Privacy Policy.
This Privacy Policy explains how Rejuvé Wellness & Aesthetics collects, uses, and safeguards your personal information and protected health information (PHI). As a medical practice offering wellness, aesthetic, and spa services in Texas, we are bound by HIPAA, the Texas Medical Records Privacy Act (TMRPA), and applicable Texas state law.
By using our website, booking an appointment, or receiving services at any Rejuvé location, you agree to the practices described in this Privacy Policy.
Rejuvé is a medical wellness and aesthetic practice led by Heather Smith, WHNP-BC, Board-Certified Women’s Health Nurse Practitioner, Certified Hormone Specialist, and Aesthetic Specialist. We offer a comprehensive range of medical-grade services including:
- Hormone Replacement Therapy (HRT) — including BioTe pellet therapy
- Medical Weight Loss — including GLP-1 medications (Semaglutide, Tirzepatide)
- Peptide Therapy
- IV Therapy
- Functional Medicine
- Botox, Dysport, Dermal Fillers, Sculptra, PDO Threads
- Tixel Skin Resurfacing, Microneedling, Morpheus8 RF, IPL/Laser, Chemical Peels
- Laser Hair Removal, Exosomes
- Lipo-Dissolve, BodyTite, Natural Growth Factor (NGF) treatments
- Facials, HydraFacial, Dermaplaning, Massages, Teeth Whitening, Lash & Brow, Japanese Head Spa
The Woodlands: 2408 Timberloch Place, Suite D7, The Woodlands, TX 77380
Montgomery: 20165 Eva St, Suite J, Montgomery, TX 77356
Phone: (281) 651-5170 | Email: info@rejuvemedspatx.com
- Full name, date of birth, and gender
- Email address, phone number, and mailing address
- Payment and billing information (we do not store full card numbers)
- Login credentials if you create an online patient portal account
- Newsletter subscription preferences
- Medical history, current health conditions, and diagnoses
- Treatment records and clinical notes
- Hormone levels, lab results, and diagnostic information
- Prescription and medication history (including GLP-1 medications, hormone therapy, and peptides)
- Health insurance information where applicable
- Before-and-after treatment photography (with your written consent)
Please note: PHI collected for salon-only services (facials, massages, lash/brow) that have no medical component is still treated with the same level of care and confidentiality.
- IP address, browser type, and device information
- Pages visited, time spent on site, and referral source
- Form submissions (contact forms, booking requests, newsletter sign-ups)
- Cookie and tracking data (see Section 8)
- Treatment: Providing, coordinating, and managing your medical, aesthetic, and wellness care
- Payment: Processing payments, handling insurance claims, and managing billing
- Healthcare Operations: Quality improvement, staff training, credentialing, and audits
- Coordinate hormone therapy monitoring and lab result follow-ups
- Manage GLP-1 prescription refills and weight loss program check-ins
- Track aesthetic treatment plans and touchup schedules (filler, Botox, thread lifts)
- Schedule follow-up care after procedures such as Morpheus8, BodyTite, or Tixel
- Send pre- and post-care instructions for booked services
- Send appointment reminders and confirmations
- Share wellness tips, treatment news, and seasonal promotions via email or SMS
- Notify you of new services, events, or blog content
You may opt out at any time by emailing info@rejuvemedspatx.com or clicking “Unsubscribe” in any email. Opting out of marketing does not affect clinical communications.
We use analytics tools such as Google Analytics to understand website usage patterns. This data is aggregated, anonymized, and never linked to your PHI.
- SSL/TLS encryption for all data transmitted through our website and booking systems
- Restricted access to PHI on a strict need-to-know basis among authorized staff
- Signed Business Associate Agreements (BAAs) with all third-party vendors who handle PHI
- Secure storage of paper and electronic medical records
- Regular HIPAA training for all staff members
- Ongoing risk assessments and security monitoring
- Breach notification procedures in compliance with the HIPAA Breach Notification Rule
- With other treating providers involved in your care (e.g., referring physicians, labs)
- With your health insurance carrier for claims and coverage verification
- With Business Associates under a signed BAA (booking platforms, EMR systems, payment processors)
- As required by Texas or federal law (court orders, public health reporting, mandatory abuse reporting)
- In emergencies where disclosure is necessary to protect your life or safety
- Marketing or advertising by third parties
- Sale of PHI to any party
- Use of before-and-after photos for social media or promotional materials
- Any other use not covered by HIPAA TPO
We Never Sell Your Information. Rejuvé Wellness & Aesthetics does not sell, rent, trade, or otherwise transfer your personal information or PHI to any outside party for commercial purposes.
As a patient of Rejuvé, you have the following rights. To exercise them, contact us at info@rejuvemedspatx.com.
- Right to Access: Request a copy of your medical records. We will respond within 30 days.
- Right to Amend: Request corrections to inaccurate or incomplete PHI.
- Right to Restrict Disclosures: Request limits on how we use or share your PHI.
- Right to Confidential Communications: Request we contact you only by specific means or location.
- Right to an Accounting of Disclosures: Request a list of non-routine PHI disclosures from the past 6 years.
- Right to Revoke Authorization: Withdraw any previously given authorization for use of your PHI.
- Right to a Paper Copy: Receive a printed copy of this Notice at any Rejuvé location.
- Right to File a Complaint: File a complaint with us or with the U.S. HHS Office for Civil Rights at hhs.gov/hipaa.
- You have the right to access your medical records within 15 business days of a written request
- Certain sensitive health information (HIV status, mental health records, substance abuse treatment) receives additional protections under the Texas Health & Safety Code
- Texas law prohibits unauthorized disclosure of your health information for marketing without express written consent
For more information, visit texasattorneygeneral.gov.
- Essential Cookies: Required for the website to function (booking system, contact forms)
- Analytics Cookies: Help us understand how visitors use our site — data is anonymized (Google Analytics)
- Marketing Cookies: Track visits from ads to measure campaign effectiveness
You may manage or disable cookies through your browser settings. We do not use cookies to collect or store PHI.
Our online booking system is operated by a third-party platform that is a Business Associate of Rejuvé, bound by a signed BAA. Any personal information entered through the booking system is subject to both this Privacy Policy and the platform’s own privacy terms.
Our website may contain links to third-party websites (e.g., Google Maps, social media). Rejuvé is not responsible for the privacy practices of those websites.
- We use your contact information only to send appointment-related communications and content you have opted into
- We do not share your email or phone number with third-party marketers
- Unsubscribe from emails at any time via the link in any email
- To opt out of SMS messages, reply STOP to any text message from us
Opting out of marketing communications does not affect clinical or appointment-related messages.
Rejuvé may take before-and-after photographs as part of your treatment record. These images are part of your PHI, stored securely in your patient file, and will not be used for marketing or social media without your separate written authorization.
To withdraw a previously given photo authorization, contact us at info@rejuvemedspatx.com.
Our medical services are intended for adults 18 years of age and older. For clients under 18 receiving any service, a parent or legal guardian must provide written consent. We do not knowingly collect personal data from minors through our website without verifiable parental consent.
We retain patient medical records for a minimum of 10 years from the date of last treatment, or as required by Texas law (whichever is longer). Non-clinical personal data (e.g., marketing email lists) is retained only as long as necessary and may be deleted upon request.
We reserve the right to update this Privacy Policy at any time. Material changes will be posted on this page with a revised effective date. For significant changes affecting your rights, we will make reasonable efforts to notify existing patients directly.
Your continued use of our website or services after any changes constitutes acceptance of the updated policy.
For any questions, concerns, or requests related to this Privacy Policy or your health information rights, please contact our Privacy Officer:
Rejuvé Wellness & Aesthetics
The Woodlands, TX 77380
20165 Eva St, Suite J
Montgomery, TX 77356
If your concern has not been resolved, you may also file a complaint with:
- U.S. HHS Office for Civil Rights — hhs.gov/hipaa/filing-a-complaint
- Texas Office of the Attorney General — texasattorneygeneral.gov
We will not retaliate against you for filing a complaint.