PRIVACY POLICY & NOTICE OF PRIVACY PRACTICES


Effective Date: March 11, 2026 | Last Updated: March 16, 2026

This Privacy Policy and Notice of Privacy Practices describes how Optimize 360 LLC collects, uses, discloses, and protects information about you in connection with your use of our website at optimize360now.com and your receipt of our telehealth and clinical services. This policy also serves as our Notice of Privacy Practices as required by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations.


PLEASE READ THIS POLICY CAREFULLY. By using our website or services, you acknowledge that you have read and understood this Privacy Policy.


1. About Optimize 360 and This Policy

Optimize 360 LLC is a direct-pay telehealth hormone optimization practice licensed and operating exclusively in the State of Indiana. Our prescribing physician holds an active Indiana medical license. As a covered entity under HIPAA, we are required by law to maintain the privacy and security of your protected health information (PHI) and to provide you with this Notice of Privacy Practices.


This policy applies to:

  • All visitors to optimize360now.com
  • All current, former, and prospective patients of Optimize 360
  • All individuals who interact with our practice via phone, text, email, or digital platforms
  • All individuals whose PHI is created, received, maintained, or transmitted by Optimize 360


2. Information We Collect

2.1 Protected Health Information (PHI)

As a HIPAA-covered entity, we collect and maintain PHI in connection with providing healthcare services. PHI includes any individually identifiable health information, including but not limited to:

  • Name, date of birth, address, phone number, email address, and government-issued ID
  • Medical history, diagnoses, symptoms, and clinical assessments
  • Laboratory results, hormone panels, and diagnostic test results
  • Medications prescribed and treatment plans
  • Payment information related to healthcare services
  • Communications between you and our clinical team

2.2 Website and Non-PHI Information

When you visit our Website, we may collect non-personally identifiable information including:

  • Browser type, IP address, and device information
  • Pages visited, time spent on site, and referring URLs
  • Information submitted through contact forms or inquiry submissions
  • Cookie and analytics data as described in Section 8 of this policy


3. How We Use Your Information

3.1 Treatment, Payment, and Healthcare Operations (TPO)

Under HIPAA, Optimize 360 is permitted to use and disclose your PHI without your specific authorization for the following purposes:

  • Treatment: Providing, coordinating, and managing your healthcare and related services, including sharing information with your treating physician and compounding pharmacy
  • Payment: Processing payment for services, verifying eligibility, and managing billing and collections
  • Healthcare Operations: Quality assessment, staff training, compliance activities, and business management activities necessary to operate our practice

3.2 Other Permitted Uses and Disclosures

We may also use or disclose your PHI without authorization in circumstances permitted or required by law, including:

  • As required by federal, state, or local law or regulation
  • For public health activities as required by law
  • To report suspected abuse, neglect, or domestic violence to appropriate authorities
  • In response to a court order, subpoena, or other lawful legal process
  • For law enforcement purposes as permitted by law
  • To avert a serious and imminent threat to your health or safety or the health or safety of others
  • For workers’ compensation programs as permitted by law
  • To the Secretary of the U.S. Department of Health and Human Services for compliance investigations

3.3 Uses Requiring Your Authorization

We will obtain your written authorization before using or disclosing your PHI for any purpose not described in this policy, including marketing communications beyond permitted healthcare communications, sale of PHI, most uses of psychotherapy notes, and any other purpose not otherwise permitted by applicable law.


You may revoke your authorization at any time in writing. Revocation will not affect uses or disclosures made prior to our receipt of your written revocation.


4. HIPAA Compliance

Optimize 360 is a covered entity under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, including the Privacy Rule (45 CFR Parts 160 and 164) and the Security Rule. We comply with all applicable HIPAA requirements as described below.

4.1 Privacy Rule Compliance

  • Maintaining written privacy policies and procedures consistent with HIPAA requirements
  • Designating a Privacy Officer responsible for developing and implementing privacy policies
  • Training all workforce members on HIPAA privacy requirements
  • Implementing appropriate administrative, technical, and physical safeguards to protect PHI
  • Executing Business Associate Agreements (BAAs) with all vendors and service providers who access PHI on our behalf, including our GoHighLevel CRM platform (HIPAA-compliant instance), compounding pharmacy partners, and laboratory services (LabCorp and Quest Diagnostics)
  • Providing patients with this Notice of Privacy Practices at first service and upon request

4.2 Security Rule Compliance

  • Conducting periodic risk assessments to identify and address vulnerabilities to PHI
  • Implementing access controls limiting PHI access to authorized workforce members only
  • Using encrypted communications for transmission of electronic PHI
  • Maintaining audit logs for access to electronic PHI
  • Implementing procedures for reporting and responding to security incidents and breaches

4.3 Breach Notification

In the event of a breach of unsecured PHI, Optimize 360 will notify affected individuals, the U.S. Department of Health and Human Services, and, if applicable, prominent media outlets, in accordance with the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D). Notifications will be provided without unreasonable delay and no later than 60 days following discovery of the breach.


5. Indiana State Privacy Law Compliance

In addition to HIPAA, Optimize 360 complies with applicable Indiana state laws governing the privacy and confidentiality of health information, including:

  • Indiana Code Title 16, Article 39 (Health Records) — governing patient access to health records, record retention requirements (minimum 7 years per IND. CODE § 16-39-7-1), and confidentiality of health information
  • Indiana Code § 16-39-5-3 — governing disclosure of health records
  • Indiana telehealth laws and regulations applicable to our practice


Where Indiana state law provides greater privacy protections than HIPAA, Optimize 360 complies with the more stringent standard.


6. Your Rights Regarding Your Health Information

As a patient of Optimize 360, you have the following rights with respect to your PHI:

6.1 Right to Access

You have the right to inspect and obtain a copy of your medical records and other PHI maintained by Optimize 360. Requests must be submitted in writing. We will respond within 30 days. A reasonable fee may be charged for copies.

6.2 Right to Request Amendment

You have the right to request that we amend PHI you believe is incorrect or incomplete. We may deny your request under certain circumstances. If denied, you have the right to submit a statement of disagreement.

6.3 Right to an Accounting of Disclosures

You have the right to request a list of certain disclosures we have made of your PHI during the past six years, other than disclosures made for treatment, payment, healthcare operations, or pursuant to your authorization.

6.4 Right to Request Restrictions

You have the right to request that we restrict certain uses or disclosures of your PHI. We are required to comply with your request if the disclosure is to a health plan for payment or healthcare operations purposes and the PHI pertains solely to services for which you have paid in full out-of-pocket.

6.5 Right to Confidential Communications

You have the right to request that we communicate with you about your health information by alternative means or at alternative locations. We will accommodate reasonable requests.

6.6 Right to a Paper Copy of This Notice

You have the right to request a paper copy of this Privacy Policy at any time, even if you have agreed to receive it electronically. Contact us at the information provided in Section 14.

6.7 Right to File a Complaint

If you believe your privacy rights have been violated, you may file a complaint with Optimize 360 directly or with the U.S. Department of Health and Human Services Office for Civil Rights at www.hhs.gov/ocr. We will not retaliate against you for filing a complaint.


7. Third-Party Service Providers and Business Associates

Optimize 360 works with certain third-party service providers who may access, process, or store PHI on our behalf. We require all such vendors to execute a Business Associate Agreement (BAA) and comply with all applicable HIPAA requirements. Our current business associates include:

  • GoHighLevel (HighLevel, Inc.) — HIPAA-compliant CRM, patient communication, intake forms, and workflow automation platform
  • LabCorp and Quest Diagnostics — laboratory services for patient diagnostic testing
  • Licensed compounding pharmacy partners — dispensing and shipping of prescribed medications


We do not sell your PHI or personal information to any third party. We do not share your PHI with advertising networks, data brokers, or marketing platforms.


No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support of services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.


8. Website Data, Cookies, and Analytics

Our Website (optimize360now.com) may use standard web technologies including cookies and analytics tools to improve user experience and website functionality. Website analytics data such as page visits and traffic sources is not linked to your PHI and is used solely for non-clinical purposes such as understanding website performance.


We do not use third-party tracking technologies in ways that would constitute an impermissible disclosure of PHI. Our website does not capture PHI through standard analytics cookies.


You may disable cookies through your browser settings. Disabling cookies will not affect your ability to access clinical services.


9. SMS / Text Messaging Program

Optimize 360 uses SMS text messaging to communicate with patients regarding their care. This section describes how our SMS program works, how you opt in, and your rights regarding text communications.

9.1 Program Description

Our SMS program is used to send the following types of messages:

  • Appointment reminders and scheduling confirmations
  • Lab order notifications and results availability alerts
  • Prescription status updates and refill reminders
  • Treatment plan updates and clinical follow-up communications
  • Payment and billing notifications
  • General care coordination and administrative communications


Optimize 360 does not use SMS messaging to send unsolicited marketing or promotional content. All text messages are related to your care, your active patient relationship with our practice, or the administration of services you have requested.

9.2 How You Opt In

You may opt in to receive SMS messages from Optimize 360 in any of the following ways:

  • By providing your mobile phone number and checking the SMS consent checkbox on our patient intake form at optimize360now.com
  • By texting our practice number and initiating a conversation
  • By verbally or in writing consenting to text communications with our care team


By opting in, you consent to receive automated and manually sent text messages from Optimize 360 at the mobile number you provide. Message and data rates may apply. Consent to receive SMS messages is not a condition of receiving medical services from Optimize 360.

9.3 Message Frequency

Message frequency varies based on your treatment phase and care activity. Patients in active treatment typically receive between 2 and 8 messages per month. Message volume may be higher during onboarding, lab result periods, or when active care coordination is required. You will not receive messages unrelated to your care or patient relationship with Optimize 360.

9.4 Opt-Out Instructions

You may opt out of SMS communications from Optimize 360 at any time by replying STOP to any text message you receive from us. Upon receiving your STOP request, we will send a one-time confirmation message and you will be removed from further SMS communications. To opt back in, reply START or contact our office directly.

9.5 Help

For help with our SMS program, reply HELP to any message or contact us at:

  • Phone: (866) 678-4360
  • Text: 765-222-9990
  • Email: Contactus@optimize360now.com

9.6 Mobile Information and Privacy

Your mobile phone number and SMS opt-in status are treated as sensitive personal information. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Your opt-in data and consent information will not be shared with any third parties. Information may be shared with subcontractors who support the delivery of services, such as our SMS platform provider, solely for the purpose of facilitating your communications with Optimize 360.


10. Data Security

Optimize 360 implements administrative, technical, and physical safeguards to protect your information from unauthorized access, use, disclosure, alteration, or destruction, including:

  • Encrypted transmission of PHI via HIPAA-compliant platforms
  • Role-based access controls limiting PHI access to authorized personnel only
  • Secure, password-protected systems with multi-factor authentication where applicable
  • Business Associate Agreements with all vendors handling PHI
  • Staff training on HIPAA privacy and security requirements
  • Periodic security risk assessments


No data transmission over the internet or electronic storage can be guaranteed to be 100% secure. If you have reason to believe your interaction with us is no longer secure, please contact us immediately.


11. Geographic Scope

Optimize 360 provides telehealth services exclusively to patients physically located in the State of Indiana at the time of service. Our prescribing physician is licensed in Indiana only. This Privacy Policy applies to all website visitors, but clinical services are restricted to Indiana residents in accordance with our physician’s licensure and applicable telehealth laws.


12. Minors

Our clinical services are intended for adults 18 years of age and older. We do not knowingly collect PHI from individuals under the age of 18 without appropriate parental or guardian consent. If you are a parent or guardian and believe we have collected information from a minor without appropriate consent, please contact us immediately.


13. Changes to This Privacy Policy

Optimize 360 reserves the right to modify this Privacy Policy at any time. Material changes will be communicated by updating the Effective Date at the top of this policy. We are required by law to abide by the terms of the current version of this Notice and to notify you if we make a material change to our privacy practices. Your continued use of our services after any modification constitutes your acceptance of the updated policy.


14. Contact Us — Privacy Officer

For questions about this Privacy Policy, to exercise your privacy rights, or to report a privacy concern, please contact our Privacy Officer:


Optimize 360 LLC — Privacy Officer

4651 W Woods Edge Ln, Muncie, IN 47304

Phone: (866) 678-4360

Email: Contactus@optimize360now.com


You also have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights:

HHS Office for Civil Rights: www.hhs.gov/ocr | 1-800-368-1019

© 2026 All Rights Reserved | Optimize 360

Website Designed and Managed By: Designer 1 Media