Privacy policy
Last updated 28 September 2026
This policy covers this website. The short version: the site itself collects nothing about you, sets no cookies of its own, and runs no analytics or tracking of any kind.
What this policy covers
This policy describes how the MyOrthoSpineMD website handles information. It does not describe how the practice handles your medical records once you are a patient — that is covered by the practice’s Notice of Privacy Practices , a separate document provided under federal health privacy law. Ask the office for a copy.
What this website collects
Nothing. There is no analytics software on this site, no tag manager, no advertising or tracking pixels, and no social media trackers. The site sets no cookies of its own and stores nothing in your browser’s local storage.
Every page is a static file. The website itself has no database and never receives what you type: the request form sends it from your browser straight to the practice, as described below.
When you send us a request
The request form asks who is contacting us, your first and last name, your phone number, your email address, and anything you choose to write in the message box. You decide what to put in that box; it may include health information. Please keep payment details out of it — card numbers have no reason to be there and we will never ask for one this way.
When you send it, your browser sends it directly to the practice’s own environment with a cloud provider. It does not pass through this website, this website never sees it, and the company that hosts these pages never receives it. Nothing you type is written to a log here, sent to any analytics service, or kept in your browser.
Stored with it are four things you did not type: the time it arrived, which language the page was in, so that whoever calls you back knows which language to speak, which of the practice’s websites you sent it from, and — if you reached us from an advertisement we placed — which one, so the practice knows whether it was worth placing. That last one says nothing about you: it is a marker in the address of the page, the same for everybody who arrives that way, and it is never sent back to the advertiser. Nothing else about you or your visit — not your IP address, not your browser, not the page you were reading when you opened the form. Later, when someone at the practice has dealt with your request, a note is added to the same record saying so and who did it.
The practice has a Business Associate Agreement with that provider — the contract federal health privacy law requires of a company that stores protected health information on a practice’s behalf. Your request is stored encrypted in that environment, only the practice can open it, and each time it is opened is recorded. No other company receives it, and it is not sent anywhere that is not covered by such an agreement.
We normally send a short confirmation to the email address you give, so that you know the request arrived. If one does not reach you, the request still arrived — nothing about it depends on that message. It travels by ordinary email, which is not protected the way the rest of this is — so it carries nothing from your request. Not your name, not your phone number, and nothing about your symptoms. It says only that a request was received, when to expect a call, and what to do if your symptoms get worse before then.
What you send this way reaches the practice and is handled as part of your care, under the Notice of Privacy Practices .
If you would rather not use the form, call 404-820-2020.
How your request is protected
The principle is that the fewer places your information goes, the fewer places it can go wrong. In practice that means five things.
- Encrypted both ways. It travels over an encrypted connection and is stored encrypted. It is not written to a log on the way, and no copy is kept in your browser.
- Held behind a sign-in. Your request is kept in a system that takes a password and then a second step — a one-time code, separate from the password — to open. Every opening there is recorded: who, and when.
- Your message stays there. When a request arrives the practice is told, so that somebody knows to look. What you wrote is never in that notice. The description of what happened to you is read inside the system above and nowhere else.
None of this makes a system impossible to break into, and we would rather say so than imply otherwise. What it does is close the ordinary ways information leaks: a third-party script on the page, an analytics trail, a list left open on a screen where anyone can read it.
How long your request is kept
It stays in that environment until someone at the practice removes it. Nothing deletes it on a timer, because when a request has served its purpose is a judgement for the practice to make rather than a date to set in advance.
If you would rather yours were not kept — you sent it and then chose another practice, for example — call the office and say so. If you go on to become a patient, what you sent becomes part of your medical record, and how long records are kept, and what you can ask about them, is governed by law and described in the Notice of Privacy Practices .
Third parties this site involves
There are three, and that is the complete list.
- Our cloud provider. It receives the request form and stores it for the practice, under the Business Associate Agreement described above. It hears from your browser only when you send a request — never while you are reading. Like any service on the internet it sees the network address the request comes from; that address is not stored with your request and the practice never sees it.
- Our hosting provider. Like any web host, it processes standard server request records — your IP address, the page requested, your browser type — to serve the site and keep it secure. We do not use these to build any profile of you. It never receives anything you type into the request form.
- Google Maps. Only as outbound links. The “Directions” links open Google Maps in a new tab; no map is embedded in these pages, so nothing loads from Google unless you click.
Typefaces are served from this site’s own domain, so no request for fonts reaches any third party.
What we send when you leave this site
Some pages here name a symptom in their address. When your browser follows a link or opens the request form, this site instructs it to send only the site’s address and never the specific page you were reading. In practice that means opening the form does not tell anyone which symptom page you came from.
Children
This site is intended for adults. It is not directed at children and does not knowingly collect information from anyone under 13. Where a parent or guardian is arranging care for a minor, that is handled through the practice in the usual way.
Changes to this policy
If the site changes in a way that affects this policy — adding analytics, for example, or handling forms directly — this page will be updated and the date at the top will change.
Contact
Questions about this policy, or about the information the practice holds about you:
MyOrthoSpineMD, P.C.
3280 Pointe Pkwy NW, Suite 2550
Norcross, GA 30092
404-820-2020
info@myorthospinemd.com
Please don’t send medical details by email. Ordinary email isn’t secure, and that address is for questions about this policy rather than about your care. For anything clinical, call the office or use the request form.
See also our terms of use and contact details.