Bariatric Associates, LLC d/b/a Physician’s Plan
Effective Date: August 24, 2026
Last Updated: August 24, 2026
1. Introduction and Scope
Bariatric Associates, LLC, doing business as Physician’s Plan (“Physician’s Plan,” “we,” “us,” or “our”), respects the privacy of our patients, customers, and website visitors. This Privacy Policy explains what information we collect, how we use and disclose it, how we protect it, the choices and rights you have, and how we ensure our operations comply with the privacy and health-information laws that apply in every jurisdiction we serve.
This Policy applies to:
- www.physiciansplan.com and all of its subdomains and pages, including landing pages, blogs, appointment-request forms, quizzes, and contact forms;
- shop.physiciansplan.com, our online store for supplements, skincare, and wellness products;
- booknow.physiciansplan.com and other online scheduling pages;
- Our seven clinic locations in South Carolina and North Carolina;
- Telehealth and virtual visits we provide to patients;
- Email, SMS/text, telephone, and social media communications with us; and
- Any other online or offline service that links to this Policy.
Two categories of information, two sets of rules. Physician’s Plan is a HIPAA covered entity. Information we create or receive in the course of providing medical care, billing for that care, and operating our practice is Protected Health Information (“PHI”) and is governed by the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”), by the HITECH Act, and by our Notice of Privacy Practices (“NPP”), which is provided to every patient at the start of care, posted at each clinic, and available on request. Information collected through our public website, online store, and marketing activities that is not PHI (for example, an unauthenticated visitor’s IP address and pages viewed) is governed by this Privacy Policy.
Where this Policy and our Notice of Privacy Practices both apply to the same information, the Notice of Privacy Practices controls with respect to PHI, and nothing in this Policy grants us rights to use or disclose PHI beyond what HIPAA and the NPP permit.
Our patient portal is hosted by a third-party vendor (MyPatientVisit). Information you submit inside the portal is handled under our Notice of Privacy Practices and the vendor’s agreement with us, which includes a HIPAA Business Associate Agreement.
2. Information We Collect
2.1 Information you provide to us directly
- Identifiers and contact details: name, date of birth, mailing address, email address, telephone and mobile number, emergency contact.
- Appointment and inquiry information: the location and service you are interested in, preferred appointment times, and any message you write to us.
- Health information you choose to share with us before you become a patient: for example, your height and weight, weight-loss goals, current medications, allergies, symptoms, skin concerns, or answers to a quiz or eligibility questionnaire on our site.
- Clinical information created during care: medical history, examination findings, laboratory and diagnostic results, diagnoses, prescriptions and medication administration records, treatment plans, progress notes, photographs used for clinical documentation, and consent forms. This information is PHI.
- Insurance and payment information: insurance identifiers where applicable, payment card data, bank account details for autopay or subscriptions, and financing applications submitted through Cherry, CareCredit, or similar partners. Payment card numbers are collected and processed by our PCI-DSS compliant payment processors; we do not store full payment card numbers on our own systems.
- Store and subscription information: products ordered, shipping address, order history, and account credentials on shop.physiciansplan.com.
- Employment information: if you apply for a job, the contents of your application, resume, and any information you provide during hiring.
- Communications: emails, text messages, chat messages, voicemail, call recordings where recording is disclosed to you, reviews, and social media messages.
2.2 Information collected automatically
When you visit our websites, we and our service providers may automatically collect:
- IP address and general geographic location derived from it;
- Device type, operating system, browser type and language;
- Referring URL and search terms that brought you to us;
- Pages viewed, links and buttons clicked, scroll depth, time on page, and dates and times of visits;
- Form-interaction and conversion events (for example, that an appointment-request form was submitted from a particular page);
- Cookie, pixel, and similar identifiers as described in Section 6.
2.3 Information from other sources
- Referring physicians, laboratories, pharmacies (including compounding and outsourcing facilities), imaging providers, and other treating providers;
- Health plans, clearinghouses, and financing partners, in connection with payment;
- Identity verification, fraud prevention, and address-validation vendors;
- Advertising, analytics, and call-tracking platforms that report to us how our marketing performs, in aggregated or pseudonymous form;
- Publicly available sources and social media platforms when you interact with our pages.
2.4 Information we do not intentionally collect
Please do not send detailed health information through unencrypted email, social media messages, text messages, or website comment fields. Use our patient portal or call your clinic instead. If you do send health information through an insecure channel, we will treat it in accordance with this Policy and, if it constitutes PHI, in accordance with HIPAA, but we cannot guarantee the security of the channel you chose.
3. How We Use Information
We use information for the following purposes:
Treatment. To evaluate your eligibility for our programs, provide medical weight-loss care (including GLP-1 and other prescription therapies), hormone replacement therapy, aesthetic and med spa services, and telehealth visits; to coordinate with pharmacies, laboratories, and other providers; and to follow up on your care.
Payment. To bill you, your health plan, or a financing partner; to process payments, memberships, and subscriptions; to verify benefits; and to pursue payment for services rendered.
Health care operations. Quality assessment and improvement, clinical protocol development, credentialing and peer review, training of staff and students, business planning, audits, accreditation and certification (including LegitScript certification), legal and compliance activities, and general administration.
Service delivery and customer support. To schedule, confirm, reschedule, and remind you of appointments; to fulfill product orders and returns; to answer your questions; and to administer accounts on our online store.
Marketing and communications, subject to the limits in Sections 6 and 7. To send newsletters, promotions, service announcements, and educational content you have asked to receive; to measure whether our advertising works; and to invite feedback and reviews. Marketing that uses PHI is done only as HIPAA permits, which for most marketing communications means only with your prior written authorization. You may opt out of marketing at any time.
Website analytics and improvement. To understand how visitors use our sites, diagnose technical problems, improve content and navigation, and secure our systems.
Safety, security, and fraud prevention. To protect our patients, staff, and property; to detect and prevent fraud, abuse, and unauthorized access; and to maintain the integrity of our systems.
Legal compliance. To comply with federal and state law, respond to lawful requests from public authorities, report as required to public health and licensing authorities, defend legal claims, and enforce our terms.
We do not sell personal information, and we do not sell or share consumer health data. We do not use or disclose PHI for advertising purposes without your written authorization.
4. How We Ensure Compliance With Privacy and Health-Information Laws
Physician’s Plan maintains a written compliance program covering privacy, security, and breach response. The program is administered by our Privacy Officer and Security Officer, is reviewed at least annually, and is designed to meet the requirements of every jurisdiction in which we operate or advertise. Specifically:
4.1 Federal health-information law
- HIPAA Privacy Rule (45 C.F.R. Part 164, Subpart E). We maintain and distribute a Notice of Privacy Practices, obtain written authorizations where required (including for marketing and for any sale of PHI), apply the minimum necessary standard, honor patient rights of access, amendment, accounting, restriction, and confidential communication, and maintain a complaint process with no retaliation against complainants.
- HIPAA Security Rule (45 C.F.R. Part 164, Subpart C). We conduct and document a security risk analysis, maintain a risk management plan, and implement administrative, physical, and technical safeguards for electronic PHI, including access controls, unique user identification, audit controls, encryption, workforce sanctions, and contingency planning.
- HIPAA Breach Notification Rule (45 C.F.R. Part 164, Subpart D) and the HITECH Act. We investigate every suspected impermissible use or disclosure, perform and document a four-factor risk assessment, and provide notice to affected individuals, the U.S. Department of Health and Human Services, and, where required, the media, within the timeframes the rule requires.
- Business Associate Agreements. Before any vendor creates, receives, maintains, or transmits PHI on our behalf, we execute a HIPAA-compliant Business Associate Agreement obligating the vendor to safeguard PHI, limit its use, report incidents, and return or destroy PHI at the end of the engagement.
- Workforce training. All workforce members receive HIPAA privacy and security training at hire and at least annually thereafter, plus role-specific training for staff who handle prescriptions, payments, or marketing. Training completion is documented.
- FTC Act Section 5 and the FTC Health Breach Notification Rule. We do not make deceptive statements about our privacy practices, and we honor the commitments in this Policy.
- Additional federal laws we follow where applicable: the CAN-SPAM Act (commercial email), the Telephone Consumer Protection Act (calls and text messages), the Children’s Online Privacy Protection Act, the Americans with Disabilities Act as it relates to accessible communication, and applicable Drug Enforcement Administration and Food and Drug Administration requirements governing prescribing and telemedicine.
4.2 State health-privacy and medical-records law
Our clinics are located in South Carolina and North Carolina, and our patients reside primarily in those states. We comply with the medical-record confidentiality, retention, and patient-access requirements of both states, including South Carolina’s Physicians’ Patient Records Act and the South Carolina Financial Identity Fraud and Identity Theft Protection Act, and North Carolina’s medical-records and Identity Theft Protection Act requirements, including their respective security-breach notification obligations to affected residents and to the state Attorney General where required. Where we provide telehealth to a patient physically located in another state, we follow that state’s medical-record confidentiality and telemedicine requirements as well as the licensure requirements applicable to the treating clinician.
4.3 State consumer privacy law
To the extent our processing of information that is not PHI falls within their scope, we honor the rights and obligations created by comprehensive state consumer privacy laws, including those of California (CCPA as amended by the CPRA, and the Confidentiality of Medical Information Act), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island, together with any additional state law that becomes effective after the date of this Policy. See Section 8 for how to exercise these rights.
4.4 Consumer health data law
We comply with laws that specifically regulate consumer health data, including the Washington My Health My Data Act, Nevada SB 370, and Connecticut’s consumer health data provisions. See Section 9.
4.5 Visitors from outside the United States
Our services are offered in and directed to the United States. If you access our sites from the European Economic Area, the United Kingdom, or another jurisdiction with data-protection legislation, we process your information only as needed to respond to you and, where that legislation applies to us, on the basis of your consent, our legitimate interests in operating our business, or compliance with a legal obligation. Your information will be transferred to and processed in the United States.
4.6 Independent verification
Physician’s Plan is certified by LegitScript, which conducts an independent review of our licensure, advertising, patient-safety, and privacy practices, and monitors us on an ongoing basis as a condition of certification.
5. How We Protect Information
We maintain administrative, physical, and technical safeguards appropriate to the sensitivity of the information we hold:
- Technical: encryption of data in transit (TLS) and encryption of electronic PHI at rest; unique user accounts; multi-factor authentication on remote and administrative access; role-based access limited to the minimum necessary; automatic logoff; endpoint protection and patch management; network segmentation and firewalls; audit logging and review of access to records; secure disposal and media sanitization.
- Administrative: written privacy and security policies; designated Privacy Officer and Security Officer; documented security risk analysis and remediation; workforce background screening; confidentiality agreements; annual and role-based training; sanctions for violations; vendor due diligence and Business Associate Agreements; documented incident response and breach notification procedures; periodic internal audits.
- Physical: locked medical-record storage and access-controlled clinic areas; visitor controls; workstation positioning and privacy screens; secure shredding of paper records.
- Retention: we retain records only as long as needed for the purposes described in this Policy and as required by state medical-record retention law, professional standards, and our records-retention schedule, and then destroy them securely. Website analytics data is retained on a shorter schedule.
No system can be guaranteed to be perfectly secure. If a breach of unsecured PHI or of personal information occurs, we will notify you and the appropriate regulators as required by HIPAA and applicable state breach-notification law.
6. Cookies, Analytics, and Tracking Technologies
We and our service providers use cookies, pixels, tags, software development kits, and similar technologies on our public websites.
Categories we use:
- Strictly necessary. enable core functions such as page loading, security, load balancing, cart and checkout on our online store, and remembering your cookie choices. These cannot be switched off in our systems.
- Performance and analytics. Google Analytics 4, deployed through Google Tag Manager, tells us how visitors find and use our sites in aggregate.
- Functionality. remember preferences such as your selected clinic location.
- Advertising. Google Ads conversion and remarketing tags and the LinkedIn Insight Tag help us measure advertising performance and, in limited cases described in Section 7, show our ads to people who have visited our site.
- Online store. shop.physiciansplan.com runs on Shopify, which sets its own cookies for cart, checkout, fraud prevention, and store analytics under Shopify’s privacy terms.
Our commitment regarding health information and tracking technologies. We configure our sites and tag management so that protected health information is not transmitted to analytics or advertising platforms. We do not place advertising or analytics tags inside the patient portal or on authenticated patient pages. We do not pass names, email addresses, phone numbers, dates of birth, appointment details, diagnoses, medications, quiz answers, or other health-related form entries to advertising vendors. Where a vendor supports it, we enable IP-address masking and disable data-sharing and ad-personalization features. We review our tag configuration periodically and after any significant website change, consistent with guidance from the HHS Office for Civil Rights and the Federal Trade Commission on the use of online tracking technologies by health care providers.
Your choices:
- Most browsers let you refuse or delete cookies through their settings, and offer a “do not track” setting.
- We honor the Global Privacy Control (GPC) browser signal as a valid request to opt out of targeted advertising and any sharing of personal information.
- Opt out of Google Analytics using Google’s browser add-on at tools.google.com/dlpage/gaoptout.
- Manage Google ad personalization at myadcenter.google.com and adssettings.google.com.
- Opt out of many participating advertising vendors at optout.aboutads.info (Digital Advertising Alliance) and optout.networkadvertising.org (Network Advertising Initiative).
- Opt out of LinkedIn ad targeting in your LinkedIn account settings.
Blocking cookies may affect how parts of our sites function.
7. Advertising and Remarketing
We advertise our services on search engines, social media, and other digital platforms. In connection with that advertising:
- Third-party vendors, including Google, use first-party cookies (such as the Google Analytics cookie) and third-party cookies (such as Google advertising cookies) together to inform, optimize, and serve ads based on someone’s past visits to our website.
- Visitors can opt out of Google’s use of cookies for personalized advertising by visiting Google Ads Settings at adssettings.google.com, and can opt out of third-party vendors’ use of cookies for personalized advertising at optout.aboutads.info.
- We do not use sensitive health information for advertising. We do not create, upload, or target advertising audiences based on a person’s health condition, diagnosis, treatment, prescription, medical procedure, body weight, or other sensitive category, and we instruct our advertising vendors and agencies not to do so on our behalf. This practice is consistent with Google’s Personalized Advertising policy and with our obligations under HIPAA.
- We do not upload patient lists to advertising platforms. We do not use PHI to build customer-match, lookalike, or retargeting audiences.
- Advertising conversion measurement is limited to non-identifying signals such as “a form was submitted” or “an appointment was requested,” never the contents of that form.
- Any use of PHI for marketing that HIPAA treats as “marketing” is done only with your prior written authorization, which you may revoke at any time.
8. Your Privacy Rights and Choices
8.1 HIPAA rights (patients)
As a patient, you have the right to:
- Inspect and obtain a copy of your medical and billing records, in electronic form where we maintain them electronically, generally within 30 days;
- Request an amendment to your record if you believe it is inaccurate or incomplete;
- Receive an accounting of certain disclosures we have made of your PHI;
- Request restrictions on how we use or disclose your PHI, including the right to restrict disclosure to a health plan for services you pay for in full out of pocket;
- Request confidential communications at an alternative address or by an alternative means;
- Receive a paper copy of our Notice of Privacy Practices at any time;
- Be notified if a breach of your unsecured PHI occurs; and
- File a complaint with us or with the U.S. Department of Health and Human Services, without retaliation.
To exercise these rights, contact our Privacy Officer using the information in Section 13, or ask any clinic for the appropriate form.
8.2 State consumer privacy rights
Depending on your state of residence, and to the extent the information is not PHI or otherwise exempt, you may have the right to:
- Know and access the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of recipients;
- Correct inaccurate personal information;
- Delete personal information we have collected from you;
- Obtain a portable copy of information you provided to us;
- Opt out of targeted advertising, of any sale of personal information, and of profiling in furtherance of decisions producing legal or similarly significant effects;
- Limit the use and disclosure of sensitive personal information;
- Withdraw consent where processing is based on consent;
- Not be discriminated against for exercising any of these rights; and
- Appeal a decision we make about your request.
How to submit a request. Email info@physiciansplan.com, write to the address in Section 13, or call (843) 606-3333. Tell us which right you wish to exercise and give us enough information to verify your identity. We will not use verification information for any other purpose. An authorized agent may submit a request on your behalf with written permission that we can verify.
Our response. We will confirm receipt within 10 days and respond substantively within 45 days, and may extend that period by an additional 45 days where reasonably necessary, in which case we will tell you why. If we decline your request, we will explain why and how to appeal; we will decide an appeal within 45 days. If your appeal is denied, you may contact your state Attorney General.
8.3 Marketing and communication choices
- Email: click “unsubscribe” in any marketing email or contact us. We will still send transactional messages such as appointment confirmations and billing notices.
- Postal mail and phone: ask us to remove you from marketing lists.
- Cookies and advertising: see Section 6.
8.4 Text messaging (SMS)
If you provide your mobile number and consent to receive text messages, we may send appointment reminders, care-related messages, and, where you have separately opted in, promotional messages. Message and data rates may apply; message frequency varies. Reply STOP to any message to opt out and HELP for assistance, or contact your clinic.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text-messaging originator opt-in data and consent are not shared with any third party, other than with the messaging vendors that deliver the messages on our behalf under contract.
9. Consumer Health Data (Washington, Nevada, and Connecticut Residents)
For residents of states with consumer health data laws, and to the extent that data is not PHI or otherwise exempt from those laws:
- What we collect: the health-related information described in Section 2, which may include your interest in weight management, hormone therapy, or aesthetic services; information you enter in a quiz, eligibility check, or appointment request; and inferences drawn from the pages you visit on our site.
- Why we collect it: to determine whether our programs may be appropriate for you, to schedule and provide care, to respond to your inquiry, and to operate and improve our services.
- Sources: you, your treating providers, and our own websites and systems.
- Who we share it with: the categories of recipients listed in Section 10, each of whom is bound by contract to protect it.
- What we do not do: we do not sell consumer health data, we do not use it for targeted advertising, and we do not use a geofence around any health care facility to identify, track, or send messages or advertisements to consumers based on their proximity to that facility.
- Your rights: you may confirm whether we collect, share, or sell your consumer health data; access it; withdraw consent to its collection and sharing; and request its deletion, including deletion by our service providers. Submit requests as described in Section 8.2. Washington residents may also file a complaint with the Washington State Attorney General.
10. How and With Whom We Share Information
We share information only as described below, and never sell it.
- Your treating clinicians and our workforce, on a minimum-necessary basis.
- Other health care providers involved in your care, including referring and consulting physicians, laboratories, imaging centers, and pharmacies (including compounding pharmacies and outsourcing facilities that dispense medications we prescribe).
- Business associates and service providers under written contract, including: electronic health record and patient-portal vendors; scheduling and appointment-reminder platforms; telehealth platforms; e-prescribing services; laboratory partners; billing, collections, and revenue-cycle vendors; payment processors and financing partners such as Cherry and CareCredit; secure cloud hosting, backup, and IT security providers; secure document destruction vendors; and professional advisors such as attorneys, accountants, and auditors.
- Website and marketing service providers, including our hosting provider, Shopify (online store), Google (analytics, tag management, and advertising), LinkedIn, email marketing platforms, and our marketing agency, each limited to the non-PHI data described in Sections 6 and 7 and bound by contract.
- Health plans, clearinghouses, and other payers, for payment purposes.
- Public health and regulatory authorities, when required or permitted by law, including reporting of adverse events, communicable diseases, suspected abuse or neglect, and responses to health-oversight audits, licensing boards, and the Department of Health and Human Services.
- Law enforcement, courts, and parties to legal process, in response to a valid subpoena, court order, warrant, or other lawful demand, and as permitted by 45 C.F.R. § 164.512.
- To avert a serious threat to the health or safety of you or others.
- Persons involved in your care, such as a family member or personal representative, when you agree or when the law permits.
- In a business transaction, such as a merger, acquisition, financing, or sale of assets, in which case PHI transfers only as HIPAA permits and the successor remains bound by this Policy for the information it receives.
- With your written authorization, for any other purpose. You may revoke an authorization at any time in writing, except to the extent we have already acted in reliance on it.
Psychotherapy notes, uses and disclosures for marketing, and any sale of PHI require your prior written authorization.
11. Children’s Privacy
Our websites and online store are intended for adults. We do not knowingly collect personal information online from children under 13, and our services are not directed to them. Patients under the age of 18 are treated only in accordance with applicable state law and with the involvement and consent of a parent or legal guardian where required, and their records are handled as PHI. If you believe a child has provided us personal information through our website, contact us and we will delete it.
12. Other Terms
Third-party websites. Our sites link to third parties, including our patient portal, our online store, review sites, and social media. Those services have their own privacy policies, and we are not responsible for their practices. Review their policies before providing information.
Do Not Track. Because there is no common industry standard for browser “Do Not Track” signals, our sites do not respond to them. We do honor the Global Privacy Control signal as described in Section 6.
Changes to this Policy. We may update this Policy from time to time. We will post the revised version here with a new “Last Updated” date, and, if the changes are material, provide additional notice. Changes to our Notice of Privacy Practices are handled separately in accordance with HIPAA. Your continued use of our sites and services after an update constitutes acceptance of the revised Policy.
Accessibility. If you need this Policy in an alternative format, contact us and we will provide one.
13. How to Contact Us
Privacy Officer
Bariatric Associates, LLC d/b/a Physician’s Plan
1705 Beaucastel Rd., Ste. 101
Mt. Pleasant, SC 29464
Email: info@physiciansplan.com
Phone: (843) 606-3333
You may also contact any clinic directly:
| Location | Address | Phone |
|---|---|---|
| West Ashley, SC | 12A Farmfield Ave., Charleston, SC 29407 | (843) 769-5510 |
| Mt. Pleasant, SC | 1705 Beaucastel Rd., Ste. 101, Mt. Pleasant, SC 29464 | (843) 606-3333 |
| Summerville, SC | 102 W. 8th N. St., Ste. G, Summerville, SC 29483 | (843) 261-1111 |
| Florence, SC | 2151 West Evans St., Ste. I, Florence, SC 29501 | (843) 629-0099 |
| Rock Hill, SC | 526 John Ross Pkwy., Ste. 107, Rock Hill, SC 29730 | (803) 329-7777 |
| Hickory, NC | 1706 Highway 70 SE, Hickory, NC 28602 | (828) 485-2833 |
| Huntersville, NC | 9601 Holly Point Dr., Ste. 202, Huntersville, NC 28078 | (704) 987-8446 |
To file a complaint. You may file a privacy complaint with our Privacy Officer at any time. You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, 200 Independence Avenue SW, Washington, D.C. 20201; 1-877-696-6775; hhs.gov/ocr/privacy/hipaa/complaints/. We will not retaliate against you for filing a complaint.
Residents of states with consumer privacy laws may also contact their state Attorney General.
This Privacy Policy is published at https://www.physiciansplan.com/privacy-policy/ and describes practices for information collected through our websites, online store, and marketing. Our Notice of Privacy Practices, which governs protected health information, is available at any clinic, from our Privacy Officer, and on request from our Privacy Officer at the address above.