Savannah River Advanced Surgery PC
Website Privacy Policy
Effective Date: August 27, 2026 Last Updated: August 27, 2026
1. Scope of This Policy, and How It Relates to Our Notice of Privacy Practices
This Privacy Policy explains how Savannah River Advanced Surgery PC ("SRAS PC," "we," "us," or "our"), a Georgia professional corporation, collects and uses information through our websites and digital marketing, including:
- savannahriversurgery.com (our surgical practice); and
- leandreamsweightloss.com (the LeanDreams virtual medical weight management program, a program and brand operated by SRAS PC).
We refer to these together as the "Sites."
This Policy covers website and consumer information — not your medical record. It applies to website visitors, prospective patients, people who submit contact or appointment-request forms, and people who interact with our advertising, email, and text messaging.
Protected health information is governed by our Notice of Privacy Practices. SRAS PC is a covered entity under the Health Insurance Portability and Accountability Act ("HIPAA"). Information that identifies you and relates to your health, your care, or payment for your care — including everything in your medical record and in the patient portal — is protected health information ("PHI") and is handled in accordance with HIPAA and our Notice of Privacy Practices. If this Privacy Policy and the Notice of Privacy Practices conflict with respect to PHI, the Notice of Privacy Practices controls.
Your use of the Sites is also subject to our Terms of Service.
Savannah River Practice Management LLC ("SRPM LLC") provides administrative, technology, billing, scheduling, and marketing support to SRAS PC. SRPM LLC does not practice medicine and is not your provider. Where SRPM LLC handles PHI on our behalf, it does so as a business associate of SRAS PC under a written business associate agreement.
2. Information We Collect
2.1 Information You Give Us
- Contact details — name, email address, telephone number, mailing address, and city or state.
- Appointment and consultation requests — the reason for your inquiry, preferred appointment times, referral source, and any details you choose to include in a free-text message field. Anything health-related you enter into a web form becomes PHI once we associate it with you as a patient or prospective patient, and from that point it is handled under our Notice of Privacy Practices.
- Program enrollment information — the information needed to create an account, verify your age and location, and enroll you in a program.
- Payment information — processed by third-party payment processors. We do not collect or store full payment card numbers on our systems. We may retain limited information such as the card brand, the last four digits, the expiration date, the billing name and address, and a processor-generated token used for recurring charges.
- Communications — email, text messages, voicemail, chat messages, reviews, survey and questionnaire responses, and support requests.
- Marketing preferences — your consent choices for email and text messaging.
2.2 Information Collected Automatically
When you visit the Sites, we and our service providers may collect:
- Device and technical data — IP address, browser type and version, operating system, device type, screen size, language, and referring and exit pages.
- Usage data — pages viewed, links clicked, time on page, scroll depth, form starts and submissions, search terms used on the Sites, and general approximate location derived from IP address.
- Cookie and identifier data — cookies, local storage, pixels, tags, software development kits, and similar technologies, and the identifiers they set.
2.3 Information From Third Parties
We may receive information from advertising and analytics platforms (aggregate campaign performance and audience data), from scheduling and CRM tools, from referral sources such as referring physicians, and from publicly available sources such as review platforms where you have posted a review.
2.4 We Do Not Knowingly Collect Sensitive Categories Through the Sites
Please do not submit Social Security numbers, financial account numbers, or detailed health histories through general website contact forms or by unencrypted email. Use the patient portal, secure intake, or a telephone call instead.
3. How We Use Information
We use website and consumer information to:
- respond to inquiries, appointment requests, and support requests;
- schedule appointments, verify eligibility, and enroll and administer program memberships;
- process payments, prevent fraud, and maintain billing records;
- operate, secure, troubleshoot, and improve the Sites;
- measure and improve our marketing, including understanding which pages and campaigns bring people to us;
- send you administrative and transactional messages;
- send you marketing email and text messages where you have consented, and to allow you to opt out at any time;
- comply with legal obligations and enforce our Terms of Service; and
- create de-identified or aggregated information, which is no longer personal information and which we may use for any lawful purpose.
We do not sell your personal information for money, and we do not permit third parties to use information collected through the Sites for their own independent marketing purposes.
4. Cookies, Analytics, Advertising Pixels, and Tracking Technologies
We use cookies and similar technologies in the following broad categories:
- Strictly necessary — needed to load pages, keep your session active, secure forms, and remember your cookie choices. These cannot be turned off through our Sites.
- Functional — remember preferences such as language or a dismissed banner.
- Analytics — help us understand how the Sites are used in aggregate, which pages perform, and where visitors have trouble.
- Advertising — used to measure the performance of our advertising, to limit how often you see the same ad, and to show our ads to people who have visited our Sites or who resemble our audience. We advertise on social media and search platforms, including Meta platforms.
4.1 How We Handle Health Information and Tracking Technologies
We use analytics and advertising technologies on our public websites to understand how visitors find us, to measure which pages and campaigns are useful, and to reach people who may be interested in our services. The specific tools we use change over time as marketing platforms change. Where those technologies operate on our general-audience pages — home pages, service and program descriptions, educational content, and general contact pages — the information involved is website and campaign information, not your medical record.
What does not change is how we treat protected health information:
- We do not disclose PHI to advertising or social media platforms. We do not send them your name, email address, telephone number, appointment details, diagnosis, medication, prescription, program enrollment, or any other identifier that would reveal that you are a patient of the practice or that you sought care for a particular condition, unless you have signed a valid HIPAA authorization permitting that specific use.
- We do not sell your protected health information.
- Vendors that receive PHI do so only as business associates under written business associate agreements that require them to protect it. Advertising platforms are not business associates and we do not treat them as such.
- Areas where you are logged in receive different treatment than our public pages. The patient portal, secure messaging, clinical intake, and telehealth visits involve protected health information, and third-party tracking technologies are not permitted to receive information from them except through a vendor operating under a business associate agreement for a permitted purpose.
If you would prefer not to submit health-related details through any web form, call us instead and a member of our staff will take the information directly. If you want to limit tracking on our public pages, see the controls described in Section 4.2.
4.2 Your Choices About Cookies and Tracking
- Browser controls. Most browsers let you block or delete cookies, block third-party cookies, and browse in a private mode. Blocking strictly necessary cookies may break parts of the Sites.
- Device and platform controls. Mobile operating systems provide advertising-identifier and tracking-permission settings. Advertising platforms, including Meta and Google, provide their own ad-preference and ad-topic controls in your account settings on those platforms.
- Industry opt-outs. Industry self-regulatory programs, including those operated by the Digital Advertising Alliance and the Network Advertising Initiative, offer interest-based-advertising opt-out tools. These opt-outs are cookie-based and may need to be renewed if you clear cookies or change browsers.
- Contact us. You may also email us using the address in Section 11 and ask us to stop using your information for marketing measurement.
4.3 Do Not Track and Global Privacy Control
- Do Not Track ("DNT"). There is no common industry or legal standard for how websites must respond to browser DNT signals. Our Sites do not currently respond to DNT signals.
- Global Privacy Control ("GPC"). GPC is an emerging browser-level signal indicating a preference to opt out of the sale or sharing of personal information for targeted advertising. We treat a GPC signal as a request to disable non-essential advertising cookies for that browser, and we honor it on that basis regardless of whether a law requires us to. Because GPC is browser- and device-specific, you will need to set it on each browser and device you use. GPC does not affect strictly necessary cookies.
5. When We Share Information
We share information in these circumstances only:
- Service providers and vendors (see Section 6), which may use the information only to perform services for us.
- Business associates, for any vendor handling PHI, under written business associate agreements.
- Payment processors, to process transactions you authorize.
- Advertising and analytics platforms, limited to non-PHI, general-audience website and campaign data as described in Section 4.
- Professional advisors, such as attorneys, accountants, and insurers, as needed.
- Legal and safety reasons — to comply with law, respond to lawful requests such as subpoenas and court orders, enforce our Terms of Service, protect our rights and property, or protect the safety of any person. Disclosures of PHI for these purposes follow the standards in our Notice of Privacy Practices.
- Business transitions — in connection with a reorganization, merger, sale of assets, or similar transaction, subject to applicable law governing patient records and health information.
- With your direction or consent, including where you ask us to send information to another person or entity.
We do not sell, rent, or trade personal information.
6. Categories of Third-Party Services We Use
We rely on third-party services in the following categories:
- Practice management, electronic health record, and telehealth platform — scheduling, charting, video visits, and clinical documentation. Handles PHI; business associate agreement in place.
- Secure patient messaging and communications — portal messaging and secure notifications. Handles PHI; business associate agreement in place.
- Billing, revenue cycle, and claims — insurance billing for surgical services, explanation-of-benefit processing, and collections support. Handles PHI; business associate agreements in place.
- Customer relationship management and patient-intake tools — lead capture, follow-up workflows, and consultation booking. May handle PHI; business associate agreement in place where applicable.
- Payment processing — card processing and subscription billing. Handles payment data; PCI-compliant processors.
- Scheduling and calendaring — consultation and appointment booking.
- Email and SMS delivery — transactional and, where you have consented, marketing messages. Business associate agreement in place where messages contain PHI.
- Website hosting, content delivery, and security — hosting, forms, and protection against attacks.
- Analytics — aggregate website performance measurement, limited to non-authenticated pages.
- Advertising platforms — including social media and search advertising, limited to non-PHI campaign measurement and audience targeting as described in Section 4. Not business associates; no PHI is disclosed to them.
- Cloud storage, document management, and secure destruction.
- Compounding and dispensing pharmacies and clinical laboratories — independently licensed providers of goods and services, which receive only the information needed to fill a prescription or perform testing.
7. Data Retention
We keep information only as long as we need it for the purposes described in this Policy, and then delete it or de-identify it. In general:
- Medical records and PHI are retained in accordance with Georgia and South Carolina law, professional standards, and our record-retention policy. HIPAA also requires certain privacy documentation to be retained for six years.
- Billing and financial records are retained as required by tax, accounting, and audit obligations.
- Website inquiry and marketing records are retained for as long as needed to respond and to maintain a reasonable marketing history, and are then deleted.
- Cookies and analytics data are retained for the periods set in each tool's configuration.
- Consent records, including SMS and marketing consent and testimonial authorizations, are retained for as long as we rely on them and for a reasonable period afterward to demonstrate compliance.
We may retain information longer where necessary to comply with law, resolve disputes, or enforce our agreements.
8. Security
We use reasonable administrative, technical, and physical safeguards to protect information, including encryption of data in transit, access controls and unique user accounts, role-based access limits, multi-factor authentication where available, staff privacy and security training, vendor due diligence and business associate agreements, and secure disposal of records. For electronic PHI we maintain the safeguards required by the HIPAA Security Rule.
No method of transmission or storage is completely secure. Email and standard text messaging are not secure; please do not send detailed health information that way. Use the patient portal or call us instead. If we become aware of a breach of unsecured PHI, we will provide notice as required by law and as described in our Notice of Privacy Practices.
9. Children
The Sites are intended for adults. The LeanDreams virtual weight management program is available only to individuals 18 years of age or older, and we do not knowingly collect personal information online from anyone under 18 in connection with that program.
Our surgical practice may treat minors when a parent or legal guardian provides consent. Information about minor patients is handled as PHI under our Notice of Privacy Practices and applicable state law, not through the Sites' general web forms.
If you believe a child has provided personal information through the Sites, contact us using Section 11 and we will delete it.
10. Your Choices and Requests About Non-PHI Website Data
Georgia has not enacted a comprehensive consumer privacy statute, and this Policy does not claim that the California Consumer Privacy Act, the EU General Data Protection Regulation, or similar laws apply to us. We do, however, offer the following as a matter of practice, in good faith, to anyone who asks:
- Access. Ask us what non-PHI website and marketing information we hold about you.
- Correction. Ask us to correct inaccurate contact or marketing information.
- Deletion. Ask us to delete non-PHI website inquiry and marketing information about you.
- Marketing opt-out. Unsubscribe from marketing email using the link in any marketing message, reply STOP to any text message, or contact us directly.
- Advertising opt-out. Use the controls described in Section 4.2, or ask us to exclude you from advertising audiences.
Some limits apply. We cannot delete information we are required to keep — in particular, we cannot delete your medical record or billing records, which are governed by HIPAA and state retention law rather than by this Policy. Requests about your medical record should be made under Section 5 of our Notice of Privacy Practices, which sets out your HIPAA rights of access, amendment, accounting, restriction, and confidential communications.
Residents of states that have enacted comprehensive consumer privacy laws may have additional statutory rights. If you believe such a law applies to you, tell us in your request and we will respond in accordance with it. We verify requests before acting on them, and we will not discriminate against you for making a request.
We aim to respond to requests under this Section within 30 days.
11. How to Contact Us
For privacy questions or to make a request about website or marketing information:
Savannah River Advanced Surgery PC Attn: Michael Whitmer, Privacy Officer 1109 Medical Center Dr., Building 3 Augusta, GA 30909 Phone: 803-220-1716 Fax: (706) 739-4728 Email: ops@leandreamsweightloss.com
LeanDreams Program support: 202-430-5326
For requests concerning your medical record or other protected health information, contact the Privacy Officer at the same address and see our Notice of Privacy Practices.
12. Changes to This Policy
We may update this Policy. When we do, we will change the "Last Updated" date and post the revised Policy on both Sites. If a change is material, we will provide more prominent notice, such as a banner on the Sites or an email to enrolled members. Your continued use of the Sites after a change takes effect means you accept the updated Policy.