1. Introduction
This Privacy Policy describes how Regulated with Loreta / The Regulated Nurse (“we,” “us,” or “our”), operated by Loreta Labode, RN under the physician supervision of Jean-Carlos Jimenez, MD, collects, uses, discloses, and protects information when you visit www.regulatedwithloreta.com (the “Site”), contact us, book or receive telehealth services, or otherwise interact with our practice.
We are a cash-pay functional medicine telehealth practice based in Staten Island, New York. Because we provide healthcare services, some information we handle is Protected Health Information (“PHI”) subject to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and related regulations. This Policy covers both (a) website and marketing data and (b) a high-level description of how we handle PHI. Counsel may require a separate HIPAA Notice of Privacy Practices (“NPP”) for patients; where an NPP applies, that notice controls for PHI.
By using the Site, you acknowledge this Policy. If you do not agree, please do not use the Site. Using our clinical services is governed by additional patient intake documents, telehealth consent, and (when finalized) our HIPAA NPP.
2. Who We Are & How to Contact Us
Practice name: Regulated with Loreta / The Regulated Nurse
Provider: Loreta Labode, RN (physician-supervised by Jean-Carlos Jimenez, MD)
Location: Staten Island, New York (telehealth-first)
Email: Loreta@regulatedwithloreta.com
Phone: 718-635-0514
Website: https://www.regulatedwithloreta.com
For privacy or PHI-related requests, email the address above with the subject line “Privacy Request.” We aim to respond within a reasonable time and as required by applicable law.
3. Scope — Website Data vs. Health Information
3.1 Website and marketing information
Information collected through cookies, analytics, contact forms, newsletter sign-ups, and similar Site features is generally treated as website/marketing data under this Policy and applicable consumer privacy and e-privacy rules (including cookie consent via CookieYes).
3.2 Protected Health Information (PHI)
Information you provide in connection with clinical care — including medical history, labs, diagnoses, treatment plans, messages in our EHR, and billing related to care — may be PHI. PHI is handled under HIPAA, our Business Associate Agreements (“BAAs”) with vendors where required, and our patient-facing privacy notices. Do not submit PHI through general website forms, email marketing fields, or social media DMs when a secure patient portal or designated clinical channel is available.
4. Information We Collect
4.1 Information you provide
- Contact details (name, email, phone) when you inquire or book a discovery call
- Scheduling preferences and appointment-related details through our booking/EHR tools (currently Optimantra)
- Clinical intake, health history, symptoms, goals, and related documents once you become a patient
- Payment and billing information for cash-pay services (processed by our payment processor; we do not store full card numbers on the Site)
- Communications you send us by email, phone, or patient messaging
- Newsletter or educational email sign-ups (if and when that feature is enabled)
4.2 Information collected automatically
- Device and browser type, approximate location (city/region level), referring URL, pages viewed, and timestamps
- IP address and similar technical identifiers
- Cookie and similar technology identifiers (see CookieYes consent records and Section 8)
- Aggregated analytics events via Google Analytics 4 (GA4), configured through Google Tag Manager (GTM), subject to your cookie preferences
4.3 Information from service partners
In the course of care we may receive or exchange information with laboratories and clinical vendors (for example Quest, LabCorp, and Rupa Health for labs; Fullscript for supplement fulfillment), as well as our supervising physician and other providers you authorize. Those partners process data under their own policies and, where required, under BAAs with us.
5. How We Use Information
- Provide, schedule, and improve telehealth and related practice services
- Communicate about appointments, care plans, labs, supplements, and administrative matters
- Process payments and maintain business records
- Operate, secure, and troubleshoot the Site
- Measure Site performance and marketing effectiveness using GA4/GTM in line with CookieYes consent choices
- Comply with law, respond to lawful requests, and protect rights, safety, and security
- Send educational or practice updates only where you have opted in and where permitted by law (CAN-SPAM and similar rules)
6. HIPAA & Clinical Confidentiality
We take reasonable and appropriate administrative, physical, and technical safeguards designed to protect PHI. Access to clinical systems is limited to workforce members and vendors who need it to perform their roles.
We use and disclose PHI for treatment, payment, and healthcare operations as permitted by HIPAA, and for other purposes with your authorization or as required by law (for example certain public health or legal obligations).
Patients may have rights under HIPAA to access, amend, and request restrictions or confidential communications regarding PHI, and to receive an accounting of certain disclosures. How to exercise those rights is described in our HIPAA Notice of Privacy Practices (when provided at intake or upon request). For PHI requests, contact Loreta@regulatedwithloreta.com.
We use Business Associate Agreements where required with vendors that may create, receive, maintain, or transmit PHI on our behalf (including our EHR, lab, and supplement partners as applicable).
7. How We Share Information
We do not sell your personal information for money. We may share information as follows:
- Service providers / Business Associates: EHR (Optimantra), lab ordering/results platforms (e.g., Rupa Health), supplement dispensing (Fullscript), payment processors, secure hosting, and professional advisors under appropriate contracts
- Supervising physician and care team members involved in your care
- Analytics and advertising technology: Google (GA4, GTM) and related Google properties, only as enabled by CookieYes consent settings for non-essential cookies/tags
- Legal and safety: when required by law, court order, or to protect persons from serious harm
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to applicable privacy and healthcare rules
7.1 Google tools we use
We use Google Analytics 4 to understand aggregated Site usage; Google Tag Manager to manage tags and measurement; and Google Search Console to monitor search indexing and Site performance in Google Search. Search Console is used by us as a site owner tool and does not place cookies on your browser when you visit our Site. GA4 and other tags fired via GTM may collect device/usage data when allowed under CookieYes.
Google’s use of information is further described in Google’s privacy documentation. Where required, we configure Google Consent Mode (or equivalent) so measurement tags respect CookieYes consent signals.
8. Cookies, CookieYes & Consent
We use CookieYes as our consent management platform (CMP). CookieYes displays a cookie banner/preference center, records your choices, and helps categorize cookies (for example Necessary, Analytics, Marketing).
Necessary cookies required for basic Site function may run without consent where permitted. Analytics, marketing, and similar non-essential cookies/tags (including GA4 via GTM) should load only after you consent, or as otherwise allowed by applicable law and our CookieYes configuration.
You can change or withdraw consent at any time using the CookieYes preference controls on the Site (typically via a “Cookie Settings” link or floating icon). Browser settings may also block cookies, though some Site features may not work.
We use cookie duration and categories as disclosed in the CookieYes cookie declaration on this Site. Review that declaration for the current list of cookies and vendors.
9. Retention
We retain website and marketing data only as long as needed for the purposes described above, unless a longer period is required by law. Clinical records and PHI are retained according to applicable New York and federal medical record retention requirements and our internal record-retention schedule (to be confirmed with counsel).
Analytics data retention in GA4 is configured in our Google Analytics property settings and should be reviewed periodically.
10. Security
We use reasonable safeguards designed to protect information, including HTTPS on the Site, access controls on clinical systems, and vendor due diligence. No method of transmission or storage is 100% secure. You use the Site and electronic communications at your own risk to the extent permitted by law.
11. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of certain personal information, to opt out of certain processing, or to appeal a denial. California residents may have additional rights under the CCPA/CPRA (including rights related to “sale” or “sharing” of personal information for cross-context behavioral advertising, if applicable). We do not knowingly sell personal information. Where our CookieYes/GTM configuration involves advertising cookies, you can manage preferences through CookieYes and may have additional opt-out rights under applicable law.
This practice primarily serves patients in the United States. If you are located in the EEA or UK and believe GDPR/UK GDPR rights apply to your information, contact us at Loreta@regulatedwithloreta.com and we will respond as required by applicable law.
To exercise rights regarding website data, email Loreta@regulatedwithloreta.com. To exercise HIPAA rights regarding PHI, use the process in our NPP (or contact us until the NPP is published). We may need to verify your identity before responding.
12. Children’s Privacy
The Site and our services are intended for adults. We do not knowingly collect personal information from children under 13 (or under 16 where required). If you believe a child provided information, contact us and we will take appropriate steps to delete it. Clinical care for minors, if ever offered, would require additional consent and compliance steps approved by counsel.
13. Third-Party Links & Embedded Tools
The Site may link to third-party sites or embed third-party tools (for example booking iframes, lab or supplement portals, or social media). Those services are governed by their own privacy policies. We are not responsible for their practices.
14. Location of Processing
We are based in New York, United States. Vendors such as Google and our hosting/EHR providers may process data in the United States or other countries. Where required, we rely on appropriate contractual and organizational measures.
15. Changes to This Policy
We may update this Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may be highlighted on the Site or communicated to patients as appropriate. Continued use of the Site after an update means you acknowledge the revised Policy, to the extent permitted by law.
16. Contact
Privacy questions or requests: Loreta@regulatedwithloreta.com · 718-635-0514
Mailing / practice locality: Staten Island, New York (full mailing address to be confirmed for patient notices and NPP).