Privacy Policy
Notice of Privacy Practices
Effective Date: January 1, 2024
Last Updated: December 14, 2024
HIPAA Notice of Privacy Practices
This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully.
Dr. Viraj V. Tirmal, MD is committed to protecting the privacy of your health information. We are required by law to maintain the privacy of your protected health information (PHI), provide you with this Notice of our legal duties and privacy practices, and follow the terms of the Notice currently in effect.
How We May Use and Disclose Your Health Information
Treatment
We may use your health information to provide you with medical treatment or services. We may disclose your health information to doctors, nurses, technicians, or other personnel involved in your care.
Payment
We may use and disclose your health information to obtain payment for services we provide to you. This includes billing and collections activities and related data processing.
Healthcare Operations
We may use and disclose your health information for our healthcare operations, including quality assessment, employee review, training, accreditation, and licensing activities.
Appointment Reminders
We may contact you to remind you of appointments, provide information about treatment alternatives, or other health-related benefits and services.
As Required by Law
We will disclose your health information when required to do so by federal, state, or local law.
Your Rights Regarding Your Health Information
- Right to Inspect and Copy: You have the right to inspect and obtain a copy of your health information.
- Right to Amend: You may ask us to amend your health information if you believe it is incorrect or incomplete.
- Right to an Accounting of Disclosures: You have the right to request a list of disclosures we have made of your health information.
- Right to Request Restrictions: You have the right to request a restriction on certain uses and disclosures of your health information.
- Right to Request Confidential Communications: You have the right to request that we communicate with you about medical matters in a certain way or at a certain location.
- Right to a Paper Copy of This Notice: You have the right to obtain a paper copy of this Notice upon request.
Website Privacy Policy
Information We Collect
When you visit our website, we may collect certain information automatically, including your IP address, browser type, operating system, referring URLs, and information about how you interact with our website.
Contact Forms
When you submit a contact form on our website, we collect the information you provide, such as your name, email address, phone number, and message content. This information is used solely to respond to your inquiry.
Cookies
Our website may use cookies to enhance your browsing experience. You can set your browser to refuse cookies, but some features of our website may not function properly without them.
Website Analytics
We use a self-hosted analytics platform (Umami) running on our own infrastructure to understand how visitors use our website. Umami collects aggregated, anonymized information such as page views, referrer, browser type, screen size, and approximate country (derived from your IP). We do not store your IP address, do not use cookies for tracking, and do not share this data with third parties or advertising networks. Visitor data is retained for one year and is used solely to improve the website experience.
Chatbot Conversations
If you use the virtual assistant chat widget on our website, the messages you send and the assistant's replies are logged to our own infrastructure so we can improve answer quality and identify gaps in the information we provide. These logs are anonymous: they are not associated with your identity, name, or contact information, and they are retained for 90 days before automatic deletion. Please do not enter protected health information (PHI), medical history, or personal identifiers in the chat. For medical questions specific to your care, contact our office directly.
Form Submission Records
When a contact, MDVIP inquiry, or Meet & Greet form is submitted, the content of the submission (your name, email, phone, and message) is sent to our practice email and is not stored in our website analytics database. Only minimal metadata about the submission (which form, when, and whether it was filtered as spam) is retained for one year for traffic-quality reporting.
Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or electronic storage is 100% secure.
Changes to This Notice
We reserve the right to change this Notice and make the new provisions effective for all health information we maintain. If we make a significant change, we will post the revised Notice on our website and in our office.
Contact Us
If you have any questions about this Notice or wish to exercise your rights, please contact us:
Dr. Viraj V. Tirmal, MD15001 Shady Grove Road, Suite 100
Rockville, MD 20850
Phone: (301) 637-9495
Fax: (301) 637-9496
Filing a Complaint
If you believe your privacy rights have been violated, you may file a complaint with our office or with the Secretary of the U.S. Department of Health and Human Services. You will not be penalized for filing a complaint.
