Legal

Privacy Policy

Last Updated: August 1, 2026

1. Introduction

Tejas Health Care ("we," "our," or "us") is committed to protecting the privacy and security of your personal and medical information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website, tejashealthcare.org (the "Website"), use our patient portal, or interact with our services (collectively, the "Services").

As a healthcare provider, we are required by law to maintain the privacy of your Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and applicable Texas state privacy laws. This Privacy Policy is provided in addition to our Notice of Privacy Practices, which is available at our offices and on our Website.

By accessing or using our Website or Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, please do not use our Website or Services.

2. Information We Collect

We collect several categories of information to provide and improve our healthcare services. The types of information we collect depend on how you interact with us.

2.1 Personal Information You Provide Directly

We collect information you voluntarily provide when you:

  • Request an appointment through our Website
  • Register as a new patient
  • Create an account on our Patient Portal
  • Complete forms, surveys, or questionnaires
  • Contact us via email, phone, or our online form
  • Subscribe to newsletters or health updates

This information may include:

  • Full name, date of birth, and gender
  • Home address, phone numbers, and email address
  • Emergency contact information
  • Insurance information (provider, policy number, group ID)
  • Medical history, current medications, allergies
  • Social Security Number (for insurance verification and billing)
  • Family size and household income (for sliding fee scale eligibility)
  • Preferred language and communication preferences
  • Username and password for Patient Portal access

2.2 Protected Health Information (PHI)

In the course of providing medical, dental, and behavioral health services, we collect and maintain Protected Health Information as defined by HIPAA. This includes medical records, treatment notes, diagnostic results, prescriptions, referral information, and billing records. PHI is subject to additional protections beyond those described in this general Privacy Policy. For a complete description of your rights regarding PHI, please refer to our Notice of Privacy Practices.

2.3 Information Collected Automatically

When you visit our Website, we may automatically collect certain information about your device and browsing activity through cookies, web beacons, and similar technologies, including:

  • IP address and approximate geographic location
  • Browser type and version
  • Operating system and device type
  • Pages visited, time spent on pages, and referring/exit pages
  • Date and time of visit
  • Clickstream data and browsing patterns

This information is used for website analytics, improving user experience, and maintaining the security of our Website. It is generally non-identifying, but to the extent it is associated with personal information, we treat it in accordance with this Privacy Policy.

3. Cookies & Tracking Technologies

Our Website uses cookies and similar tracking technologies to enhance your browsing experience and collect analytical data. Cookies are small text files stored on your device by your web browser.

  • Essential Cookies: Necessary for the Website to function properly, including security features and basic navigation. These cannot be disabled.
  • Analytics Cookies: Help us understand how visitors interact with the Website by collecting and reporting information anonymously. We use Google Analytics and similar services.
  • Functional Cookies: Allow the Website to remember choices you make (such as your language preference) to provide a more personalized experience.

You can control cookie preferences through your browser settings. Most browsers allow you to refuse or delete cookies. However, disabling cookies may affect the functionality of certain parts of our Website. We do not respond to "Do Not Track" signals at this time, as there is no universally accepted standard for how to interpret such signals.

4. How We Use Your Information

We use the information we collect for the following purposes:

  • Treatment & Healthcare Operations: To provide medical, dental, and behavioral health services; coordinate care with specialists and referral partners; maintain your medical records; and conduct quality improvement activities.
  • Payment & Billing: To verify insurance eligibility, submit claims, process payments, determine sliding fee scale eligibility, and manage billing inquiries — as permitted by HIPAA.
  • Appointment Management: To schedule, confirm, and remind you of appointments via your preferred communication method.
  • Patient Portal: To provide secure access to your medical records, test results, and communication with your healthcare providers.
  • Communications: To respond to your inquiries, send administrative information, and provide health-related information and updates you have requested.
  • Website Improvement: To analyze usage patterns, improve Website functionality, and enhance user experience.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, and governmental requests, and to protect the rights and safety of Tejas Health Care, our patients, and the public.
  • Marketing & Fundraising: With your consent, to send information about new services, health events, and fundraising initiatives. You may opt out of marketing communications at any time.

We will not use your Protected Health Information for purposes not permitted by HIPAA without your written authorization, except as required or permitted by law.

5. How We Share & Disclose Your Information

We may share your information in the following circumstances:

5.1 Treatment, Payment, and Healthcare Operations (TPO)

Under HIPAA, we may use and disclose your PHI for treatment, payment, and healthcare operations without your specific authorization:

  • Treatment: Sharing your medical information with specialists, laboratories, pharmacies, and other healthcare providers involved in your care.
  • Payment: Disclosing necessary information to insurance companies, billing services, and collection agencies to obtain payment for services.
  • Healthcare Operations: Using information for quality assessment, staff training, compliance audits, and business planning.

5.2 Service Providers & Business Associates

We may share information with third-party service providers and business associates who perform services on our behalf, including but not limited to electronic health records vendors, billing and collections services, IT support and cloud hosting providers, and secure messaging platforms. These entities are contractually bound to protect your information and comply with HIPAA requirements as business associates.

5.3 Legal Obligations & Public Health

  • As required by federal, state, or local law
  • In response to a valid court order, subpoena, or legal process
  • For public health activities and disease reporting
  • To report suspected abuse, neglect, or domestic violence
  • For health oversight activities such as audits and investigations
  • To avert a serious threat to health or safety

5.4 With Your Authorization

Uses and disclosures of your PHI for purposes other than TPO, as required by law, or as described in our Notice of Privacy Practices will be made only with your written authorization. You may revoke your authorization at any time in writing, except to the extent that we have already acted in reliance on it.

5.5 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of all or a portion of our assets, your information may be transferred as part of the transaction, subject to applicable privacy laws and your right to receive notice of such transfer.

5.6 Data Not Sold

Consumer information is not shared with third parties for marketing purposes. We do not sell, rent, or lease your personal information or Protected Health Information to third parties for their marketing or promotional use.

6. Your HIPAA Rights Regarding Protected Health Information

Under HIPAA, you have the following rights regarding your Protected Health Information. To exercise any of these rights, please submit a written request to our Privacy Officer at the address listed in Section 11.

  • Right to Access: You have the right to inspect and obtain a copy of your PHI in our designated record set, including medical and billing records. We will provide copies within 30 days of your request (with one 30-day extension available). A reasonable, cost-based fee may apply.
  • Right to Amend: If you believe your PHI is incorrect or incomplete, you may request an amendment. We will respond within 60 days. We may deny your request if we determine the information is accurate and complete.
  • Right to an Accounting of Disclosures: You may request a list of certain disclosures we have made of your PHI within the six years prior to your request. The first accounting in any 12-month period is free; additional requests may incur a reasonable fee.
  • Right to Request Restrictions: You may request restrictions on how we use and disclose your PHI for treatment, payment, and healthcare operations. We are not required to agree to all restrictions, but if we agree, we will comply except in emergency situations.
  • Right to Request Confidential Communications: You may request that we communicate with you about your PHI by alternative means or at alternative locations (e.g., only at your work phone number or by mail to a P.O. box).
  • Right to a Paper Copy of This Notice: You may request a paper copy of our Notice of Privacy Practices at any time, even if you have agreed to receive it electronically.
  • Right to File a Complaint: If you believe your privacy rights have been violated, you may file a complaint with our Privacy Officer or with the U.S. Department of Health and Human Services Office for Civil Rights. We will not retaliate against you for filing a complaint.
  • Right to Receive Breach Notification: In the event of a breach of your unsecured PHI, we will notify you as required by HIPAA and the HITECH Act.

7. Data Security & Retention

We implement administrative, technical, and physical safeguards designed to protect your personal information and PHI from unauthorized access, use, alteration, and disclosure. These measures include, but are not limited to:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure, access-controlled electronic health records systems
  • Multi-factor authentication for Patient Portal access
  • Regular security risk assessments and vulnerability testing
  • Workforce training on privacy and security policies
  • Physical security controls at our facilities
  • Business Associate Agreements with all service providers handling PHI
  • Audit logging and monitoring of access to electronic PHI
  • Incident response and breach notification procedures

While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security. In the event of a data breach involving your personal information, we will notify you in accordance with applicable law.

We retain your personal information and PHI for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations (including HIPAA and Texas Medical Board retention requirements), resolve disputes, and enforce our agreements. Medical records for adults are typically retained for a minimum of seven (7) years from the date of last service; records of minors are retained until the patient reaches age 21, or longer as required by law.

8. Children's Privacy

Our Website is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 through our Website without verifiable parental consent. If we become aware that a child under 13 has provided us with personal information without parental consent, we will take steps to delete such information promptly.

For medical treatment of minors, we collect information in accordance with Texas law regarding parental consent and minor consent for certain services. Parents and legal guardians have rights to access their minor child's medical records, subject to exceptions provided by law for certain types of care.

9. Third-Party Links & Services

Our Website may contain links to third-party websites, services, or resources, including health information portals, government agency websites, and community resources. We are not responsible for the privacy practices, content, or security of any third-party websites. We encourage you to review the privacy policies of any third-party websites before providing personal information. This Privacy Policy applies solely to information collected by Tejas Health Care through our Website and Services.

10. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time. When we make changes, we will revise the "Last Updated" date at the top of this page and post the updated policy on our Website. For material changes, we will provide a more prominent notice (such as a notification on our homepage or through our Patient Portal). Your continued use of our Website or Services after any changes constitutes your acceptance of the revised Privacy Policy. We encourage you to review this Privacy Policy periodically.

11. Contact Information & Complaints

If you have questions, concerns, or complaints about this Privacy Policy, our data practices, or wish to exercise any of your privacy rights, please contact our Privacy Officer:

Privacy Officer

Tejas Health Care

753 East Travis

La Grange, TX 78945

Phone: (877) 768-1101

Email: support@tejashealth.org

You also have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights by visiting www.hhs.gov/ocr/complaints or by calling 1-800-368-1019. We will not retaliate against you for filing a complaint.

12. Texas Privacy Rights & State Law Compliance

In addition to HIPAA, we comply with the Texas Medical Records Privacy Act (Texas Health & Safety Code Chapter 181) and the Texas Identity Theft Enforcement and Protection Act. Texas residents have additional rights under state law regarding the privacy and security of their medical and personal information. To the extent state law provides greater protections than federal law, we will comply with the more protective standard.

Residents of certain states (including California, Colorado, Connecticut, Virginia, and Utah) may have additional rights under applicable state comprehensive privacy laws, including the right to access, delete, and obtain a portable copy of personal information, as well as the right to opt out of certain processing activities. To exercise any of these rights, please contact our Privacy Officer. We will not discriminate against you for exercising your privacy rights.