PRIVACY POLICY & NOTICE OF PRIVACY PRACTICES

Carolina Regional Orthopaedics, PA

Orthopedic Surgery • Pain Management • Sports Medicine • Joint Replacement • Regenerative Medicine

Effective Date: August 1, 2026 | Last Updated: August 1, 2026

Carolina Regional Orthopaedics, PA (“we,” “us,” “our,” or the “Practice”) operates the website at https://www.crortho.com/ and provides healthcare services at the location(s) listed above. We are committed to protecting the privacy of all website visitors and the confidentiality of protected health information (PHI) of our patients in accordance with the Health Insurance Portability and Accountability Act (HIPAA), applicable state laws, and California privacy laws where they apply to California residents.

This document serves as both our general Website Privacy Statement and our HIPAA Notice of Privacy Practices. It applies to information collected through our website as well as PHI created, received, maintained, or transmitted in the course of providing healthcare services. By using our website or receiving services from us, you acknowledge that you have read and understand this policy.

1. Website Privacy Statement

Scope. This Website Privacy Statement governs the collection, use, disclosure, and protection of information collected from visitors to our website. It does not apply to information collected offline or through other channels, except as noted for patient information which is also governed by the HIPAA section below. Your use of the website constitutes acceptance of these practices.

1.1 Information We Collect We may collect the following categories of information:

  • Personally Identifiable Information (PII): Information you voluntarily provide through contact forms, appointment request forms, patient portals, or other submissions, such as your full name, email address, phone number, mailing address, date of birth, insurance information, and details about your medical concerns or reason for inquiry.
  • Demographic and Preference Data: Anonymous or aggregated information such as ZIP code, age range, gender, areas of interest, and how you heard about us.
  • Technical and Usage Data: Automatically collected information including your IP address, browser type and version, operating system, device type, referring/exit pages, date/time of visits, pages viewed, time spent on site, and clickstream data. We may also collect location data if permitted by your device/browser settings.
  • Health-Related Information: Any health symptoms, medical history, or treatment preferences you voluntarily disclose via website forms. Note: Once you become a patient or this information is used in connection with care, it becomes Protected Health Information (PHI) subject to the HIPAA Notice below.
  • Communications Data: Records of your communications with us via email, phone, text, or website forms, including appointment requests, feedback, or complaints.

We do not knowingly collect personal information from children under 13 years of age. If you believe we have collected such information, please contact us immediately so we can delete it in accordance with the Children’s Online Privacy Protection Act (COPPA).

1.2 How We Use Your Information We use the information we collect for the following purposes:

  • To operate, maintain, and improve our website, services, and user experience;
  • To respond to your inquiries, schedule appointments, provide information about our services, and follow up on requests;
  • To process and manage patient intake, insurance verification, and related documentation;
  • To send appointment reminders, treatment information, or health-related communications (you may opt out of non-essential communications);
  • To analyze website traffic and usage patterns using analytics tools to improve our content and offerings;
  • To detect, prevent, and address technical issues, security incidents, fraud, or abuse;
  • To comply with legal obligations, enforce our Terms of Service, and protect the rights, property, or safety of our patients, staff, and the public;
  • For other purposes with your consent or as otherwise permitted or required by law.

1.3 Cookies, Tracking Technologies, and Analytics

We and our third-party service providers use cookies, web beacons, pixels, local storage, and similar tracking technologies to enhance your browsing experience, remember preferences, analyze site performance, and deliver relevant content. Specifically:

  • Essential cookies for site functionality (e.g., form submissions, session management);
  • Analytics cookies (e.g., Google Analytics) to understand visitor behavior, traffic sources, and popular content. We do not share identifiable information with Google for advertising purposes without consent;
  • Preference and functionality cookies to remember form data or customize content;
  • We do not use third-party advertising cookies or engage in cross-site tracking for behavioral advertising at this time.

You can manage or disable cookies through your browser settings. Note that disabling certain cookies may affect website functionality, such as the ability to submit forms.

Do Not Track (DNT) Disclosure (CalOPPA): Our website does not respond to Do Not Track (DNT) signals sent by browsers at this time. We continue to collect information as described in this policy regardless of DNT settings. We will update this disclosure if our practices change.

1.4 Information Sharing and Disclosure

We do not sell, rent, lease, or trade your personal information for monetary or other valuable consideration. We may share information in the following limited circumstances:

  • Service Providers and Business Partners: With trusted third parties who perform services on our behalf (e.g., website hosting, form processing, email delivery, analytics providers, IT support, scheduling or patient portal vendors). These parties are contractually obligated to use the information only for the purposes we specify and to maintain appropriate confidentiality and security.
  • Legal and Safety Requirements: When required by law, court order, subpoena, or governmental regulation; to enforce our Terms; to protect the rights, property, or safety of the Practice, our patients, employees, or the public; or in connection with a legal investigation.
  • Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of the transaction, subject to the privacy policy of the acquiring entity.
  • With Your Consent: For any other purpose with your explicit consent.
  • Aggregated/Anonymized Data: We may share aggregated, de-identified, or anonymized data that cannot reasonably be used to identify you.

Third-Party Links: Our website may contain links to external sites. We are not responsible for the privacy practices, content, or security of those third-party sites. We encourage you to review their privacy policies.

1.5 Data Security

We implement reasonable and appropriate administrative, technical, and physical safeguards to protect your information from unauthorized access, use, disclosure, alteration, or destruction. These include:

  • Encryption of data in transit using industry-standard SSL/TLS protocols;
  • Secure hosting environments with firewalls, intrusion detection, and regular security updates;
  • Access controls limiting PHI and sensitive data to authorized personnel on a need-to-know basis;
  • Staff training on privacy and security policies;
  • Regular risk assessments and monitoring;
  • Secure disposal or destruction of records when no longer needed, in accordance with retention requirements.

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify affected individuals and relevant authorities as required by applicable law (including HIPAA breach notification rules and applicable state statutes).

1.6 Data Retention

We retain personal information only as long as necessary to fulfill the purposes for which it was collected, to comply with our legal and regulatory obligations (including medical record retention requirements under applicable state law), to resolve disputes, and to enforce our agreements. Website analytics data is typically retained in aggregated form for a limited period. When information is no longer needed, we securely delete or anonymize it.

1.7 Your California Privacy Rights (CCPA/CPRA & CalOPPA)

If you are a resident of California, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) and the California Online Privacy Protection Act (CalOPPA). These rights apply to personal information we collect through our website or in the course of providing services, subject to certain exceptions (particularly for information that constitutes PHI protected under HIPAA, which is generally exempt from CCPA but still subject to strong HIPAA protections).

We do not “sell” personal information as that term is defined under CCPA, nor do we engage in cross-context behavioral advertising that would trigger a right to opt-out of “sharing.” We also do not use or disclose sensitive personal information (such as health-related data) for purposes other than those permitted under applicable law or with your consent.

Your Rights Include:

  • Right to Know
  • Right to Delete
  • Right to Correct
  • Right to Opt-Out of Sale or Sharing
  • Right to Limit Use and Disclosure of Sensitive Personal Information
  • Right to Non-Discrimination

How to Exercise Your Rights: To submit a verifiable consumer request, please contact our Privacy Officer by phone at (252) 443-0400. Please provide sufficient information to allow us to reasonably verify your identity. We will respond to verifiable requests within 45 days of receipt (we may extend by an additional 45 days with notice).

Note on Healthcare Records: Many of your rights regarding medical records and PHI are governed by HIPAA (see Section 2 below). CCPA rights apply primarily to non-PHI personal information collected via the website or other non-treatment contexts. Where both apply, we will honor your rights to the fullest extent permitted by law.

1.8 Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, legal requirements, or for other operational reasons. When we make material changes, we will update the “Last Updated” date at the top of this document, post the revised policy on our website, and make it available at our clinic location(s). Your continued use of the website after any such changes constitutes your acceptance of the revised policy. We encourage you to review this policy periodically.

2. HIPAA Notice of Privacy Practices

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Carolina Regional Orthopaedics, PA (“Practice,” “we,” “us,” or “our”) is a covered entity under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations (the “Privacy Rule” and “Security Rule”). We are required by law to maintain the privacy of your protected health information (PHI) — individually identifiable health information that relates to your past, present, or future physical or mental health or condition, the provision of healthcare to you, or the past, present, or future payment for the provision of healthcare to you — and to provide you with this Notice of our legal duties and privacy practices with respect to your PHI.

This Notice applies to all PHI created, received, maintained, or transmitted by the Practice, whether in electronic, paper, or oral form. It describes how we may use and disclose your PHI, your rights regarding your PHI, and our obligations concerning your PHI.

2.1 How We May Use and Disclose Your Protected Health Information

We may use or disclose your PHI for purposes of treatment, payment, and healthcare operations without your written authorization, as permitted by HIPAA. We may also use or disclose your PHI for other purposes with your written authorization or as otherwise permitted or required by law.

Treatment

Examples include evaluating your condition, providing medical treatment and procedures, prescribing medications, coordinating care with other providers, discussing care with designated family members, sending appointment reminders, and providing information about treatment alternatives.

Payment

Examples include verifying insurance coverage, submitting claims, collecting payments, appealing denials, and related billing activities.

Healthcare Operations

Examples include quality assessment, care coordination, staff training, licensing and accreditation, compliance activities, business planning, and patient satisfaction surveys.

Other Permitted or Required Uses and Disclosures (Without Authorization)

These include disclosures required by law, public health activities, health oversight, judicial proceedings, law enforcement, serious threats to health or safety, workers’ compensation, and disclosures to business associates under HIPAA-compliant agreements.

Uses and Disclosures Requiring Your Written Authorization

Most other uses and disclosures (including marketing and sale of PHI) require your written authorization, which you may revoke in writing at any time (except to the extent already relied upon).

2.2 Your Rights Regarding Your Protected Health Information

You have the right to:

  • Inspect and obtain a copy of your PHI
  • Request amendment of your PHI
  • Receive an accounting of certain disclosures
  • Request restrictions on uses and disclosures
  • Request confidential communications
  • Receive a paper copy of this Notice
  • File a complaint without retaliation

2.3 Our Legal Duties and Responsibilities

We are required by HIPAA to maintain the privacy of your PHI, provide this Notice, abide by its terms, notify you of breaches of unsecured PHI, train our workforce, implement appropriate safeguards, and enter into Business Associate Agreements where required.

2.4 Contact Information and How to Exercise Your Rights

Privacy Officer

Carolina Regional Orthopaedics, PA

Phone: (252) 443-0400

Website: https://www.crortho.com/

Mailing Address for Privacy Requests: Carolina Regional Orthopaedics, PA Attn: Privacy Officer 110 Patrick Ct Rocky Mount, NC 27804

We will make every effort to respond to your inquiries and requests promptly and in accordance with applicable legal timeframes.

Contact Us

To contact us, please click here.