Website & Patient Portal Privacy Policy
Effective July 23, 2026 · Last updated August 18, 2026
Operator: Nora Bassam Khoury, MD, PLLC, a Florida professional limited liability company doing business as Nomad Health ("Nomad Health," "we," "us," "our")
Covers: https://mynomadhealth.com and all pages and applications served from that domain, including the public marketing site, the enrollment/welcome pages, the patient portal (/patient-portal), and the staff EHR interface (/ehr) (collectively, the "Services").
Software provider: The Services run on the SanaLogs Chart Pro platform, developed and operated for Nomad Health by Brickell Bay Group LLC as a service provider.
Version: 1.3
Contact: info@mynomadhealth.com · Tel (305) 680-0566 · Fax (888) 318-3956 · 400 Arthur Godfrey Rd, Suite 200-01, Miami Beach, FL 33140.
Privacy Officer: Steven A. Pino, Director of Clinical Operations
1. Scope; Relationship to the Notice of Privacy Practices
This Privacy Policy explains what information the Services collect, how it is used, who it is shared with, and the choices you have.
If you are a patient of Nomad Health, your medical information ("protected health information" or "PHI") is governed first and foremost by our HIPAA Notice of Privacy Practices ("NPP"). If this Policy and the NPP conflict with respect to PHI, the NPP controls. This Policy adds detail about the websites and applications themselves — accounts, cookies and browser storage, security logging, payments, and non-patient data such as the enrollment interest list.
2. Information We Collect, by Surface
We built the Services deliberately minimal: the web applications load no third-party analytics, no advertising trackers, no external fonts, and no third-party scripts — with two narrow exceptions, each described where it occurs: the optional bot-protection widget in the table in Section 5, which is not currently active, and, during a telehealth video visit, the public network-address lookup described in Section 2.9. The following is a complete inventory of collection points.
2.1 Public marketing site (mynomadhealth.com)
- Browsing: viewing the site does not require an account and sets no advertising or analytics cookies. Standard web-server access logs are kept for security (see Section 2.7).
- Interest list ("Join the interest list" / waitlist): if you ask to be contacted when enrollment opens, we collect your name, email address, phone number, the membership plan you are interested in, and an optional note. As stated on the form itself: "We'll only use this to contact you about membership." That is the only use we make of interest-list information — we do not sell it, share it with third parties for their own use, or add it to any unrelated marketing list. See Sections 4.2 (contact consent) and 7 (retention).
- Scheduling/booking: when choosing an intake appointment time, your browser retrieves open time slots (dates and times only — no personal data is sent to request them). Your selected plan and slot are temporarily kept in your browser's local storage purely so they survive the payment redirect; the server independently re-validates them.
2.2 Enrollment ("/welcome" signup)
When enrollment is open and you sign up after payment, we collect: first name, last name, date of birth, sex, email address (which becomes your portal sign-in), and mobile phone number. This information is transmitted to our practice systems to create your patient record and portal credentials. Your portal sign-in details are generated by the electronic health record system. Staff may hand them to you directly, or — if you have an email address on record — email you a one-time temporary password at that address; either way you are asked to choose your own password the first time you sign in, and after that no one at the practice can see it.
2.3 Patient portal
The portal requires a patient account and displays your own record (visits, invoices, medications, allergies, problems, demographics). Through it you can submit the practice's intake and consent forms. Depending on the form, you may provide:
- Contact and demographic details (address, phone, email, preferred name);
- Emergency contact name, relationship, and phone;
- Primary care provider and preferred pharmacy;
- Medical, surgical, family, and social history (including tobacco, alcohol, and drug-use questions);
- Current medications and allergies;
- Consents and acknowledgments (consent to treat, Florida telehealth consent, HIPAA NPP acknowledgment, release-of-information authorizations, financial policy / Good Faith Estimate acknowledgment);
- For school/sports physicals: student name, date of birth, school, grade, activity, and parent/guardian name, relationship, and consent;
- A hand-drawn electronic signature, captured on a signature pad on your screen (see Section 3).
Each completed form is composed into a PDF document — including your answers, your drawn signature image, your printed name, the form name and version, and a timestamp — and filed directly into your medical chart, where it is PHI governed by the NPP. Patient-reported medications and allergies are reviewed by staff before your chart's clinical lists are updated; they are never applied automatically.
2.4 Staff EHR
The /ehr surface is for our workforce only. Staff activity in the EHR (record access, scheduling, orders, security administration) is audit-logged by the EHR system, and staff clinical note signing and co-signing capture the provider's own drawn signature image into the chart.
Device notifications. The EHR can send an alert to a staff member's own device (for example, that someone is waiting in the telehealth waiting room), and — if you turn notifications on in the portal — to your device (for example, that something is waiting for you in the portal), through a push-notification service, OneSignal. Both are governed by a practice rule stated here so you can hold us to it: the alert itself carries no patient name, no record number, and no clinical information — only a signal to go look in the EHR or sign in to the portal, where the ordinary access controls and audit logging apply. What that service receives is a device registration identifier and that content-free alert; patient devices are registered under a random alias that is meaningless outside our own systems, and the alias-to-patient link never leaves our server.
2.5 Payments
Membership fees and per-service payments are processed by Helcim (Helcim Inc.). The payment form is served by Helcim inside a secure frame on our page — we never see, collect, or store your full payment card number; you enter payment details directly with Helcim, which returns to us confirmation of payment, the amount, and the product/tier purchased. Helcim's own privacy policy (https://www.helcim.com/legal/privacy-policy/) governs its processing. Invoices generated inside the practice do not contain card data; "paid" status is recorded as a document in your chart.
Current status: online payment is not yet live. Online enrollment is disabled, and the public site offers an interest list instead; the payment integration is not accepting live payments. This section will be updated when online payment opens.
2.6 Documents and images
Portal form submissions (PDF), school-physical forms (Florida DH 3040 and FHSAA EL2 PDFs), lab requisitions and lab result PDFs uploaded by staff, invoices, and signature images (PNG) are stored as documents in the EHR. Clinical images associated with your care may also be stored in your chart. Upload size is limited and file types are restricted and content-checked.
2.7 Security, server, and network logs (all surfaces)
To protect the Services we automatically log limited technical data:
- Web server and web application firewall (WAF) logs: IP address, request path and method, timestamps, and any blocked-attack details (the platform runs a WAF based on ModSecurity with the OWASP Core Rule Set);
- Intrusion detection/prevention: IP-level detection and blocking decisions (CrowdSec) and host audit logs;
- Rate limiting: counters keyed to IP address (and, for form submission, to the patient account) to prevent abuse; exceeding limits temporarily blocks requests;
- Relay service logs: the intermediary service that files portal forms and processes enrollment logs event type, IP address, patient internal ID, form ID, filename, and plan tier — it is deliberately designed never to log names, emails, phones, dates of birth, form answers, tokens, or document contents;
- EHR audit logs: access to and actions on patient records by authenticated users, kept as part of our HIPAA security program.
These logs are used only for security, abuse prevention, troubleshooting, and legal compliance.
2.8 Cookies and browser storage
- The patient portal and staff EHR applications set no cookies of their own and use no advertising or analytics cookies anywhere.
- Sign-in sessions are held in your browser's sessionStorage (cleared when the tab closes): an access token for your session and your sign-in name. No PHI and no drafts of clinical notes are ever placed in browser storage.
- The embedded EHR administration screens use the EHR system's own session cookie, which is set with
Secure,HttpOnly, andSameSite=Strictflags. - The marketing site uses browser localStorage transiently to carry your selected plan/appointment slot through the payment redirect.
- A device used for a guardian hand-off during a school physical sets a temporary lock flag (no personal data) in sessionStorage so the device cannot browse other records until staff unlock it.
Because we use no non-essential cookies, there is no cookie-consent banner; if non-essential cookies or analytics are ever added, this Policy and the site will be updated first.
2.9 Telehealth video visits
Video visits take place inside the patient portal itself. There is no third-party video, meeting, or conferencing company involved, and no separate account or app.
- Nothing is recorded and nothing is stored. Video visits are not recorded. No audio or video from a visit is stored by us, by our software provider, or by anyone else — the media exists only while it is in flight between the two devices on the call.
- How the connection is made. Your device and your provider's device connect peer to peer wherever the network allows, using WebRTC, whose media encryption (DTLS-SRTP) is a mandatory property of the technology rather than an option. To find that path, your browser performs a standard address-discovery lookup against a public STUN server, which learns only a network address (IP and port) — no name, no account, no clinical information. Where a direct path is impossible, the already-encrypted stream is relayed through a TURN server run on our own infrastructure, in the same trust domain as the rest of the Services — not through an outside video provider.
- What passes through our server. Only the technical setup messages the two browsers use to find each other (session-description and candidate-address data), held in memory and discarded when the call ends, plus time-limited credentials for the relay above. These carry no clinical content.
- What we log. The fact and timing of a call — that a patient entered the waiting room, that a named staff member admitted them, and that the call ended, identified by internal record numbers — is written to our audit log, exactly as other access to your record is. Call content is never logged.
- On your device. Your camera and microphone are used only during the visit, and only after your browser asks you for permission, which you can refuse or revoke. A local preview of your own camera in the waiting room never leaves your device.
2.10 Medications dispensed in our office
When your provider dispenses a medication to you in the office (see the Terms of Use, Section 3.5), we record the medication, strength, quantity, lot and expiration, the date, and who dispensed it, and we generate the container label required by Florida law. This dispensing record is filed in your chart and is PHI governed by the NPP. It is kept for the period Florida law requires of a dispensing practitioner and is available to the Department of Health on lawful request. This information is not sent to any pharmacy benefit manager, data broker, prescription-history aggregator, or other outside company.
2.11 Laboratory testing
- Point-of-care tests we run ourselves produce a result that our staff enters into your chart. No specimen and no information leaves the practice.
- Tests sent to an outside laboratory generate a requisition PDF containing your name, date of birth, sex, phone, address, the tests ordered, and the diagnosis codes supporting them. You carry that requisition to the laboratory's patient service center, and the laboratory receives the information printed on it. We use Finlay Clinical Laboratories and/or Quest Diagnostics as the practice directs for the test ordered. There is no electronic lab interface — no automatic transmission of orders or results — so the requisition you present and the result document our staff files into your chart are the entire data flow.
2.12 Clinical reference lookups (staff side, no patient data sent)
To help clinicians look things up while charting, the staff EHR queries three free public U.S. government information services: openFDA (FDA drug labeling), MedlinePlus Connect (National Library of Medicine patient-education handouts), and RxNav / RxNorm (National Library of Medicine drug naming). Two facts about these matter to you:
- These lookups are made by our own server, not by your browser, and the only thing sent is the item being looked up — a drug code, a drug name typed by staff, or a diagnosis code. No patient name, record number, date of birth, or any other identifier is sent, and there is no field in which one could be sent. The government service therefore cannot associate a lookup with you.
- The material that comes back (for example, a MedlinePlus handout attached to your visit summary) is public health-education content reproduced with the attribution its publisher requires. Growth-chart reference data published by the CDC is used the same way, except that it ships inside the application, so no request is made at all.
3. Electronic Signatures
Where the Services ask you to sign (portal forms; provider note signing), you draw your signature with a mouse, finger, or stylus. The drawn signature is captured as an image, embedded into the relevant PDF or stored as a chart document together with your printed name and a timestamp, and retained as part of the record it signs. Your drawn electronic signature is intended to be legally binding to the same extent as an ink signature, under the federal ESIGN Act and the Florida Uniform Electronic Transaction Act. See the standalone E-Signature & Electronic Records Consent for full terms, including how to withdraw consent and request paper alternatives.
4. How We Use Information
4.1 Uses
- Provide medical care and operate the practice (treatment, payment, health care operations — per the NPP);
- Conduct telehealth visits, including video visits through the portal (Section 2.9);
- Order and record laboratory testing, and dispense and record medications in our office (Sections 2.10–2.11);
- Create and administer your account and portal credentials;
- Schedule and manage appointments (including intake-visit booking);
- Process payments through our payment processor (Helcim) and maintain billing records, including corrections and refunds;
- Communicate with you about your care, membership, appointments, and billing;
- Contact interest-list members about membership only;
- Secure, monitor, troubleshoot, and improve the Services;
- Comply with legal obligations.
4.2 Interest-list contact; telephone and text consent
By submitting the interest list form with your contact details, you agree that Nomad Health may contact you about membership enrollment by email, phone call, or text message at the details you provided. Our interest-list outreach is done manually by our staff; we do not use automated dialing or prerecorded-message systems for it. Message and data rates may apply to any texts. You may opt out at any time by replying STOP to any text or by emailing info@mynomadhealth.com, and we will remove you from the list. We do not use interest-list details for any other marketing and do not share them with third parties for marketing.
4.3 What we do NOT do
- We do not sell personal information or PHI.
- We do not run third-party advertising, ad pixels, or cross-site tracking on any surface.
- We do not use analytics services.
- We do not record telehealth visits, and we do not store audio or video from them.
- We do not send your prescription or dispensing information to pharmacy benefit managers, prescription-history aggregators, or data brokers.
5. Who We Share Information With (Third Parties / Subprocessors)
We share information only with the parties below, only as described:
| Party | Role | What they receive |
|---|---|---|
| Brickell Bay Group LLC | Software developer/operator of the SanaLogs Chart Pro platform (service provider to the practice) | Operates the software environment in which practice data is processed. We require a Business Associate Agreement with this provider before it handles protected health information. |
| Amazon Web Services, Inc. (AWS) | Cloud hosting (encrypted server and storage volumes; encrypted backups) and outbound email delivery | Service data resides on AWS infrastructure encrypted at rest. Email we send you is delivered through AWS, which therefore receives your email address and the message we send. We require a Business Associate Agreement with AWS before protected health information is stored on its infrastructure or sent through it. |
| Helcim Inc. | Payment processing (Helcim's embedded secure payment form) | Payment card details you enter directly with Helcim; purchase details (amount, tier). No live payments are processed yet — online enrollment is not open. |
| GoDaddy | Domain registrar for mynomadhealth.com | No customer or patient data; domain services only |
| Cloudflare, Inc. (Turnstile) | Optional bot protection on enrollment forms | If activated, the Turnstile widget communicates with Cloudflare to verify you are human; currently not activated — no Cloudflare code loads |
| Finlay Clinical Laboratories and/or Quest Diagnostics | Outside laboratory testing (the practice directs which, per test) | If your provider orders a send-out lab, the requisition you carry to that laboratory's patient service center contains your name, DOB, sex, phone, address, ordered tests, and diagnosis codes. There is no electronic lab interface; the paper/PDF requisition you present is the only data flow. Tests we run in the office send nothing to anyone (Section 2.11). |
| SRFax (Wavetel Technologies) | Outbound prescription faxing, at your or your provider's direction | When a prescription is faxed to the pharmacy you choose, the fax pages (a cover sheet and the prescription — your name, date of birth, prescriber, and the medication) pass through this fax service to that pharmacy's machine. We require a Business Associate Agreement with this provider before prescriptions containing protected health information are transmitted through it. |
| NPPES NPI Registry (U.S. CMS) | Public pharmacy lookup made by our server for staff | A pharmacy name, city, state, or zip code only. No patient identifier is sent and none can be. |
| OneSignal, Inc. | Push notifications to staff devices and, if you enable them, to your own device (Section 2.4) | A device registration identifier and a content-free alert. Patient devices are registered under a random alias — OneSignal is never given your name, record number, email, or any clinical content; the alert only tells you to open the portal, where sign-in and the ordinary access controls apply. |
| Public STUN service (network address discovery) | Helps two devices on a video visit find a network path (Section 2.9) | An IP address and port only. No name, no account, no clinical information, and no audio or video — media never passes through it. |
| Let's Encrypt / certificate authority | TLS certificates | No personal data; certificate issuance only |
| openFDA (U.S. FDA), MedlinePlus Connect and RxNav (U.S. National Library of Medicine) | Public clinical reference lookups made by our server for staff (Section 2.12) | A drug code, drug name, or diagnosis code only. No patient identifier is sent and none can be. |
We may also disclose information: to comply with law, subpoena, or court order (subject to the NPP and Florida's patient-records protections for PHI); to protect the rights, safety, or property of patients, the public, or the practice; or in connection with a sale, merger, or reorganization of the practice, subject to HIPAA and Florida medical-records transfer and records-custodian requirements.
6. Security
Measures in place (summarized; details in our internal security documentation):
- In transit: TLS 1.2/1.3 only, modern cipher suites, HSTS on every surface;
- Telehealth media: encrypted end to end between the two devices on the call by WebRTC's mandatory DTLS-SRTP; peer-to-peer where the network allows, otherwise relayed — still encrypted — through our own server. Not recorded, not stored, never sent to a third-party video service. Call-setup messages are held in memory only and are discarded when the call ends;
- At rest: all server storage volumes (database, documents, backups, relay data) are encrypted (AWS EBS/KMS encryption);
- Perimeter: web application firewall (ModSecurity + OWASP Core Rule Set, in blocking mode), intrusion detection and IP banning (CrowdSec), per-IP and global rate limits, brute-force throttles on login endpoints, DDoS protections;
- Application: role-based access; patient portal sessions are read-only against the record and structurally cannot write to other patients' charts (server-side identity is derived from the session token, never from anything the browser claims); EHR audit logging of record access; 30-minute staff session timeout; password complexity requirements;
- Hardening: CIS-aligned host baseline, automatic security updates, restricted administrative access, nightly encrypted backups;
- Workforce: all workforce members are required to sign confidentiality agreements, receive HIPAA security-awareness training, and be subject to a sanction policy for violations, before they are given access to protected health information.
No system is perfectly secure; we cannot guarantee absolute security, but we notify you of breaches as described in Section 8.
7. Data Retention
- Medical records (PHI): retained for seven (7) years from the date of last patient contact. Records of minor patients, and records subject to litigation holds or other legal requirements, are retained longer where Florida or federal law requires. This meets or exceeds the minimums under Florida medical-records law (§ 456.057, Fla. Stat., and Board of Medicine rule 64B8-10.002).
- Interest list (pre-launch): contact information collected before the Practice opens for enrollment is retained only until the Practice opens for enrollment. When enrollment opens, interest-list members are invited to subscribe, and the pre-launch interest list is then purged. We do not retain interest-list information indefinitely, and you may ask to be removed at any time.
- Security and access logs: access and security logs are retained for at least one (1) year; HIPAA-required audit documentation is retained for six (6) years, for security, audit, and compliance purposes. These periods may be adjusted as our security program evolves.
- Backups: encrypted; currently 7 daily database copies and 4 weekly document-volume copies are retained on encrypted storage.
- Dispensing records: records of medications dispensed to you in the office are part of your medical record and are retained for at least as long as the medical-record period above, and for any longer period Florida law requires of a dispensing practitioner (§ 465.0276, Fla. Stat., and the rules it applies).
- Telehealth video: nothing to retain — no audio or video is recorded or stored. The call-setup data described in Section 2.9 is discarded when the call ends. What remains is the clinical note and the audit entry that the call occurred.
- Payment records: retained per our payment processor's terms and tax/accounting requirements. Our own invoice, payment, correction, and refund records are kept as an append-only history in your chart — a correction or refund is recorded as an additional entry and the original is not erased — for the medical-record retention period above.
8. Breach Notification (HIPAA + Florida FIPA)
If a breach of unsecured PHI or of personal information covered by the Florida Information Protection Act (§ 501.171, Fla. Stat.) occurs, we will investigate, mitigate, and notify affected individuals and regulators as required: under HIPAA, individual notice without unreasonable delay and within 60 days of discovery; under FIPA, notice to affected Florida residents within 30 days of determination of a breach (15-day extension for good cause), notice to the Florida Department of Legal Affairs for breaches affecting 500 or more Florida residents, and notice to consumer reporting agencies for breaches affecting more than 1,000 individuals. Where both laws apply we follow the shorter deadline. Report suspected security issues to info@mynomadhealth.com.
9. Children and Minors
The public website, interest list, and enrollment flow are intended for adults (18+). Minor patients are enrolled and managed by a parent or legal guardian — for example, the school/sports physical intake is completed and signed by the parent/guardian (or by the student only if 18 or older). The patient portal does not currently offer separate proxy/family accounts; parents or guardians of minor patients should contact the office about access to a minor's records, which we handle per the NPP and Florida law. We do not knowingly collect information online from children under 13 except as part of a parent/guardian-directed patient relationship.
10. Your Rights and Choices
- PHI rights (access, amendment, accounting, restrictions, confidential communications) — see the NPP; exercised through the Privacy Officer.
- Interest list — opt out any time (Section 4.2).
- Email — non-care marketing email, if any, will include an unsubscribe mechanism; care and account communications are transactional.
- Browser storage — clearing your browser storage/tab signs you out; nothing else is stored client-side.
- Do Not Track / Global Privacy Control: we do not track users across sites, so these signals do not change our behavior — there is nothing to opt out of.
11. Accessibility
Nomad Health is committed to making the Services accessible to people with disabilities, consistent with the Americans with Disabilities Act. We aim to conform the Services to WCAG 2.1 Level AA. If you have difficulty using any part of the Services, contact info@mynomadhealth.com and we will provide the information or service you need through an alternative method.
12. Changes to This Policy
We may update this Policy from time to time. The current version and its effective date are posted at https://mynomadhealth.com/privacy. Material changes affecting how we use previously collected information will be notified through the Services or by email before they take effect. Continued use after the effective date constitutes acceptance, except where law requires fresh consent.
13. Contact
Privacy questions, requests, or complaints: Steven A. Pino, Director of Clinical Operations, Nomad Health, 400 Arthur Godfrey Rd #200-01, Miami Beach, FL 33140, info@mynomadhealth.com. You may also complain to the HHS Office for Civil Rights (see the NPP) — we will never retaliate against you for doing so.