Salus

Privacy Policy

Salus Clinical PLLC  ·  Effective July 21, 2026  ·  Version 2.1

If you are experiencing a medical emergency, call 911 immediately. Do not use this website or any Salus messaging channel to report an emergency.

Important: Our Notice of Privacy Practices is a separate document that governs how medical information about you is used and disclosed in connection with health care services under the Health Insurance Portability and Accountability Act (“HIPAA”) and the Texas Medical Records Privacy Act. This Privacy Policy does not replace it.

1. Introduction

Salus Clinical PLLC (“Salus,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy describes the information we collect from and about visitors to www.salusclinical.com (the “Site”), prospective and current members, candidates for employment, and others with whom we interact, and explains how that information is used, disclosed, and protected.

By using the Site or submitting information to us, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, do not use the Site and do not submit information to us.

References in this Privacy Policy to the “Site” include any member portal or application we make available.

This Privacy Policy should be read together with our Terms of Use, which govern your use of the Site and contain provisions regarding dispute resolution and limitations of liability. Precedence between the two documents is determined by subject matter: this Privacy Policy controls on questions of privacy and the handling of personal information, and the Terms of Use control on questions of your use of the Site, dispute resolution, disclaimers of warranties, limitations of liability, and indemnification. The order of precedence among all of our member-facing documents is set out in Section 3 of the Terms of Use.

2. No Physician-Patient Relationship; No Medical Advice

Use of the Site, receipt of our communications, and interaction with us on social media do not establish a physician-patient relationship. That relationship is established only upon acceptance of membership, execution of the applicable clinical agreements and consents, and commencement of clinical evaluation by a licensed clinician.

Information published on the Site or provided through our communications is general in nature, is not medical advice directed to any individual, and should not be relied upon in place of consultation with a qualified health care professional. We make no representation that any test, protocol, intervention, or service is safe, appropriate, or effective for any particular person. Always consult an appropriate health care professional regarding your individual circumstances.

3. Scope and Our Status as a Healthcare Provider

Salus Clinical PLLC is a professional limited liability company organized under the laws of the State of Texas for the practice of medicine. Clinical services are furnished by physicians and other clinicians independently licensed in the jurisdictions in which they practice, and clinical judgment is exercised solely by those licensed clinicians and is not directed by any non-clinical person or entity.

We handle medical information in accordance with the Texas Medical Records Privacy Act (Texas Health and Safety Code Chapter 181), the confidentiality obligations of the Texas Medical Practice Act, and HIPAA where it applies to a particular record or transaction. As a matter of practice, we apply HIPAA-equivalent privacy and security standards to all clinical information we hold, whether or not a specific record is subject to HIPAA, and we maintain a privacy and security program that includes a Notice of Privacy Practices, written agreements with vendors that handle medical information, workforce privacy training, and assigned internal responsibility for privacy and security oversight.

This Privacy Policy governs information collected through the Site, through marketing and membership inquiry channels, and through our administrative and business operations. It applies principally to information that is not protected health information, including information collected from prospective members before a clinical relationship is established.

This Privacy Policy does not govern:

4. Information We Collect

For purposes of this Privacy Policy, “personal information” means information that identifies, relates to, describes, or could reasonably be linked with a particular individual.

You are not required to provide any information we request. Declining to do so may limit what we are able to do for you, including our ability to evaluate a membership application or deliver certain services.

4.1 Information You Provide

Information you provide before or outside of a clinical relationship may relate to your health status, goals, or interests without constituting PHI. Certain state statutes classify this as consumer health data, and Section 9.4 describes the commitments applicable to it.

4.2 Genetic, Epigenetic, Biometric, and Wearable Information

Our services may involve genomic sequencing, epigenetic analysis, multi-omic profiling, continuous physiologic monitoring, advanced imaging, and functional and body composition assessment. You may also elect to share health and activity information from third-party devices and applications, including continuous glucose monitors, wearable trackers, and platforms such as Apple Health. Information derived from these sources is treated as sensitive information in every context in which we handle it.

We collect, process, and retain this information only pursuant to your separate, express, written authorization, which will identify the specific information involved, the purposes of processing, the categories of recipients, and the retention period.

Where a service involves capture of a biometric identifier as defined by Texas Business and Commerce Code Section 503.001, including a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry, we obtain your informed consent before capture, do not sell, lease, or otherwise disclose the identifier except as that statute permits, and destroy it within a reasonable time and no later than one year after the purpose for collection expires. You may withdraw that authorization prospectively at any time, and you may discontinue device and application sharing through the settings of the relevant device, application, or portal. We do not use such information for advertising, and we do not sell it or share it for cross-context behavioral advertising.

4.3 Information Collected Automatically

We and our service providers collect IP address and derived approximate location; device, operating system, and browser characteristics; pages viewed, links clicked, and session behavior; and date, time, diagnostic, and error information. Section 7 describes the technologies used and your choices.

4.4 Information from Social Media

If you interact with us on a social media platform, we may see and use information you make available there, and your account name may be visible to others who view our accounts. Social media platforms operate independently of Salus, and we are not responsible for their practices or for information you choose to post. Do not post health information about yourself on social media in an attempt to communicate with us.

4.5 Information from Third Parties

We may receive information from referring clinicians, laboratories and diagnostic vendors, family offices and advisors who refer you with your authorization, payment processors, screening vendors in connection with employment applications, and publicly available sources.

4.6 Unsolicited Information

Do not send us information we have not requested. Detailed clinical information, diagnoses, medication lists, laboratory results, or images transmitted through public contact forms or unencrypted email are submitted at your own risk and without any expectation of confidentiality beyond what applicable law independently requires. We may delete unsolicited submissions without review. Such a submission creates no obligation on our part and does not establish a clinical relationship.

4.7 Accuracy

You are responsible for the accuracy and completeness of information you provide and for updating it when it changes. We may rely on that information without independent verification except where verification is clinically or legally required, and Salus is not responsible for consequences arising from information you have supplied that is inaccurate, incomplete, or outdated.

5. How We Use Information

We process personal information based on your consent, performance of a contract with you, compliance with legal obligations, and our legitimate interests in operating, securing, and improving our services. Sensitive information, including health, genetic, and biometric information, is processed only with your consent except where processing without consent is expressly permitted or required by law, including for treatment, payment, and healthcare operations under HIPAA.

We use information to:

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use consumer health data, genetic information, or biometric information for advertising or for profiling in furtherance of decisions producing legal or similarly significant effects.

5.1 De-Identified and Aggregated Information

We may create de-identified or aggregated information, applying the HIPAA de-identification standards where PHI is involved. We maintain it in de-identified form, do not attempt to reidentify it, and contractually obligate any recipient to refrain from reidentification. De-identified and aggregated information is not personal information and may be used and disclosed for any lawful purpose, including research, benchmarking, and publication.

6. How We Disclose Information

We disclose information only as follows:

We do not disclose information to data brokers, and we do not permit service providers to use your information for their own marketing purposes.

Where lawful and practicable, we will notify you before disclosing information in response to legal process so that you may seek protective relief. We are not obligated to challenge process on your behalf, and we may comply with facially valid process without notice where notice is prohibited or would impede an investigation or create a risk of harm.

7. Cookies, Analytics, and Tracking Technologies

We do not deploy third-party advertising pixels, social media pixels, or advertising network tags on membership application pages, intake forms, member portal pages, or any page on which health information may be entered or displayed, and we do not transmit information entered into forms to advertising platforms. Analytics on informational pages are configured with IP anonymization where the vendor supports it, and analytics vendors are engaged under contracts restricting them to service provider roles.

Strictly necessary technologies support security, session management, load balancing, and core Site function and cannot be disabled. Performance and analytics technologies measure Site usage in aggregate. Functional technologies remember preferences. These include first-party and third-party cookies, session and persistent cookies, web beacons, software development kits, and server logs.

We recognize and honor the Global Privacy Control browser signal as a valid opt-out of sale and of sharing for targeted advertising where applicable law provides for such treatment. Because no uniform standard governs browser “Do Not Track” signals, we do not respond to them.

8. Your Choices

9. Your Privacy Rights

9.1 Rights Generally Available

Subject to Sections 9.5 and 9.6, you may request access to personal information we hold about you, request correction of inaccuracies, request deletion, obtain a portable copy where applicable law provides for one, opt out of marketing communications, and withdraw a previously granted authorization on a prospective basis.

Withdrawal of authorization does not affect the lawfulness of prior processing, does not require deletion of information we are obligated or permitted to retain, and may result in our inability to continue providing services.

9.2 Texas Residents

Under the Texas Data Privacy and Security Act, Texas residents hold the rights described in Section 9.1 and may opt out of processing for targeted advertising, sale, or profiling in furtherance of decisions producing legal or similarly significant effects.

9.3 California Residents

This section applies to California residents under the California Consumer Privacy Act as amended (“CCPA”). PHI governed by HIPAA and medical information governed by the California Confidentiality of Medical Information Act are exempt from the CCPA, and requests concerning that information are handled under the applicable health privacy framework.

In the preceding twelve months we have collected the following categories of personal information and disclosed them for business purposes to the categories of recipients indicated.

CategoryExamplesDisclosed To
IdentifiersName, postal address, email address, telephone number, IP address, account identifiersCloud, hosting, and IT providers; practice management and records platforms; payment processors; professional advisors
Customer records information (Cal. Civ. Code 1798.80(e))Name, address, telephone number, financial account information, employment informationCloud, hosting, and IT providers; payment processors; professional advisors
Protected classification characteristicsAge, date of birth, sexCloud, hosting, and IT providers; practice management and records platforms
Commercial informationMembership tier, invoices, payment history, services considered or receivedCloud, hosting, and IT providers; payment processors; professional advisors
Internet or network activityPages viewed, session behavior, referring pagesCloud and hosting providers; analytics providers acting as service providers
Geolocation dataApproximate location derived from IP addressCloud and hosting providers; analytics providers acting as service providers
Sensory informationVoicemail and call recordings where madeCloud, hosting, and telecommunications providers
Professional or employment informationResumes, licensure, credentialing, referencesCloud and hosting providers; screening vendors; professional advisors
Sensitive personal informationHealth information, genetic information, biometric information, account credentials, financial account informationPractice management and records platforms; laboratories and diagnostic partners with your authorization

We have not sold personal information and have not shared personal information for cross-context behavioral advertising in the preceding twelve months. We do not use or disclose sensitive personal information for purposes beyond those permitted under the CCPA without limitation rights, and we do not use it to infer characteristics.

California residents may request to know the categories and specific pieces of personal information collected, the sources, the business purposes, and the categories of recipients; may request correction and deletion; may request a portable copy; and may limit the use and disclosure of sensitive personal information. We do not discriminate against individuals for exercising these rights, including by denying services, charging different prices, or providing a different level of service.

Shine the Light. California Civil Code Section 1798.83 permits California residents to request information about disclosures of personal information to third parties for those third parties’ direct marketing purposes. We do not make such disclosures.

9.4 Consumer Health Data

For residents of states with dedicated consumer health data statutes, including Washington, Nevada, and Connecticut, we collect consumer health data only for the purposes in Section 5 and with consent where required; we do not sell it and will not do so absent a separate signed authorization meeting statutory requirements; we do not use geofencing around any healthcare facility to identify, track, or advertise to individuals; and internal access is limited to personnel whose function requires it.

9.5 Exceptions

We may decline a request, in whole or in part, where the information is exempt from the applicable statute; where retention is required by medical recordkeeping, financial, tax, audit, or insurance obligations; where necessary to complete a transaction you requested or to detect or prevent fraud or security incidents; where the information is subject to legal hold or is reasonably anticipated to be relevant to actual or threatened litigation, investigation, or regulatory inquiry; where deletion would impair the rights of another individual; or where the information is de-identified or aggregated. Where we decline, we will state the basis and act on any portion not subject to the exception.

9.6 Verification, Abuse, and Timing

We will verify your identity before acting, using information already in our possession and, where necessary, additional verification proportionate to the sensitivity of the information requested. Verification information is used only for that purpose, and we may decline requests we cannot verify. An authorized agent may submit a request with written authorization, and we may contact you directly to confirm. We may describe rather than produce certain categories of information, including government identification numbers, financial account numbers, and account credentials, where production would create security risk.

We may decline or charge a reasonable fee for requests that are manifestly unfounded, excessive, or repetitive, including more than two substantive requests in any twelve-month period from the same individual, and for requests submitted through automated means or in bulk on behalf of individuals who have not authorized them.

Submit requests to privacy@salusclinical.com with the subject line “Privacy Request,” including your name, email address, mailing address, telephone number, and a description of your request. We respond within forty-five days, extendable once by an additional forty-five days where reasonably necessary, with notice to you. Requests for your medical records are handled separately and more quickly: we provide records within fifteen business days of a written request, as required by Texas law, subject to the limited grounds for withholding that Texas and federal law permit. If we deny a request, you may appeal by writing to the same address with the subject line “Privacy Appeal,” describing why you believe the determination was incorrect, and we will respond within sixty days. If the appeal is denied, we will provide instructions for contacting the Texas Attorney General or the attorney general of your state of residence.

10. Data Security

We maintain an information security program with administrative, physical, and technical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Measures include encryption in transit and at rest; role-based access control, least-privilege provisioning, and periodic access review; multi-factor authentication for administrative and clinical systems; network segmentation and endpoint protection; logging and monitoring; vendor security diligence and contractual security obligations; workforce privacy and security training; a written and periodically tested incident response plan; and periodic risk assessment consistent with the HIPAA Security Rule.

No method of transmission or storage is completely secure. We do not warrant, guarantee, or represent that personal information will remain free from unauthorized access, and we expressly disclaim any such warranty. Our obligation is to maintain safeguards that are reasonable and appropriate under applicable law, not to achieve a particular outcome. To the fullest extent permitted by law, Salus is not liable for unauthorized access resulting from circumstances beyond our reasonable control, including your own disclosure of credentials, compromise of your devices or accounts, or the acts of third parties.

You are responsible for safeguarding any credentials issued to you, for limiting access to your devices, and for notifying us promptly of suspected unauthorized use. Do not share credentials with anyone not authorized to access your account. Communications sent through unencrypted email or SMS may be intercepted, and by electing those channels you accept that risk.

In the event of a breach of unsecured personal information, we will notify affected individuals without unreasonable delay and no later than sixty days after determining that a breach occurred, consistent with the Texas Identity Theft Enforcement and Protection Act, and will notify the Texas Attorney General where a breach affects two hundred fifty or more Texas residents. Where a breach involves protected health information, we will also provide the notifications required by the HIPAA Breach Notification Rule. Where a breach involves identifiable health information drawn from a personal health record, wearable, or health application and is not subject to HIPAA, we will provide the notifications required by the FTC Health Breach Notification Rule. Notification is not an admission of fault or liability.

11. Data Retention

We retain personal information only as long as necessary for the purposes in this Privacy Policy or as required by law, considering the nature and sensitivity of the information, the risk of harm from unauthorized use, and applicable limitation periods. Medical records are retained in accordance with Texas Medical Board requirements and other applicable law, and financial records in accordance with tax, audit, and insurance requirements. Inquiry and marketing information is retained for no longer than twenty-four months following the last interaction unless a relationship has been established. Candidate information is retained for twelve months following a hiring decision unless you consent to longer retention.

We also retain information for the duration of any legal hold and for the applicable statute of limitations where it is reasonably anticipated to be relevant to actual or threatened litigation, investigation, regulatory inquiry, or the establishment or defense of legal claims. When retention is no longer required, we delete or de-identify the information. Deletion from active systems may not immediately remove information from backup or archival media, which is overwritten in the ordinary course.

12. Text Messaging

If you provide a mobile number and consent to text messaging, you may receive appointment, scheduling, and service messages. Message and data rates may apply, and you may opt out by replying STOP or by contacting us. Consent to text messaging is never a condition of receiving services. Mobile numbers and messaging consent are not shared with third parties for their marketing purposes. We may continue to send transactional and administrative messages after a marketing opt-out.

13. Third-Party Sites and Platforms

The Site may link to or embed third-party websites, features, and interactive tools. When you provide information to those services, you are providing it to the third party and not to Salus. We do not control those services, do not endorse them by linking to them, and are not responsible for their content, security, or privacy practices. Review their policies before providing information.

14. Children

The Site is directed to adults and is not intended for individuals under eighteen. We do not knowingly collect personal information from individuals under thirteen through the Site. Where clinical services are provided to a minor, information is collected from a parent or legal guardian in a clinical setting under the Notice of Privacy Practices. If you believe a child has provided information through the Site, contact us and we will delete it.

15. Jurisdiction and Location of Processing

The Site is directed to residents of the United States, and information is processed and stored in the United States. If you access the Site from outside the United States, you do so on your own initiative and are responsible for compliance with local law. We do not currently offer services in the European Economic Area, the United Kingdom, or Switzerland, and this Privacy Policy does not address the General Data Protection Regulation.

16. General Provisions

Changes. We may modify this Privacy Policy at any time and will post the revised version with an updated effective date. Material changes will be preceded by notice by email or prominent Site notice, and where applicable law requires consent to a change, we will obtain it before applying the change to information already collected. Continued use of the Site after the effective date constitutes acknowledgment of the revised Privacy Policy.

No contract; no third-party beneficiaries. This Privacy Policy is a disclosure of practices. It does not constitute a contract, does not create rights or remedies beyond those independently provided by applicable law, and creates no third-party beneficiary rights. Legal rights and obligations between you and Salus are governed by the Terms of Use and by any written agreement you have executed with us.

Governing law and venue. This Privacy Policy and any dispute concerning it are governed by the laws of the State of Texas without regard to conflict-of-laws principles, except that nothing in this provision limits or waives any right, protection, or remedy afforded to you under the health privacy, medical records, or consumer protection laws of your state of residence, which apply to the extent they cannot lawfully be waived by agreement. Subject to any binding arbitration provision in the Terms of Use, venue lies exclusively in the state or federal courts located in Travis County, Texas, and you consent to personal jurisdiction there.

Severability and no waiver. If any provision is held unenforceable, it will be modified to the minimum extent necessary or severed, and the remainder will continue in full effect. Our failure to enforce a provision is not a waiver of it.

Interpretation and accessibility. Headings are for convenience only, “including” means “including without limitation,” and the English version controls over any translation. If you require this Privacy Policy in an alternative format, contact us and we will provide one at no charge.

17. Contact Us

Salus Clinical PLLC
Attn: Legal Department
100 Congress Avenue
Austin, Texas 78701

Legal, privacy and disputes: legal@salusclinical.com

For matters concerning protected health information, contact us using the information above or the privacy official identified in our Notice of Privacy Practices. You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights. We will not retaliate against any individual for filing a complaint or exercising a privacy right.

← Return to Salus