Working draft — not approved for patient enrollment
This review copy remains pending Pennsylvania healthcare-counsel approval.
POWFIT MD Website Privacy Policy
Pre-launch draft date: August 22, 2026
Working draft: This document is undergoing Pennsylvania healthcare-counsel review. It is not approved for patient enrollment or a clinical launch.
This Privacy Policy describes how Prisk Orthopaedics and Wellness, PC ("P.O.W., PC"), doing business as POWFIT MD ("POWFIT MD," "we," "us," or "our") collects, uses, and protects information when you visit powfitmd.com (the "Site"), use our patient portal, communicate with us by phone, chat, text, or email, or receive care through our telehealth and in-person services.
POWFIT MD is a physician-owned medical practice founded by Victor Prisk, MD, a board-certified orthopaedic surgeon practicing in the Pittsburgh, Pennsylvania area. We are a healthcare provider - not a marketing platform - and we treat your information accordingly.
If you are a patient: Your medical information is protected health information ("PHI") under the Health Insurance Portability and Accountability Act ("HIPAA"). Our use and disclosure of PHI is governed by our HIPAA Notice of Privacy Practices, which controls over this Privacy Policy wherever the two overlap. This Privacy Policy primarily addresses website, marketing, and non-clinical data.
1. Who This Policy Covers
We interact with two broad groups of people, and we collect different information from each:
| Category | Who you are | What governs your data |
|---|---|---|
| Site visitors | Anyone browsing public pages of powfitmd.com (service descriptions, pricing, blog, FAQ) without logging in | This Privacy Policy |
| Registered patients and prospective patients | Anyone who creates a portal account, completes a medical intake, books a visit, or receives care | This Privacy Policy and HIPAA / our Notice of Privacy Practices |
2. Information We Collect
2.1 From Site Visitors (Public Pages)
- Device and usage data: IP address, browser type, device type, pages viewed, referring page, and approximate (city-level) location, collected via cookies and similar technologies (see Section 8).
- Information you submit voluntarily: name, email, or phone number if you fill out a contact form, join an email list, or request information.
2.2 From Registered Patients and Prospective Patients
- Identity and contact information: name, date of birth, address, email, phone number, and government-issued photo ID where required to verify identity for telehealth or controlled-substance prescribing.
- Health information: medical history, symptoms, medications, allergies, laboratory results, photographs you submit for clinical review, visit records, prescriptions, and messages you exchange with our clinical team. This is PHI under HIPAA.
- Account and subscription information: portal login credentials, membership plan, appointment history, and communication preferences.
- Payment information: processed by Stripe as described in Section 7. We do not store full card numbers.
- Communications: portal messages, emails, text messages, and—only if a separately disclosed feature is enabled and the required consent is obtained—chat transcripts or recorded calls.
- Referral program data: if you participate in our patient referral program, we record your referral code and any account credits earned. Referral rewards are account credits, not cash, and participation is voluntary.
3. How We Use Information
We use information to:
- Provide medical care, including telehealth visits, prescriptions, and lab orders;
- Register and verify your identity as a patient;
- Manage subscriptions, billing, appointments, and customer service;
- Communicate with you about your care, your account, and (with your consent) our services;
- Operate, secure, and improve the Site and portal;
- Comply with legal obligations (e.g., medical record retention, prescription monitoring, breach notification).
We do not sell your personal information. We do not sell PHI. We do not share patient information with third parties for their own advertising purposes.
4. Where Your Medical Records Live: Our Systems and Vendors
We use vendors only for approved purposes. Before a vendor is permitted to create, receive, maintain, or transmit PHI on our behalf, we evaluate the exact service and configuration, limit the data it receives, and put a HIPAA Business Associate Agreement ("BAA") in place when required. A vendor named in a plan or future-feature description is not authorized to receive PHI until those steps are complete.
- ModMed (Modernizing Medicine) - Electronic Health Record. ModMed is the Practice's chart of record. The POWFIT MD portal does not itself prescribe. When a clinician issues a prescription, it is documented and transmitted through the Practice's approved EHR/e-prescribing workflow. Controlled-substance prescriptions use a certified electronic prescribing of controlled substances (EPCS) workflow except where law recognizes a specific exception.
- Google Cloud Platform - Hosting and infrastructure. Our Site and portal use approved, HIPAA-eligible Google Cloud services covered by the Practice's agreement with Google. A Google Cloud service is not approved for PHI merely because Google offers a BAA; the specific service and configuration must also be authorized.
- Pharmacies - treatment disclosures. If a clinician issues a prescription, you may select any qualified pharmacy able to fill it. We disclose the prescription and minimum necessary demographic information to that pharmacy through an approved electronic or secure transmission channel. We verify any compounding pharmacy and product-specific pathway before use.
- Stripe - Payments. See Section 7.
- Communications vendors. Email, SMS, telephony, transcription, or AI services remain disabled for PHI until the exact service is approved and any required agreement, notice, consent, retention rule, and human escalation process is in place.
The custom POWFIT MD portal is a front end for intake, scheduling, subscriptions, and messaging; it does not replace the EHR. Information you submit through the portal may be transferred into our electronic health record by our staff as part of maintaining your medical record.
5. Website Help and Future AI Features
POWFIT MD does not currently offer a free-form AI chatbot for individual medical questions. The website's help control presents prewritten navigation and support choices. Do not enter symptoms, diagnoses, medication details, or other medical information into a public website-help field.
If we later enable an AI-assisted chat feature, we will update this Policy and provide an appropriate notice before collection begins. The feature will remain administrative, will not diagnose or prescribe, and will include a human handoff. We will also disclose the provider, data use, retention, and whether a conversation becomes part of the medical record. Do not use any website chat or portal message for an emergency; call 911.
6. Phone Automation and Recording
POWFIT MD does not currently use an AI voice agent or routine automated call recording/transcription for the new platform. If either feature is enabled, we will provide a clear notice, obtain the consent required for that specific communication, offer a non-automated alternative, describe retention and data use, and update this Policy before processing begins. Any enabled phone automation will be limited to administrative work and will include a human handoff. Do not use a practice phone automation for an emergency; call 911.
7. Payments - Stripe
We use Stripe to process payments and manage subscriptions.
- When you enter card details, they go directly to Stripe; we do not receive or store your full card number.
- Payment processing is handled outside HIPAA under the payment-processing exemption for financial transactions (HIPAA § 1179). To keep it that way, we deliberately keep clinical details out of Stripe: charges are described generically (e.g., "Membership," "Consultation"), and detailed receipts, if needed, come from our HIPAA-covered systems - not from Stripe.
- Stripe's own privacy practices are described at https://stripe.com/privacy.
8. Cookies, Analytics, and Tracking Technologies
- Public pages: The public marketing site currently uses no analytics cookies, no third-party advertising pixels (such as the Meta Pixel or Google Ads tags), and no cross-site trackers. Only cookies strictly necessary for the Site to function may be set. Nothing you submit through the Site - including waitlist and intake-interest forms - is shared with advertising platforms. If we later adopt privacy-conscious, first-party analytics or advertising measurement (per our marketing plan, only limited de-identified conversion events through a privacy gateway - never health information, never your identity), we will update this Policy to describe exactly what is collected and provide an opt-out before any such measurement begins.
- Authenticated pages: We do not place third-party advertising pixels or ad-network trackers (e.g., Meta Pixel, Google Ads tags) on the patient portal, intake flows, or any page behind a login. Any analytics used inside authenticated experiences are limited to vendors under a BAA, or are disabled.
- Managing cookies: You can control cookies through your browser settings. Blocking cookies may limit some Site features but will not affect your ability to receive care.
9. Email and Text (SMS) Communications
- Care-related messages may include appointment reminders, lab-ready notices, refill notifications, or billing notices. A channel is used only after it is enabled by the Practice and the required preferences or consent are recorded.
- Marketing messages are sent only with your prior consent, and never disclose your health conditions in the message body.
- Opt-out: Reply STOP to any text (or use UNSUBSCRIBE/CANCEL/QUIT or any reasonable method) to stop texts; use the unsubscribe link in any marketing email. We honor revocations promptly and in all cases within the timeframes required by law. Opting out of marketing does not stop messages necessary for your treatment or account (e.g., appointment confirmations), which you may separately manage in your portal settings.
- SMS is not an encrypted channel. We keep text content minimal and avoid including diagnoses or medication details in message bodies.
10. Data Retention
- Medical records will be retained in accordance with the Practice's counsel-reviewed Data Retention & Destruction Policy, applicable law, and professional obligations. This working draft does not approve a blanket retention period. The previously discussed ten-year period is a planning assumption only until the Practice adopts the final record-class schedule.
- Website and account data will follow that approved record-class schedule, including its deletion, legal-hold, backup/PITR, log, and secure-disposal rules. Account status alone does not establish a final retention period.
- Future recordings or AI transcripts, if enabled, will follow a documented retention schedule disclosed at or before collection and will be handled as part of the medical record when applicable.
11. Security
We use administrative, technical, and physical safeguards appropriate to a medical practice, including: encryption of data in transit (TLS) and at rest; access controls and role-based permissions; multi-factor authentication for staff and prescribers (including required authentication for controlled-substance e-prescribing); audit logging; required vendor agreements for enabled services; and workforce HIPAA training. No system is perfectly secure; if a breach affecting your information occurs, we will notify you as required by HIPAA and the Pennsylvania Breach of Personal Information Notification Act.
12. Children
Our services are for adults. You must be 18 years of age or older to create an account or receive care from POWFIT MD. We do not knowingly collect information from anyone under 18; if we learn we have done so, we will delete it.
13. Your Rights
- HIPAA rights (patients): access to your records, amendment, an accounting of certain disclosures, restriction requests, and confidential communications - described in full in our Notice of Privacy Practices.
- Pennsylvania: Pennsylvania does not currently have a comprehensive consumer privacy statute, but you are protected by Pennsylvania's breach notification law and by our HIPAA obligations.
- Other states: If you reside in a state with a consumer privacy law granting rights of access, deletion, or correction, you may submit a request using the contact information below. Note that most state consumer privacy laws exempt PHI held by HIPAA-covered entities; requests concerning your medical record are handled under HIPAA instead.
- We will never discriminate against you for exercising a privacy right.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with a new "Last Updated" date, and, where appropriate, notified to registered patients through the portal or email.
15. Contact Us
Prisk Orthopaedics and Wellness, PC d/b/a POWFIT MD Privacy Contact: Victor Prisk, MD Phone: (412) 525-7692 Or by mail to: Prisk Orthopaedics and Wellness, PC d/b/a POWFIT MD, 2490 Mosside Blvd., Monroeville, PA 15146
For questions about your medical records or HIPAA rights, please see our HIPAA Notice of Privacy Practices or contact our Privacy Officer.