Privacy Policy

Raíces Holistic Psychiatry Last Updated: April 2026

Nubia Chong, MD, A Professional Corporation, doing business as Raíces Holistic Therapy and Psychiatry ("Raíces," "we," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, protect, and disclose your information through our website at drnubia.com and in connection with services provided to you.

---

Notice of Privacy Practices (HIPAA)

Your privacy and dignity are deeply respected at Raíces. This notice explains how your health information may be used or shared and outlines your rights under the Health Insurance Portability and Accountability Act (HIPAA).

Confidentiality & Its Limits

All information you share with us is held in confidence and treated with deep care. We are committed to creating a space that feels safe, supportive, and honoring of your privacy.

Because of our role as a licensed provider, there are a few legal exceptions to confidentiality. We are a mandated reporter, which means we are required to break confidentiality only in specific situations, such as:

- If there is a serious and imminent risk of harm to yourself or someone else

- If we become aware of abuse or neglect involving a child, elder, or dependent adult

- If we are ordered by a court to release specific information

Whenever possible, we will do our best to speak with you first if one of these situations arises, so that you are not caught off guard. In addition, we may need to communicate with your family doctor and/or referring doctor as deemed necessary for your care.

How Your Information May Be Used or Shared

Your Protected Health Information (PHI) may be used or disclosed in the following situations:

- To provide, schedule, or manage psychiatric or wellness services

- To send appointment updates, reminders, or confirmations

- To support your care — for example, when coordination with another provider or emergency services is needed for your well-being

- To meet legal requirements, such as a court-ordered release of records

- To protect your safety and/or the safety of others

- To process billing and payment

- For administrative needs such as legal, transcription, or auditing services — always with signed confidentiality agreements in place

Sensitive information, such as psychotherapy notes, HIV status, or substance use history, will not be shared without your written consent, unless required by law.

We will never sell your data or share your information for marketing or promotional purposes.

Third-Party Service Providers (Business Associates)

We use the following HIPAA-compliant third-party platforms that may handle your PHI on our behalf. Each has entered into a Business Associate Agreement (BAA) with us:

- IntakeQ — our electronic health record, scheduling, and patient portal platform.

- Google Workspace — our secure email platform

These providers are contractually required to protect your information in accordance with HIPAA.

Your Rights Under HIPAA

You have the right to:

- Know what PHI we collect and why

- Access or request deletion of your PHI

- Receive a copy of your records

- Request corrections to your PHI

- Request how and where you receive communications (e.g., by email only or at a preferred address)

- Limit what PHI is shared and with whom

- Request a list of disclosures

- Designate someone to act on your behalf (e.g., legal guardian or healthcare proxy)

- Revoke previous permissions at any time

- File a complaint with the U.S. Department of Health and Human Services or the applicable state authority, without fear of retaliation

To learn more or file a complaint, visit: hhs.gov/ocr/privacy/hipaa/complaints

Note: You will receive a full HIPAA Notice of Privacy Practices and consent form as part of your intake paperwork.

---

Website Privacy Policy

Information We Collect

When you visit drnubia.com, we may collect the following:

Information you provide directly:

- Your name, email address, phone number, and any message content submitted through our contact form

- Any other information you choose to share when reaching out to us

Information collected automatically:

- Basic usage data such as pages visited and time spent on the site, collected through Squarespace's built-in analytics

- Cookies and similar tracking technologies used by Squarespace to support website functionality and performance (see Cookies section below)

How We Use Your Information

Information submitted through our contact form is used solely to respond to your inquiry and, if applicable, to schedule an initial consultation. We do not use your contact information for marketing purposes or share it with third parties for any commercial purpose.

Cookies

Our website is hosted on Squarespace, which uses cookies to support basic website functionality, analytics, and performance. Cookies are small text files stored on your device. You may adjust your browser settings to refuse cookies, though some site features may not function properly as a result.

We do not use advertising cookies or third-party tracking cookies for marketing purposes.

Third-Party Website Services

Our website is built and hosted on Squarespace. Squarespace may collect certain data as part of their platform. You can review Squarespace's privacy policy at squarespace.com/privacy.

Contact Form Data Retention

Information submitted through our contact form is retained only as long as necessary to respond to your inquiry or establish care. If you do not become a patient, your contact information is not retained beyond that initial communication.

---

Medical Records Retention

In accordance with California law, medical records are retained for a minimum of seven (7) years from the date of service, or seven (7) years after a minor patient reaches the age of 18, whichever is later.

California Residents — Your Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to:

- Know what personal information we collect about you

- Request deletion of your personal information

- Opt out of the sale of your personal information (we do not sell personal information)

- Not be discriminated against for exercising your privacy rights

To exercise these rights, please contact us at contact@drnubia.com.

Children's Privacy

Our website is not directed at children under the age of 13, and we do not knowingly collect personal information from children without verifiable parental consent.

Data Security

We take reasonable technical and administrative measures to protect your information. Our email is hosted on Google Workspace, which is encrypted and covered under a HIPAA Business Associate Agreement. Our patient portal is hosted on IntakeQ, which is similarly HIPAA-compliant. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page. We encourage you to review this policy periodically.

Contact Us

If you have any questions about this Privacy Policy or your privacy rights, please contact us at:

Raíces Holistic Therapy & Psychiatry

contact@drnubia.com

drnubia.com