0
Skip to Content
Carolina Longevity
Carolina Longevity
About
Our Services
A La Carte Recovery Services
Assessments
Clinical Testing
All Assessments
Comprehensive Baseline Assessment
Core Baseline Assessment
Strength & Performance Assessment
Metabolic Health Assessment
À La Carte Options
Memberships
Partners
Contact
Blog
Get Started
Carolina Longevity
Carolina Longevity
About
Our Services
A La Carte Recovery Services
Assessments
Clinical Testing
All Assessments
Comprehensive Baseline Assessment
Core Baseline Assessment
Strength & Performance Assessment
Metabolic Health Assessment
À La Carte Options
Memberships
Partners
Contact
Blog
Get Started
About
Folder: Services
Back
Our Services
A La Carte Recovery Services
Assessments
Clinical Testing
Folder: Assessments
Back
All Assessments
Comprehensive Baseline Assessment
Core Baseline Assessment
Strength & Performance Assessment
Metabolic Health Assessment
À La Carte Options
Memberships
Partners
Contact
Blog
Get Started

Privacy Policy

Carolina Longevity
50101 Governors Dr, Ste 105, Chapel Hill, NC 27517
Phone: (984) 234-6951

Effective Date: July 1, 2026
Last Updated: July 1, 2026

1. Introduction and Scope

Carolina Longevity ("Carolina Longevity," "we," "us," or "our") is a physician-led longevity and preventive medicine practice located in Chapel Hill, North Carolina. We are committed to protecting the privacy, confidentiality, and security of the personal information and health information entrusted to us.

This Privacy Policy explains how we collect, use, disclose, and safeguard information through:

  • our website at www.carolinalongevity.com and any subdomains (the "Site");
  • our online forms, appointment requests, and membership inquiries;
  • our email and text communications; and
  • our general business operations.

Two categories of information, two sets of rules. It is important to understand the distinction:

CategoryWhat it isGoverning rules
Protected Health Information (PHI) Individually identifiable health information created or received by us as your health care provider — your medical record, lab and imaging results, diagnoses, treatment and medication history, appointment records, and billing records The Health Insurance Portability and Accountability Act (HIPAA), the HITECH Act, and applicable North Carolina law. Our uses and disclosures of PHI are described in detail in our Notice of Privacy Practices, which controls over this Privacy Policy for all PHI.
Website and business information Information collected from visitors to our Site who are not yet patients, and information collected outside the treatment relationship — contact form submissions, marketing email subscriptions, analytics data, cookies This Privacy Policy

If any provision of this Privacy Policy conflicts with our Notice of Privacy Practices with respect to PHI, the Notice of Privacy Practices governs.

2. Jurisdiction We Serve

Carolina Longevity operates a single physical location in Chapel Hill, North Carolina. Our clinicians are licensed by the North Carolina Medical Board, and we provide clinical services — including in-person visits and virtual (telehealth) visits — to patients located in the State of North Carolina at the time of service. Our Site is not directed to, and we do not knowingly market clinical services to, residents of other states or countries.

Accordingly, this Privacy Policy is written to comply with the privacy laws of the jurisdiction we serve: federal law applicable throughout the United States, and the law of the State of North Carolina. See Section 12 for the specific authorities with which we comply.

3. Information We Collect

3.1 Information you provide directly

  • Contact and inquiry information: name, email address, telephone number, and the content of any message you send through our contact form, our membership inquiry forms, by email, or by phone.
  • Appointment and intake information: the information you provide when scheduling or preparing for a visit, including date of birth, address, and the reason for your visit.
  • Health information: medical history, symptoms, medications, allergies, family history, lifestyle and nutrition information, laboratory results, DXA body composition and VO₂ max results, hormone panels, and other clinical data. Once you become a patient, this information is PHI and is governed by our Notice of Privacy Practices.
  • Payment information: billing address and payment card details, which are collected and processed by our payment processor. We do not store full payment card numbers on our systems.
  • Marketing preferences: your email address and preferences if you subscribe to our newsletter or updates.

3.2 Information collected automatically

When you visit the Site, we and our service providers may automatically collect:

  • IP address and approximate general location (city/region level);
  • browser type, operating system, device type, and screen size;
  • pages viewed, links clicked, referring URL, and time spent on pages;
  • date and time of access.

We collect this information using cookies and similar technologies. See Section 5.

3.3 Information from third parties

With your authorization or as otherwise permitted by law, we may receive health information about you from other health care providers, clinical laboratories, imaging facilities, pharmacies, health information exchanges, and — if applicable — your health plan. This information is PHI and is governed by our Notice of Privacy Practices.

4. How We Use Information

We use website and business information to:

  • respond to your inquiries and requests for information;
  • schedule, confirm, and remind you of appointments;
  • provide information about our services, assessments, and memberships;
  • process payments and administer memberships;
  • send marketing communications to those who have asked to receive them (you may unsubscribe at any time);
  • operate, maintain, secure, troubleshoot, and improve the Site;
  • detect and prevent fraud, abuse, and security incidents; and
  • comply with our legal obligations.

We use PHI only for treatment, payment, and health care operations, and for the other purposes described in our Notice of Privacy Practices or otherwise permitted or required by law. Any other use or disclosure of your PHI requires your written authorization, which you may revoke at any time.

5. Cookies, Analytics, and Online Tracking

Our Site uses cookies and similar technologies for two purposes:

  • Strictly necessary and functional cookies, which are required for the Site to load, remember your preferences, and keep your session secure.
  • Analytics cookies, which help us understand how visitors find and use our Site so we can improve it. We use Google Analytics (delivered via Google Tag Manager) and analytics provided by our website host, Squarespace. Analytics data is collected in aggregate and is used to measure Site performance, not to build advertising profiles about you.

Our email marketing is delivered through Flodesk, which may use tracking pixels in emails to tell us whether a message was opened or a link was clicked.

5.1 Our commitments regarding health information and advertising

We take the following positions, and we hold our vendors to them:

  • We do not sell your personal information or your health information. We have never done so and we do not do so for money or for any other valuable consideration.
  • We do not use advertising or social-media tracking pixels to transmit health information to advertising platforms. We do not permit third-party advertising trackers to collect information that could reveal that you sought, received, or inquired about a specific health condition, service, medication, or treatment from us.
  • We do not use PHI for marketing purposes without your prior written authorization, as required by 45 C.F.R. § 164.508(a)(3).
  • We do not permit third-party tracking technologies inside our patient portal. The patient portal is an authenticated environment; information in it is PHI and is not shared with analytics or advertising vendors.

5.2 Your choices

  • Cookie banner: where presented, you may accept or decline non-essential cookies and change your choice at any time.
  • Browser controls: most browsers let you block or delete cookies and send a "Do Not Track" or Global Privacy Control signal. We honor Global Privacy Control signals as an opt-out of non-essential analytics cookies where technically feasible.
  • Google Analytics opt-out: you may install the Google Analytics Opt-out Browser Add-on at tools.google.com/dlpage/gaoptout.
  • Marketing email: every marketing email contains an unsubscribe link, as required by the CAN-SPAM Act. You may also email or call us to be removed.
  • Text messages and calls: you may opt out of appointment reminders and other non-essential text messages by replying STOP, or by contacting us. Note that we may still need to contact you regarding your care.

6. When and With Whom We Share Information

We share information only as described below. We do not sell, rent, or trade your personal information or health information.

  • Treatment. With other health care providers, laboratories, imaging facilities, pharmacies, and specialists involved in your care.
  • Payment. With payment processors, and — only if you ask us to bill insurance — with your health plan. If you pay for an item or service in full, out of pocket, you have the right under 45 C.F.R. § 164.522(a)(1)(vi) to require that we not disclose that information to your health plan, and we will honor that request.
  • Business associates / service providers. With vendors who perform functions on our behalf, including our electronic health record and patient portal vendor (Elation Health), our website host (Squarespace), our email marketing platform (Flodesk), our payment processor, and any billing, IT, or professional services vendors. Every vendor that creates, receives, maintains, or transmits PHI on our behalf is required to sign a HIPAA Business Associate Agreement obligating it to safeguard PHI and to use it only for the permitted purpose. Vendors that receive only non-health website data are bound by contract to protect it and not to use it for their own purposes.
  • As required or permitted by law. Including public health reporting, reporting of suspected abuse or neglect, health oversight activities, judicial and administrative proceedings, law enforcement requests that meet HIPAA's requirements, workers' compensation, and to avert a serious and imminent threat to health or safety. These are described more fully in our Notice of Privacy Practices.
  • Controlled substances reporting. Because we prescribe controlled substances (including testosterone, a Schedule III controlled substance), we are required to review and report dispensing information to the North Carolina Controlled Substances Reporting System under N.C. Gen. Stat. § 90-113.70 et seq.
  • Business transfer. If Carolina Longevity is involved in a merger, acquisition, or sale of assets, patient records may transfer to the successor entity, subject to HIPAA and North Carolina law, and you will be notified as required.
  • With your authorization. For any other purpose, we obtain your written authorization first.

7. How We Protect Information

We maintain administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of the information we hold, as required by the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C). These include:

  • Encryption in transit. All connections to our Site, our online forms, and our patient portal are protected using SSL/TLS encryption. Any page on which we collect personal, health, or payment information is served exclusively over HTTPS.
  • Encryption at rest. PHI stored in our electronic health record and patient portal is encrypted at rest by our EHR vendor.
  • Access controls. Unique user credentials for every workforce member, multi-factor authentication where available, and role-based access limited to the minimum necessary information each person needs to do their job (45 C.F.R. § 164.502(b)).
  • Audit controls. Logging and review of access to electronic PHI.
  • Workforce training. HIPAA privacy and security training at hire and periodically thereafter, with sanctions for violations.
  • Ongoing review. Periodic review of our safeguards, policies, and procedures, and remediation of risks we identify.
  • Secure disposal. Destruction of records containing personal information in a manner that renders them unreadable and undecipherable, as required by N.C. Gen. Stat. § 75-64.
  • Vendor diligence. Business Associate Agreements and security review of vendors that handle PHI.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your interaction with us is no longer secure, contact us immediately using the information in Section 16.

8. Data Retention

We retain medical records consistent with the guidance of the North Carolina Medical Board — generally at least eleven (11) years from the date of the last professional contact for adult patients, and for patients who were minors, until age 30 or eleven years after the last contact, whichever is longer. Billing and financial records are retained as required by applicable tax and business law. Website inquiry and marketing data is retained only as long as needed for the purpose for which it was collected, and then deleted or de-identified.

9. Your Privacy Rights

9.1 If you are a patient (HIPAA rights)

You have the right to:

  • Access and receive a copy of your medical and billing records, including in an electronic format, and to direct us to send a copy to a person you designate;
  • Request an amendment to your record if you believe it is inaccurate or incomplete;
  • Receive an accounting of certain disclosures we have made;
  • Request restrictions on how we use or disclose your PHI, including the mandatory restriction for out-of-pocket payments described in Section 6;
  • Request confidential communications at an alternative address or by an alternative means;
  • Receive a paper copy of our Notice of Privacy Practices on request;
  • Be notified if there is a breach of your unsecured PHI; and
  • File a complaint without any retaliation.

These rights, and how to exercise them, are described in full in our Notice of Privacy Practices. Under N.C. Gen. Stat. § 90-411, we may charge a reasonable, cost-based fee for copies of records as permitted by that statute and by HIPAA.

9.2 If you are a website visitor

North Carolina has not enacted a comprehensive consumer data privacy statute. Regardless, as a matter of practice we will, on request:

  • tell you what personal information we hold about you;
  • correct information that is inaccurate;
  • delete information we are not required to retain by law or for legitimate business purposes; and
  • remove you from all marketing communications.

To make a request, contact us using the information in Section 16. We will verify your identity before acting on a request and will respond within 45 days.

10. Breach Notification

If we discover a breach of unsecured protected health information, we will notify:

  • each affected individual, without unreasonable delay and in no case later than 60 days after discovery, as required by the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400–414);
  • the U.S. Department of Health and Human Services, on the timeline required by that rule; and
  • prominent media outlets serving the area, if the breach affects more than 500 North Carolina residents.

Separately, if a security breach affects the personal information of North Carolina residents, we will notify affected individuals and the Consumer Protection Division of the North Carolina Attorney General's Office without unreasonable delay, as required by the North Carolina Identity Theft Protection Act, N.C. Gen. Stat. § 75-65. Our notice will include a description of the incident, the steps we have taken to protect information from further unauthorized access, a telephone number for further assistance, and advice directing you to remain vigilant by reviewing account statements and monitoring free credit reports, together with contact information for the major consumer reporting agencies, the Federal Trade Commission, and the North Carolina Attorney General's Office.

11. Telehealth and Patient Portal

Telehealth. We offer virtual visits to patients located in North Carolina. Virtual visits are conducted over a HIPAA-compliant, encrypted platform covered by a Business Associate Agreement. We do not record virtual visits without your written consent. Please join virtual visits from a private location; we cannot control the privacy of the space you are in or the security of your personal network.

Patient portal. We use Elation Passport, the patient portal provided by our electronic health record vendor, Elation Health. Access requires a unique username and password over an encrypted connection. You are responsible for keeping your credentials confidential and for not sharing your account. If you grant a family member, caregiver, or other person access to your record through the portal's proxy or "Family and Friends" feature, that person will be able to see the information you have authorized them to see until you revoke that access. Notify us immediately if you believe your account has been accessed without authorization.

Unencrypted email and text. Standard email and SMS text messaging are not secure. If you ask us to communicate with you by unencrypted email or text, we will honor that request, but you should understand and accept the risk that the message could be intercepted or read by someone else. For anything sensitive, use the patient portal.

12. How We Comply With Applicable Privacy and Health Information Laws

This section identifies the specific laws and regulations governing privacy and protected health information in the jurisdiction we serve, and the measures by which we comply with each.

12.1 Federal law

AuthorityHow we comply
HIPAA Privacy Rule, 45 C.F.R. Part 160 and Part 164, Subparts A and EWe maintain and follow written privacy policies and procedures; we assign responsibility for privacy compliance within our practice; we apply the minimum necessary standard; we obtain written authorization before any use or disclosure not otherwise permitted; we honor individual rights; and we publish and distribute a compliant Notice of Privacy Practices, posted prominently on this website as required by 45 C.F.R. § 164.520(c)(3)(i).
HIPAA Security Rule, 45 C.F.R. Part 164, Subpart CWe maintain the administrative, physical, and technical safeguards described in Section 7 and review them periodically, including SSL/TLS encryption of all transmitted patient, transactional, and confidential information, encryption at rest, access and audit controls, and a contingency plan.
HIPAA Breach Notification Rule, 45 C.F.R. §§ 164.400–414We maintain a written breach response and risk assessment procedure and notify individuals, HHS, and the media on the timelines described in Section 10.
HITECH Act, 42 U.S.C. § 17931 et seq.We execute Business Associate Agreements with every vendor that handles PHI on our behalf, honor the right to an electronic copy of records, and honor the out-of-pocket restriction right.
42 C.F.R. Part 2 (Confidentiality of Substance Use Disorder Patient Records), as amended effective February 16, 2026We are not a Part 2 program. To the extent we receive records from a Part 2 program, we segregate and safeguard those records, do not redisclose them except as Part 2 permits, and do not use them in legal proceedings against the patient without a court order or the patient's written consent. Our Notice of Privacy Practices describes these limits.
Section 5 of the FTC Act, 15 U.S.C. § 45, and the FTC Health Breach Notification Rule, 16 C.F.R. Part 318We do not make misleading statements about our privacy practices, and we do not disclose individually identifiable health information to advertising platforms or data brokers. See Section 5.1.
CAN-SPAM Act, 15 U.S.C. § 7701 et seq.Every marketing email identifies us, includes our physical address, and provides a functioning unsubscribe mechanism that we honor promptly.
Telephone Consumer Protection Act, 47 U.S.C. § 227We obtain the consent required before sending automated calls or texts and honor opt-out requests.
Children's Online Privacy Protection Act, 15 U.S.C. § 6501 et seq.Our Site is not directed to children under 13 and we do not knowingly collect personal information from children under 13 online. See Section 13.

The 2024 HIPAA Privacy Rule to Support Reproductive Health Care Privacy was vacated nationwide in Purl v. U.S. Department of Health and Human Services (N.D. Tex. June 18, 2025), and the appeal was dismissed on September 10, 2025. We therefore do not apply the vacated attestation requirement; we continue to protect all PHI, including reproductive and sexual health information, under the general HIPAA Privacy Rule and North Carolina law.

12.2 North Carolina law

AuthorityHow we comply
North Carolina Identity Theft Protection Act, N.C. Gen. Stat. Ch. 75, Art. 2AWe follow the breach notification requirements of § 75-65 (Section 10 above); we destroy records containing personal information so as to render them unreadable, as required by § 75-64; and we restrict the collection, use, and display of Social Security numbers as required by § 75-62.
Physician-patient privilege, N.C. Gen. Stat. § 8-53We do not disclose information acquired in attending a patient in a professional character in response to a subpoena or in litigation unless the privilege is waived by the patient or a court compels disclosure. A HIPAA-compliant authorization or valid court order is required.
Medical records copies, N.C. Gen. Stat. § 90-411Any fee we charge for copies of records is limited to the amounts permitted by this statute and by HIPAA, whichever is more protective of the patient.
Communicable disease information, N.C. Gen. Stat. § 130A-143Information identifying a person with a communicable disease or condition, including HIV status, is held strictly confidential and released only as that statute permits.
Minors' consent and confidentiality, N.C. Gen. Stat. § 90-21.4(b)Where a minor lawfully consents to their own care, we protect the confidentiality of that care as North Carolina law requires.
Controlled Substances Reporting System, N.C. Gen. Stat. § 90-113.70 et seq.We query and report to the CSRS as required in connection with controlled substance prescribing, and we treat CSRS data as confidential and use it only for permitted purposes.
North Carolina Medical Board rules and position statements, including those on telemedicine and retention of medical recordsWe hold active North Carolina licensure, apply the same standard of care and confidentiality to virtual visits as to in-person visits, and retain records for the periods described in Section 8.

Where federal and North Carolina law differ, we follow whichever standard provides greater protection to the patient, consistent with HIPAA's preemption rule at 45 C.F.R. § 160.203.

12.3 Laws of other states

We provide clinical services only to patients located in North Carolina and do not target residents of other states. Should our service area expand, we will update this Privacy Policy and our practices to comply with the privacy laws of each additional jurisdiction before providing services there.

13. Children's Privacy

Our Site and services are intended for adults. We do not knowingly collect personal information online from children under 13. Patients under 18 are seen only with the involvement of a parent or legal guardian, except where North Carolina law permits a minor to consent to their own care. If you believe a child under 13 has provided us personal information through the Site, contact us and we will delete it.

14. Third-Party Websites

Our Site may link to third-party sites, including our social media pages, our scheduling tools, and our patient portal. Those services have their own privacy policies, and this Privacy Policy does not apply to them. We encourage you to read the privacy policy of any site you visit.

15. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or in the law. The "Last Updated" date at the top shows when it was last revised. Material changes will be posted prominently on this page. Changes to our privacy practices with respect to PHI will also be reflected in a revised Notice of Privacy Practices, which we will post on this Site and make available in our office.

16. How to Contact Us or File a Complaint

Privacy Inquiries
Carolina Longevity
50101 Governors Dr, Ste 105
Chapel Hill, NC 27517
Phone: (984) 234-6951
Email: privacy@carolinalongevity.com

If you believe your privacy rights have been violated, you may file a complaint with us at the address above. We will not retaliate against you in any way for filing a complaint.

You may also file a complaint with:

U.S. Department of Health and Human Services, Office for Civil Rights
200 Independence Avenue SW, Room 509F, HHH Building, Washington, D.C. 20201
Phone: 1-877-696-6775
Online: ocrportal.hhs.gov/ocr/smartscreen/main.jsf

North Carolina Attorney General, Consumer Protection Division
9001 Mail Service Center, Raleigh, NC 27699-9001
Phone: 1-877-566-7226
Online: ncdoj.gov/file-a-complaint

Subscribe

Address:

50101 Governors Dr, Ste 105, Chapel Hill, NC 27517

Phone Number:

984-234-6951

Services

Assessments

Memberships

About

Learn

Contact

©2026 Carolina Longevity. All rights reserved.

All treatments are individualized and based on a licensed physician's clinical judgment. Results vary and are not guaranteed. Carolina Longevity provides primary and preventive care services to patients located in North Carolina. Telehealth services are available only when the patient is physically located in North Carolina at the time of the visit. Patients should seek emergency medical care when appropriate.

Terms of Service

Privacy Policy