Site Logotype

Privacy Policy and HIPAA Notice of Privacy Practices Summary

Effective Date: 12-31-2025


Introduction

Enigma Medi Spa & Laser Center and Enigma Plastic Surgery & Laser Center (collectively referred to as “Enigma,” “we,” “us,” or “our”) are two separate corporations that share the website https://enigmamedispa.com. Each entity independently operates its own medical and business services in Philadelphia, PA, and is responsible for handling its own patient records and data.

We are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

This Privacy Policy does not replace our separate HIPAA Notice of Privacy Practices, which governs how we use and disclose protected health information (PHI).


* AI Concierge Disclaimer:

Information provided by Nia, the Enigma AI Concierge, is intended for general guidance only and does not constitute medical, legal, or professional advice. While we strive for accuracy, responses may occasionally contain errors or omissions. For verified information or personalized recommendations, please consult a licensed Enigma provider or live representative.


Information We Collect

Personal Information

We may collect personal information that you voluntarily provide, including:

  • Contact Information: Name, email, phone number, mailing address
  • Medical Information: Health history, medications, allergies, treatment preferences, relevant medical conditions
  • Treatment Records: Procedures performed, treatment outcomes, before/after photos (with your written consent)
  • Appointment Information: Scheduling preferences, consultation notes, treatment history
  • Payment Information: Billing address and payment method details (processed securely by third-party vendors)
  • Communication Records: Emails, phone calls, and text messages exchanged with our staff

Automatically Collected Information

When you use our website, we automatically collect:

  • Technical Information: IP address, browser type, device data, operating system
  • Usage Data: Pages visited, time on site, referring websites, search terms
  • Cookies & Tracking Technologies: Data collected via cookies and web beacons. (You can manage cookies in your browser settings.)

How We Use Your Information

Medical Care & Treatment

  • Providing medical and aesthetic treatments
  • Maintaining accurate medical records
  • Coordinating care between healthcare providers
  • Following up on treatments and monitoring outcomes
  • Ensuring continuity of care

Business Operations

  • Scheduling appointments and managing calendars
  • Processing payments and billing
  • Communicating with you about treatments, appointments, or services
  • Sending appointment reminders and follow-ups
  • Providing customer service and managing patient relationships

Marketing & Communications

  • Sending promotional materials and special offers (with your consent)
  • Sharing before/after photos (with explicit written consent)
  • Responding to inquiries and feedback
  • Improving our services based on patient input

Communication Privacy

Enigma Medi Spa & Laser Center and Enigma Plastic Surgery & Laser Center are committed to protecting the privacy of all communications with our clients and patients.

We use secure and compliant systems to communicate via phone, SMS text message, and email for appointment-related and service-related purposes.

All communications adhere to HIPAA, TCPA, and CTIA requirements and include the following safeguards:

  • We only send text or email messages to individuals who have provided explicit written consent.
  • You may opt out of promotional or marketing texts anytime by replying STOP, or from emails by clicking Unsubscribe.
  • Appointment-related notifications (confirmations, reminders, rescheduling) may continue as part of essential healthcare communication unless you specifically request otherwise.
  • Message and data rates may apply depending on your carrier.
  • All messages are transmitted using secure, encrypted systems to prevent unauthorized access or disclosure.
  • We do not sell, rent, or share your contact information with third parties for marketing purposes.
  • Our messaging platforms are routinely audited for HIPAA and TCPA compliance to maintain data protection and confidentiality.

Legal & Regulatory Compliance

  • Complying with healthcare laws and regulations
  • Responding to legal requests and preventing fraud
  • Protecting our rights and the rights of others

Information Sharing & Disclosure

Healthcare Providers

  • Licensed medical professionals involved in your care
  • Referring physicians or specialists as part of your treatment plan
  • Accredited healthcare facilities providing related services

Service Providers

  • Third-party vendors who assist with scheduling, payments, IT, or marketing (under confidentiality agreements)
  • Professional consultants such as legal, accounting, or compliance advisors

Legal Requirements

  • When required by law, subpoena, or court order
  • To protect patient, staff, or public safety
  • To prevent fraud or illegal activity

Business Transfers

  • In connection with a merger, acquisition, or asset sale (with proper confidentiality protections)

Data Security

We implement administrative, technical, and physical safeguards to protect your information, including:

  • Secure data storage and encrypted transmissions
  • Staff access controls and authentication
  • Regular cybersecurity audits and updates
  • HIPAA compliance for all protected health information
  • Secure disposal of paper and electronic records

Your Rights & Choices

Access & Correction

  • Request access to or correction of your personal information
  • Update your contact or communication preferences

Communication Preferences

  • Opt out of marketing messages at any time
  • Specify your preferred method of contact
  • Request removal from promotional lists

Medical Records

  • Request copies of your medical records (subject to law)
  • Request amendments or an accounting of disclosures

Data Portability

  • Request electronic copies of your data in a standard format

Cookies & Tracking

We use cookies to:

  • Remember your preferences
  • Analyze site traffic and performance
  • Deliver relevant content and ads
    You can disable cookies in your browser settings (may affect functionality).

Third-Party Links

Our website may contain links to third-party sites not controlled by us. Please review their privacy policies before submitting personal information.


Children’s Privacy

Our services are intended for adults 18 and older. We do not knowingly collect data from minors without parental consent. If such data is discovered, it will be deleted immediately.


California Privacy Rights (CCPA)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how it is used
  • Request deletion of your personal data (subject to legal exceptions)
  • Opt out of the sale of your personal data (we do not sell personal data)
  • Exercise your rights without discrimination

Changes to This Policy

We may update this Privacy Policy periodically. Updates will be posted on our website and may also be communicated via email or in-office notice.


Contact Us

Enigma Plastic Surgery & Laser Center
1520 Locust Street
Philadelphia, PA 19102
Phone: 215-717-7117
Email: info@enigmamedispa.com

Enigma Medi Spa & Laser Center
10767 Bustleton Avenue
Philadelphia, PA 19116
Phone: 215-717-7000
Email: enigmamedispa@gmail.com

For medical record or HIPAA-related inquiries, please contact our Privacy Officer at either office.


HIPAA NOTICE OF PRIVACY PRACTICES (NPP) SUMMARY

Your Privacy Rights

At Enigma Medi Spa & Laser Center and Enigma Plastic Surgery & Laser Center, we are dedicated to safeguarding your Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA).

This summary explains how we may use and share your PHI and your rights regarding that information.


How We Use & Share Your Information

We may use and share your PHI for the following purposes:

  • For Treatment: To provide you with medical or aesthetic services and coordinate care among providers.
  • For Payment: To bill for services and process insurance or other payments.
  • For Healthcare Operations: For internal functions such as quality assessments, staff training, and compliance audits.
  • As Required by Law: For public health reporting, regulatory oversight, or court orders.

We will not use or share your PHI for marketing or research without your written authorization.


Your Rights Regarding Your Health Information

You have the right to:

  • Access Your Records: Obtain copies of your medical records.
  • Request Corrections: Ask us to correct inaccurate or incomplete data.
  • Request Confidential Communications: Ask us to contact you at a specific address or number.
  • Restrict Disclosures: Request limitations on how your data is used or shared (subject to legal exceptions).
  • Get a List of Disclosures: Receive an accounting of non-treatment or non-payment disclosures.
  • Receive a Copy of This Notice: Request a copy at any time.

Our Responsibilities

  • We are required by law to maintain the privacy and security of your PHI.
  • We will notify you promptly in the event of a data breach involving your information.
  • We will adhere to the practices outlined in this notice and the full HIPAA Privacy Policy.

Questions or Complaints

If you believe your privacy rights have been violated, you may contact our Privacy Officer at:

Enigma Plastic Surgery & Laser Center
1520 Locust Street, Philadelphia, PA 19102
Phone: 215-717-7117

Enigma Medi Spa & Laser Center
10767 Bustleton Avenue, Philadelphia, PA 19116
Phone: 215-717-7000

You may also file a complaint with the U.S. Department of Health and Human Services (HHS).
We will not retaliate against you for filing a complaint.


Full Notice Available

This summary provides an overview. Our full HIPAA Notice of Privacy Practices is available upon request at any of our locations or via email.

Call or Text NIA
MedSpa Concierge*
English + Español