Legal
Privacy Policy
Last updated: 2026
HIPAA Compliance & Protected Health Information (PHI)
Regen Wellness Center is committed to maintaining the privacy and security of your health information in accordance with the Health Insurance Portability and Accountability Act (HIPAA) and international healthcare privacy standards. Protected Health Information (PHI) includes any information that can identify you and relates to your past, present, or future health condition, treatment, or payment for healthcare services. We handle all patient health information with the highest standards of confidentiality and security.
Information We Collect
Regen Wellness Center collects personal and health information submitted through our application process solely for the purpose of clinical pre-qualification and program coordination. This includes: name, contact information, date of birth, country of residence, comprehensive health history, current medications, previous medical treatments, laboratory results, imaging studies, insurance information (if applicable), and program objectives. All PHI is collected through secure, encrypted channels and stored in HIPAA-compliant systems.
How We Use Your Information
All information submitted through our application is reviewed exclusively by the medical director's office and authorized clinical staff for the purpose of: evaluating clinical candidacy, designing individualized treatment protocols, coordinating medical care, processing payments, complying with legal and regulatory requirements, and improving the quality of our medical services. We do not use your information for marketing, profiling, or third-party commercial purposes without your explicit consent.
Information Sharing & Disclosure
We do not sell, share, or disclose personal or health information to any third party without your explicit written authorization, except in the following circumstances: (1) Treatment coordination with your primary care physician or other healthcare providers with your consent; (2) Business associates who provide services on our behalf and who have signed Business Associate Agreements (BAAs) ensuring HIPAA compliance; (3) Legal obligations under applicable law, court orders, or regulatory requirements; (4) Medical emergency circumstances where disclosure is necessary to prevent serious harm. Any third-party service provider with access to PHI operates under strict contractual obligations to maintain confidentiality and security.
Data Security & Technical Safeguards
All patient data is transmitted and stored using industry-standard encryption protocols. Data in transit is protected using TLS 1.2 or higher encryption. Data at rest is encrypted using AES-256 encryption standards. Access to patient application data and medical records is restricted to the medical director's office and authorized clinical staff operating under signed confidentiality agreements. Our systems employ multi-factor authentication, role-based access controls, and comprehensive audit logging. We conduct regular security assessments and maintain documented security policies and procedures. All staff undergo annual HIPAA privacy and security training.
Business Associate Agreements
Any third-party service provider that processes, stores, or transmits PHI on our behalf is required to sign a Business Associate Agreement (BAA) that obligates them to: implement appropriate safeguards to protect PHI, report any security incidents or breaches, restrict use and disclosure of PHI to only what is necessary, and comply with all applicable HIPAA regulations. Our current and planned service providers include HIPAA-compliant healthcare technology platforms that have executed BAAs with Regen Wellness Center.
Your Rights Under HIPAA
As a patient or prospective patient, you have the following rights regarding your health information: (1) Right to Access: Request copies of your medical records and PHI; (2) Right to Amend: Request corrections to inaccurate or incomplete information; (3) Right to Accounting of Disclosures: Receive a list of certain disclosures of your PHI; (4) Right to Request Restrictions: Request limitations on how we use or disclose your PHI; (5) Right to Confidential Communications: Request to receive communications in a specific manner or location; (6) Right to a Paper Copy of this Notice: Request a printed copy of this privacy policy. To exercise any of these rights, contact our Privacy Officer through the administrative office.
Data Retention & Disposal
Application data for applicants who do not advance to evaluation is retained for 12 months and then securely deleted in accordance with HIPAA-compliant disposal procedures. Complete medical records for enrolled patients are retained for a minimum of seven (7) years following the last date of service, or longer if required by applicable law or ongoing medical necessity. Upon expiration of the retention period, all PHI is destroyed using secure methods that render it unrecoverable, including digital shredding of electronic records and physical destruction of paper documents.
Breach Notification
In the event of a breach of unsecured PHI, Regen Wellness Center will notify affected individuals without unreasonable delay and no later than 60 days following discovery of the breach, as required by HIPAA. Notification will include: a description of the breach, the types of information involved, steps individuals should take to protect themselves, actions we are taking to investigate and mitigate harm, and contact information for further inquiries. We maintain a comprehensive incident response plan and conduct immediate investigations of any suspected or confirmed security incidents.
International Data Transfers
Medical services are provided in Mazatlán, Mexico, and patient health information may be stored on servers located in the United States or other jurisdictions that provide equivalent or superior data protection standards. Any international transfer of PHI is conducted in accordance with applicable data protection laws and only through HIPAA-compliant service providers with appropriate safeguards. Patients from the United States, Canada, and other countries are informed that their data may be processed in jurisdictions outside their country of residence, and such processing is subject to this privacy policy and applicable HIPAA standards.
Minors & Protected Individuals
We do not knowingly collect health information from individuals under the age of 18 without parental or legal guardian consent. For patients requiring legal representation, all consents and authorizations must be provided by legally authorized representatives. Special protections apply to information related to mental health, substance abuse treatment, HIV/AIDS status, and genetic testing, which are subject to additional confidentiality requirements beyond standard HIPAA protections.
Contact & Privacy Officer
Privacy inquiries, requests to exercise your rights, or reports of potential privacy violations may be directed to the Privacy Officer at Regen Wellness Center, Mazatlán, Sinaloa, México. You may contact us via the secure contact information provided during the application process. You have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights if you believe your privacy rights have been violated. We will not retaliate against you for filing a complaint.
Changes to This Privacy Policy
Regen Wellness Center reserves the right to update this privacy policy at any time to reflect changes in our practices, legal requirements, or HIPAA regulations. The effective date will be updated accordingly. Material changes will be communicated to enrolled patients via secure communication channels. Continued use of our services following notice of changes constitutes acceptance of the updated policy. For current and prospective patients, the most recent version of this policy governs our use and disclosure of your health information.