HIPAA Compliant

PRIVACY POLICY

Effective Date: June 30, 2026 ·  Last Updated: June 30, 2026

AMG Wellness ("AMG Wellness," "we," "us," or "our"), located at 8111 Ashlane Way, Suite 100, The Woodlands, TX 77382, is committed to protecting the privacy and security of your personal information, including your Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and its implementing regulations, including the HIPAA Privacy Rule (45 C.F.R. Parts 160 and 164).

This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or communicate with us. Please read this policy carefully. If you do not agree with its terms, please discontinue use of our site and services.

1. Scope — HIPAA Notice of Privacy Practices

As a healthcare provider offering medically supervised wellness protocols, AMG Wellness is a Covered Entity under HIPAA. This Privacy Policy serves as our Notice of Privacy Practices ("NPP") as required by 45 C.F.R. § 164.520. We are required by law to:

  • Maintain the privacy of your PHI;
  • Provide you with notice of our legal duties and privacy practices;
  • Notify you following a breach of unsecured PHI; and
  • Abide by the terms of this Notice currently in effect.

2. Information We Collect

A. Protected Health Information (PHI)

PHI includes any individually identifiable health information we create, receive, maintain, or transmit in connection with your care, including but not limited to:

  • Name, date of birth, address, phone number, and email address;
  • Medical history, current health conditions, and treatment information;
  • Body composition data collected via InBody 380 analysis;
  • Prescription and medication information related to peptide therapy and GLP-1 protocols;
  • Payment and billing information used in connection with healthcare services;
  • Communications with our clinical staff, including Good Faith Exam records.

B. Non-PHI Website Data

  • IP address, browser type, device identifiers, and pages visited (via analytics tools, subject to your cookie consent);
  • Contact form submissions (name, email, phone, message);
  • Appointment booking information submitted through our scheduling system.

3. How We Use Your Information

We use your PHI for the following Treatment, Payment, and Healthcare Operations (TPO) purposes, which do not require your separate authorization under HIPAA:

  • Treatment: To provide, coordinate, and manage your wellness protocols, including body contouring, peptide/GLP-1 therapy, and InBody 380 body composition analysis;
  • Payment: To process payments, submit billing information, and manage your account;
  • Healthcare Operations: For quality assessment, staff training, compliance activities, and business management;
  • Appointment Scheduling: To confirm, remind, and manage your appointments;
  • Communications: To respond to your inquiries and send you information relevant to your care.

Uses beyond TPO require your written authorization, which you may revoke at any time (except where we have already acted in reliance on it).

4. Disclosures of Your Information

We may disclose your PHI without your authorization in the following circumstances permitted or required by HIPAA:

  • Compounding Pharmacies: We share necessary prescription and health information with licensed compounding pharmacies that fulfill your GLP-1 and peptide medication orders. These pharmacies are our Business Associates and are bound by Business Associate Agreements ("BAAs") requiring them to protect your PHI;
  • Business Associates: Third-party service providers (e.g., electronic health record systems, payment processors, telehealth platforms) who perform services on our behalf under BAAs;
  • As Required by Law: To comply with federal, state, or local laws, court orders, or government investigations;
  • Public Health Activities: To authorized public health authorities for disease reporting and prevention;
  • Health Oversight: To agencies conducting audits, investigations, or inspections;
  • Serious Threats: To prevent or lessen a serious and imminent threat to health or safety;
  • Workers' Compensation: As authorized by workers' compensation laws.

We will not sell your PHI. We will not use or disclose your PHI for marketing purposes without your written authorization.

5. Your HIPAA Rights

You have the following rights regarding your PHI, subject to limited exceptions:

  • Right to Access: Request a copy of your PHI in a designated record set (45 C.F.R. § 164.524);
  • Right to Amend: Request correction of inaccurate or incomplete PHI (45 C.F.R. § 164.526);
  • Right to an Accounting of Disclosures: Obtain a list of certain disclosures we have made of your PHI (45 C.F.R. § 164.528);
  • Right to Request Restrictions: Ask us to limit how we use or disclose your PHI for TPO purposes (45 C.F.R. § 164.522);
  • Right to Confidential Communications: Request that we communicate with you in a specific way or at a specific location;
  • Right to a Paper Copy of This Notice: Request a printed copy of this NPP at any time;
  • Right to Notification of Breach: Be notified if your unsecured PHI is breached.

To exercise any of these rights, contact our Privacy Officer at [email protected] or (346) 550-9228.

6. Data Security

We implement administrative, physical, and technical safeguards as required by the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C) to protect the confidentiality, integrity, and availability of electronic PHI ("ePHI"), including:

  • Encryption of ePHI in transit (TLS/SSL) and at rest;
  • Access controls limiting PHI access to authorized personnel only;
  • Audit logging of access to ePHI systems;
  • Regular risk assessments and workforce training;
  • Business Associate Agreements with all third-party vendors handling PHI.

No method of transmission over the Internet or electronic storage is 100% secure. While we use commercially reasonable means to protect your information, we cannot guarantee absolute security.

7. Telehealth and Good Faith Exam

Our Good Faith Exam process, conducted through our telehealth partner MyMedIntake, involves the collection and transmission of PHI necessary to establish a valid prescriber-patient relationship. All telehealth interactions are conducted over HIPAA-compliant, encrypted platforms. PHI collected during the Good Faith Exam is used solely for the purpose of evaluating your eligibility for peptide and GLP-1 therapy protocols.

8. Cookies and Website Analytics

Our website uses cookies and analytics tools (including Google Analytics 4) solely with your explicit consent, obtained through our cookie consent banner. Analytics data is non-PHI and is used to improve website performance and user experience. You may withdraw consent at any time by adjusting your cookie preferences. We do not link analytics data to your PHI.

9. Children's Privacy

Our services are intended for adults aged 18 and older. We do not knowingly collect PHI or personal information from individuals under the age of 18. If you believe we have inadvertently collected information from a minor, please contact us immediately and we will promptly delete it.

10. Texas State Privacy Laws

In addition to HIPAA, we comply with applicable Texas state privacy laws, including the Texas Medical Records Privacy Act (Tex. Health & Safety Code Ch. 181) ("TMRPA"), which provides additional protections for health information beyond federal HIPAA requirements. Under TMRPA, we will not disclose your PHI without your written authorization except as permitted by law.

11. Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy at any time. Material changes will be posted on this page with an updated effective date. We may also notify you by email if you have provided your contact information. Your continued use of our services after any modification constitutes your acceptance of the updated policy. We will maintain prior versions of this policy and make them available upon request.

12. Complaints

If you believe your privacy rights have been violated, you may file a complaint with us or with the U.S. Department of Health and Human Services Office for Civil Rights:

We will not retaliate against you for filing a complaint.

13. Contact Us

For questions about this Privacy Policy or to exercise your rights, contact:

AMG Wellness — Privacy Officer

8111 Ashlane Way, Suite 100

The Woodlands, TX 77382