tracking Technology Inventory

First-Party Tracking

  1. Nivano Session Cookies
    • Purpose: User authentication and session management
    • Duration: Session-based (expires when browser closes)
    • PHI Risk: High (patient portal access)
    • BAA Required: N/A (internal processing)
  2. Preferences Cookies
    • Purpose: Remember user settings and language preferences
    • Duration: 12 months
    • PHI Risk: Low (general preferences only)
    • BAA Required: No

Third-Party Tracking

  1. Google Analytics 4
    • Purpose: Website performance and user behavior analysis
    • Duration: 26 months
    • PHI Risk: Medium (IP + health page visits)
    • BAA Status: Active BAA in place
  2. Microsoft Clarity
    • Purpose: Session replay and heatmap analysis
    • Duration: 12 months
    • PHI Risk: Medium (session recordings may capture PHI)
    • BAA Status: Active BAA in place
  3. Salesforce Health Cloud
    • Purpose: Patient relationship management
    • Duration: Per business requirements
    • PHI Risk: High (comprehensive PHI processing)
    • BAA Status: Healthcare-specific BAA active

Data Retention and Disposal

Retention Periods

Secure Disposal

Your Rights and Choices

Access Rights

Control Rights

Contact Information

For questions about our use of tracking technologies:

Privacy Officer

Data Protection Officer (for EU residents)

Updates to This Policy

This Cookie Policy may be updated periodically to reflect changes in:

Last Updated: August 7, 2025
Next Review Date: February 7, 2026
Policy Version: 1.0

We will notify you of significant changes through:


This Cookie Policy demonstrates our commitment to transparency in data collection while maintaining strict HIPAA compliance and protecting patient privacy.