Privacy Policy
LifeStrong PR Wellness Center Last Updated: September 2, 2026
Last updated: June 1, 2025Your privacy matters to us, especially when it comes to your Protected Health Information (PHI). Below, we walk through what we collect, why we collect it, who might see it, and the rights you have under HIPAA (the Health Insurance Portability and Accountability Act of 1996).
1. Information We Collect
Running a clinical practice means gathering a fair amount of information about the people we treat. Here's what that looks like in practice.
Personal Identifiers: Your name, date of birth, a government ID number, and how to reach you (phone, email, mailing address).
Protected Health Information: This is the heart of what we protect: your medical history, records from Shockwave or Pelvic Floor therapy sessions, any diagnostic images taken during your care, and the symptoms you've reported to us.
Insurance and Billing: Policy numbers, your claims history, and payment card details, which we never handle ourselves directly. All card payments run through a PCI-compliant processor.
Website and Portal Activity: Standard technical data like your IP address and browser type, plus how you interact with the LifeStrong Patient Portal.
2. How We Use Your Information
We don't collect data for its own sake. Everything ties back to one of three purposes.
First, treatment and coordination. If you're a candidate for Shockwave therapy or another service, your records help us make that call, and if you visit more than one of our locations, they help your care follow you.
Second, billing and scheduling. This covers verifying what your insurance will cover, running payments, and keeping our automated booking system accurate.
Third, quality assurance. Every so often we review de-identified data internally, just to confirm our FDA-cleared equipment is still delivering the results patients expect from us.
3. HIPAA Compliance
LifeStrong PR Wellness Center is what HIPAA calls a "covered entity." In plain terms, that means we're legally bound to protect your PHI and to tell you, clearly, how we handle it.
One principle guides day-to-day access internally: minimum necessary. Your physical therapist sees your treatment notes. Your billing coordinator sees your account. Neither one has a reason to see more than that, so they don't.
4. Who We Share Your Information With
We don't sell patient data. Full stop. That said, there are a few situations where sharing is unavoidable:
- Insurance providers, because claims can't get processed without them.
- Business associates, meaning HIPAA-compliant vendors like our EHR (Electronic Health Record) software company.
- Legal authorities, when federal law, Puerto Rico law, or a valid subpoena requires it.
5. How We Keep Your Data Secure
Your records live on encrypted servers using AES-256 encryption, and anyone logging into the Patient Portal needs to clear multi-factor authentication first.
If we ever suspect a breach, HIPAA's Breach Notification Rule kicks in. We'll notify you and the Department of Health and Human Services without unreasonable delay, and no later than 60 days after we discover it.
6. Your Rights as a Patient
You have real, enforceable rights over your own health information:
Right
What it lets you do
Inspect
View your records, or request a copy.
Amend
Ask us to fix something you believe is wrong.
Portability
Get an electronic copy to send to another provider.
Restriction
Ask us to limit how your info gets used for treatment or billing.
If you'd like to exercise any of these, just reach out to our office. Someone on our team will walk you through it.
We may update this policy from time to time as our practices or the law change. It's worth a re-read now and then.