Privacy Policy
Effective date: August 5, 2026
Last updated: August 5, 2026
This page contains two documents. Part 1 is our Website Privacy Policy, which explains how we handle information collected through our website and digital services. Part 2 is the HIPAA Notice of Privacy Practices for Tailwind Care Provider Group, P.A., which explains how protected health information is used and disclosed when you or your child receives care from us.
Part 1: Website Privacy Policy
Who we are
Tailwind Care is a virtual-first pediatric weight management program. Our services are delivered through two related entities:
- Tailwind Care, Inc. ("Tailwind Care," "we," "us," or "our") operates the website, technology platform, scheduling, messaging, billing support, and other administrative and operational functions.
- Tailwind Care Provider Group, P.A., a Florida professional corporation (the "Provider Group"), employs and contracts with the licensed clinicians - nurse practitioners, registered dietitians, and licensed clinical social workers - who provide medical and behavioral health services to patients.
The Provider Group provides services to patients located in Arizona, Indiana, Michigan, North Carolina, Pennsylvania, and Texas. Our services are only available to families located in states where our clinicians are licensed to practice.
If you have questions about this Privacy Policy, contact us at privacy@tailwindcare.org.
Where we operate
Tailwind Care is a virtual-first pediatric weight management practice. We are not yet accepting patients. At launch, services will be available only to families located in the following states: Arizona, Indiana, Michigan, North Carolina, Pennsylvania, and Texas. Patients must be physically located in one of these states at the time of each visit. We do not provide services in any other state. This page will be updated as our service area changes.
What this policy covers
This Privacy Policy applies to information we collect when you:
- Visit our website at tailwindcare.org
- Create an account or sign up for our services
- Communicate with us by email, text message, phone, or chat
- Use our family portal or other digital tools
When you or your child becomes a patient of the Provider Group, health information collected in connection with your care is protected health information ("PHI") governed by the Health Insurance Portability and Accountability Act ("HIPAA") and the Notice of Privacy Practices in Part 2 below. Where this Privacy Policy and the Notice of Privacy Practices overlap, the Notice of Privacy Practices governs PHI.
Information we collect
Information you provide to us. This may include:
- Contact and account information: your name, email address, phone number, mailing address, and account credentials
- Information about your child: name, date of birth, and health information you share during signup, intake, screeners, and care
- Insurance information: payer, member ID, and related coverage details used to verify eligibility and benefits
- Payment information: processed by our payment processor; we do not store full card numbers on our own systems
- Communications: messages you send to our care team, support requests, and survey responses
Information collected automatically. When you visit our website, we and our service providers may collect:
- Device and browser information, IP address, and general location (city/state level)
- Pages viewed, links clicked, and how you arrived at our site
- Cookies and similar technologies as described in the Cookies section below
How we use information
We use the information we collect to:
- Provide, coordinate, and improve our services, including scheduling, care coordination, and family communications
- Verify insurance eligibility and benefits and provide written coverage information before your first visit
- Process payments and manage billing
- Send appointment reminders, service updates, and other communications about your care
- Respond to questions and provide customer support
- Maintain the security and integrity of our systems
- Comply with legal and regulatory obligations
- Understand how our website is used so we can improve it
We use certain technology tools, including artificial intelligence tools operating under agreements that protect health information, to support administrative and clinical workflows such as drafting visit documentation and preparing educational materials. Licensed clinicians review all clinical outputs. Automated tools do not make medical decisions about your child's care.
How we share information
We share personal information only in the following circumstances:
- With the Provider Group and its clinicians, to deliver care to you and your child
- With service providers that support our operations - such as our electronic health record platform, secure cloud hosting, video visit platform, payment processor, laboratory and pharmacy partners, and communications tools. Service providers that handle health information do so under business associate agreements as required by HIPAA and may only use it to provide services to us.
- With your health plan or payer, to verify eligibility, submit claims, and obtain prior authorizations
- With other healthcare providers involved in your child's care, such as your child's pediatrician, with your consent or as permitted by law
- As required by law, including in response to lawful requests by public authorities, court orders, or to protect health and safety
- In a business transaction, such as a merger or acquisition, in which case we will require the successor to honor the commitments in this policy
What we do not do
- We do not sell your personal information or your child's personal information. Not for money, and not in exchange for anything else.
- We do not use or disclose health information for advertising. We will never use information about your child's health, weight, diagnoses, medications, or care to target advertising to you or anyone else.
- We do not permit third-party advertising trackers on the logged-in portions of our services (the family portal and any page where care is delivered or health information is entered).
Cookies and similar technologies
Our public website uses:
- Strictly necessary cookies for security, session management, and core site functionality. These cannot be disabled.
- First-party measurement - we use our own measurement tool to understand how visitors use our public website, such as pages visited and referral source. This information stays with us and is not shared with advertising networks.
You can manage cookies through your browser settings. Where required by law, we provide a cookie banner or preference center to manage non-essential cookies.
Some browsers offer a "Do Not Track" signal. Because there is no common standard for interpreting these signals, our website does not currently respond to them, but the commitments in this policy apply regardless.
Children's privacy
Our services are pediatric by design, and we take children's privacy seriously.
- Our website and signup process are directed to parents and legal guardians, not to children. Accounts must be created by an adult who is at least 18 years old and is the parent or legal guardian of the child receiving care.
- Where we provide portal access to an adolescent patient, that access is established by and with the consent of a parent or legal guardian as part of the child's care.
- For any child under 13, we collect personal information online only with verifiable parental consent, consistent with the Children's Online Privacy Protection Act (COPPA), and only as needed to provide care.
- We do not use children's personal information for marketing or advertising, and we do not condition a child's participation in care on providing more information than is reasonably necessary.
- Parents and guardians may review, request correction of, or request deletion of their child's information, subject to medical record retention requirements, by contacting us at privacy@tailwindcare.org.
A note on adolescent confidentiality
State law provides adolescents with confidentiality protections for certain types of health information. Where applicable law limits a parent's or guardian's access to portions of an adolescent's health record, we honor those protections in our systems and in how we respond to access requests. Questions about what is and is not accessible to caregivers can be directed to our care team.
Your privacy rights
Depending on where you live, you may have rights under state privacy laws, which may include the right to:
- Know what personal information we have collected about you
- Access a copy of your personal information
- Correct inaccurate personal information
- Request deletion of personal information, subject to legal retention requirements
- Opt out of the sale or sharing of personal information (as noted above, we do not sell personal information)
To exercise any of these rights, contact us at privacy@tailwindcare.org. We will verify your identity before fulfilling a request and will respond within the timeframe required by applicable law. We will not discriminate against you for exercising your privacy rights.
Rights relating to protected health information - including the right to access, amend, and receive an accounting of disclosures of your or your child's medical records - are described in the Notice of Privacy Practices in Part 2.
Data security
We use administrative, technical, and physical safeguards designed to protect personal information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Access controls that limit who can view sensitive information, enforced at the data layer
- Business associate agreements with all vendors that handle health information
- Logging and monitoring of access to health information
No system is perfectly secure. If a breach of unsecured health information occurs, we will notify affected individuals as required by law.
Data retention
We retain personal information for as long as needed to provide services, comply with legal obligations (including medical record retention laws, which for pediatric records generally extend for a period of years after the patient reaches the age of majority), resolve disputes, and enforce agreements. When information is no longer needed, we securely delete or de-identify it.
Communications preferences
- Email: you can opt out of non-essential emails using the unsubscribe link in any marketing message. We will still send transactional messages about your account and care.
- Text messages: by providing your mobile number and opting in, you consent to receive text messages from us about appointments, care coordination, and account matters. Message and data rates may apply. Message frequency varies. Reply STOP to opt out or HELP for help. We do not share your mobile number with third parties for their marketing purposes. Do not use text messaging for emergencies - call 911.
- Phone: you may ask us to stop calling for non-essential purposes at any time.
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will post the updated policy on this page with a new effective date and, where required by law, provide additional notice. Your continued use of our services after changes take effect means you accept the updated policy.
Contact us
Tailwind Care, Inc.
1111B S Governors Ave # 28109, Dover, DE 19904
privacy@tailwindcare.org
919.244.2335
Part 2: HIPAA Notice of Privacy Practices
Effective date: August 5, 2026
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU OR YOUR CHILD MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
Who this notice applies to
This Notice of Privacy Practices (this "Notice") applies to Tailwind Care Provider Group, P.A. and its workforce members, clinicians, contractors, and business associates that help it provide healthcare services (collectively, the "Practice," "we," "us," or "our"). Tailwind Care, Inc. supports the Practice with non-clinical administrative, operational, and technology functions.
Because we provide pediatric services, this Notice applies to protected health information ("PHI") about a child and to information provided by a parent, legal guardian, or other authorized representative acting on the child's behalf, as permitted by law.
What is PHI
PHI is individually identifiable health information relating to a person's past, present, or future physical or mental health condition, the provision of healthcare, or payment for healthcare. For our patients, PHI may include names, dates of birth, and contact details; height, weight, BMI, growth, nutrition, activity, sleep, and lab information; screener results and behavioral health information; diagnoses, medications, and care plans; visit notes and communications with the care team; and insurance, billing, and claims information.
How we may use and disclose PHI without your written authorization
Treatment. We may use and disclose PHI to provide, coordinate, and manage your child's care - for example, reviewing health history, evaluating labs and screeners, communicating among the care team (nurse practitioner, dietitian, and behavioral health clinician), prescribing medications, ordering labs, and creating care plans. With your consent or as permitted by law, we may share information with other providers involved in your child's care, such as your child's pediatrician.
Payment. We may use and disclose PHI for payment purposes, including verifying insurance eligibility and benefits, obtaining prior authorizations, submitting claims, billing, and collections.
Healthcare operations. We may use and disclose PHI for our operations, including quality assessment and improvement, staff training and supervision, credentialing, compliance, auditing, and practice management.
Appointment reminders and care communications. We may contact you about appointments, follow-up care, forms, prescriptions, lab requests, and other service-related matters, by the communication methods you have provided.
Individuals involved in care. Where permitted by law, we may disclose relevant PHI to a parent, guardian, caregiver, or other person involved in your child's care or in payment for that care. Note: state law may give adolescent patients confidentiality rights over certain information, and access for parents and caregivers may be limited accordingly. Where more than one caregiver is involved in a child's care, access to information may differ between caregivers as permitted or required by law or court order.
Business associates. We may disclose PHI to vendors that help us operate - such as our electronic health record platform, cloud hosting providers, billing and clearinghouse services, laboratories, pharmacies, video visit and communication platforms - under written agreements requiring them to safeguard the information.
As required by law. We may use or disclose PHI when federal, state, or local law requires it, including mandatory reporting of suspected child abuse or neglect.
Public health and safety. We may disclose PHI for public health activities and when necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public.
Health oversight, legal proceedings, and law enforcement. We may disclose PHI to health oversight agencies, in response to court orders or other lawful process, or to law enforcement as permitted or required by law.
Other permitted uses. We may use or disclose PHI for research, workers' compensation, or other purposes only as permitted by HIPAA and applicable state law, which in some cases requires additional protections or your authorization.
Uses and disclosures that require your written authorization
We will obtain your written authorization before:
- Using or disclosing PHI for marketing purposes
- Selling PHI (which we do not do)
- Using or disclosing psychotherapy notes, except as permitted by law
- Any other use or disclosure not described in this Notice
You may revoke an authorization in writing at any time, except to the extent we have already relied on it.
Your rights regarding PHI
Subject to applicable law, you (or, for a minor patient, the child's personal representative, subject to adolescent confidentiality laws) have the right to:
- Inspect and copy PHI in our records, including an electronic copy of the medical record
- Request an amendment of PHI you believe is incorrect or incomplete
- Request an accounting of certain disclosures of PHI
- Request restrictions on certain uses and disclosures, including the right to restrict disclosures to a health plan for services paid fully out of pocket
- Request confidential communications by alternative means or at alternative locations
- Receive a paper copy of this Notice on request, even if you agreed to receive it electronically
- Be notified following a breach of unsecured PHI
To exercise any of these rights, contact us at privacy@tailwindcare.org or 1111B S Governors Ave # 28109, Dover, DE 19904.
Our responsibilities
We are required by law to maintain the privacy and security of PHI, to provide this Notice of our legal duties and privacy practices, to notify you following a breach of unsecured PHI, and to abide by the terms of the Notice currently in effect. We reserve the right to change this Notice and to make the revised Notice effective for PHI we already hold. The current Notice will always be posted on our website.
Complaints
If you believe your privacy rights have been violated, you may file a complaint with us at privacy@tailwindcare.org or with the U.S. Department of Health and Human Services, Office for Civil Rights, 200 Independence Avenue S.W., Washington, D.C. 20201, or online at hhs.gov/ocr. We will not retaliate against you for filing a complaint.
Contact
Tailwind Care Provider Group, P.A.
Privacy Officer: Lindsay Goldman
1111B S Governors Ave # 28109, Dover, DE 19904
privacy@tailwindcare.org
919.244.2335