Skip to main content
    Book Consultation
    Contact our office to schedule a consultation
    Dr. Hassan Nasser — Detroit Face MD logo
    Book Now
    Legal & Compliance

    Privacy Policy & HIPAA Notice | Dr. Hassan Nasser

    Dr. Hassan Nasser and Detroit Face MD are committed to protecting your health information, digital privacy, and communications in full compliance with HIPAA, the Michigan Public Health Code, and applicable federal regulations.

    HIPAA CompliantA2P 10DLC RegisteredMichigan Licensed PracticeSSL Encrypted

    Last Updated: June 25, 2026  |  Effective Date: June 25, 2026

    256-bit SSL Encryption

    All data transmitted is encrypted end-to-end.

    HIPAA Compliant

    Protected Health Information handled per 45 CFR Parts 160 & 164.

    A2P SMS Registered

    Text messaging compliant with TCPA and A2P 10DLC standards.

    No Sale of PHI

    We never sell, rent, or trade your personal or health information.

    Table of Contents

    1. Who We Are & Scope of This Policy
    2. HIPAA Notice of Privacy Practices
    3. Information We Collect
    4. How We Use Your Information
    5. SMS / Text Messaging Consent (A2P 10DLC)
    6. Sharing & Disclosure of Information
    7. Data Retention
    8. Your Rights Under HIPAA
    9. California Consumer Privacy Act (CCPA)
    10. Cookies & Tracking Technologies
    11. Third-Party Links & Services
    12. Children's Privacy (COPPA)
    13. Security Measures
    14. Changes to This Policy
    15. Contact Our Privacy Officer

    1Who We Are & Scope of This Policy

    This Privacy Policy applies to Dr. Hassan Nasser, MD ("Dr. Nasser," "Detroit Face MD," "we," "us," or "our"), a board-certified otolaryngologist with fellowship training in head and neck surgical oncology, licensed in the State of Michigan, operating at offices in Dearborn, MI and serving patients throughout Metro Detroit and Southeast Michigan.

    This policy governs the collection, use, storage, and disclosure of personal information and Protected Health Information (PHI) obtained through:

    • Our website at karmaxdesign.com and all associated subdomains
    • Online contact forms and appointment request submissions
    • SMS/text messaging communications
    • Email correspondence
    • Phone calls and voicemail
    • In-office patient interactions
    • Patient portals and electronic health record (EHR) systems

    By using our website or submitting any form of communication to our practice, you acknowledge that you have read and agree to this Privacy Policy.

    2HIPAA Notice of Privacy Practices

    Federal Law Requirement

    This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully. This notice is required by the Health Insurance Portability and Accountability Act of 1996 (HIPAA), 45 CFR Parts 160 and 164.

    Our Duties Under HIPAA

    As a covered healthcare entity, Dr. Hassan Nasser's practice is required by law to:

    • Maintain the privacy of your PHI
    • Provide you with this notice of our legal duties and privacy practices
    • Follow the terms of the notice currently in effect
    • Notify you in the event of a breach of your unsecured PHI

    Permitted Uses & Disclosures of PHI

    We may use or disclose your PHI without your authorization for the following purposes:

    • Treatment: We may use and disclose PHI to provide, coordinate, or manage your care with referring physicians, specialists, hospitals, and other healthcare providers.
    • Payment: We may use and disclose PHI to obtain payment for services, including submission of claims to your insurance company or Medicare/Medicaid.
    • Healthcare Operations: We may use PHI for quality improvement, training, licensing, credentialing, and business management activities.
    • Required by Law: We may disclose PHI when required to do so by federal, state, or local law, including public health authorities and law enforcement under lawful processes.
    • Business Associates: We may share PHI with vendors (Business Associates) who assist us under signed Business Associate Agreements (BAAs) that obligate them to protect your information.

    Uses Requiring Authorization

    We will not use or disclose your PHI for marketing purposes, for sale to third parties, or for psychotherapy notes without your written authorization. You may revoke any authorization at any time in writing.

    3Information We Collect

    Information You Provide Directly

    • Full name, date of birth, and gender
    • Contact information (address, phone number, email address)
    • Health insurance information and policy numbers
    • Medical history, symptoms, diagnoses, and treatment preferences
    • Appointment requests and scheduling information
    • Communications submitted via our contact and consultation forms
    • SMS opt-in consent and phone number for text communications

    Information Collected Automatically

    • IP address, browser type, operating system, and device type
    • Pages visited, time on site, referring URLs, and click paths
    • Geographic location at the city/state level
    • Cookies, pixel tags, and session identifiers (see Section 10)

    Information from Third Parties

    • Referring physicians and healthcare providers
    • Insurance companies and third-party payers
    • Hospitals and care coordination networks

    4How We Use Your Information

    We use the information we collect to:

    • Schedule and confirm appointments and consultations
    • Provide medical care and coordinate treatment with other healthcare providers
    • Process billing and insurance claims
    • Send appointment reminders, post-care instructions, and follow-up communications via phone, email, or SMS (where consent has been given)
    • Respond to inquiries submitted through our website or by phone
    • Improve our website functionality and patient experience
    • Comply with legal and regulatory obligations
    • Conduct quality assurance and practice management activities

    Important: This website does not provide medical advice. Information on this site is for educational purposes only. Always consult Dr. Nasser or a qualified physician for medical decisions. No physician-patient relationship is established by use of this website.

    5SMS / Text Messaging Consent (A2P 10DLC)

    A2P 10DLC Registered

    Our SMS/text messaging program is registered under the A2P 10DLC framework with The Campaign Registry (TCR) in compliance with CTIA guidelines and the Telephone Consumer Protection Act (TCPA), 47 U.S.C. § 227.

    Types of Text Messages We May Send

    By providing your mobile phone number and consenting to text communications, you agree to receive the following message types from Dr. Hassan Nasser's practice:

    • Appointment Reminders: Confirmations, reminders, and cancellation notifications.
    • Care Coordination: Post-operative instructions, pre-surgical preparation reminders, and follow-up care guidance.
    • Transactional Messages: Responses to your submitted inquiries or form submissions.
    • Practice Updates: Important announcements about office hours, closures, or safety protocols.

    Standard SMS Disclosures

    • Message Frequency: Message frequency varies based on your appointments and inquiries, typically 1–4 messages per month.
    • Message & Data Rates: Standard message and data rates may apply. Contact your wireless carrier for details.
    • Opt-Out: Reply STOP to any text message at any time to unsubscribe from all non-emergency text communications. You will receive one final confirmation message.
    • Help: Reply HELP for assistance or contact our office at (313) 555-0100.
    • No PHI in Marketing Texts: We do not include Protected Health Information in marketing text messages. Care-coordination messages containing PHI are sent only where permitted under HIPAA and with your consent.
    • No Third-Party Sharing for Marketing: Your mobile number will not be shared with third parties for their marketing purposes.
    • Consent is Not a Condition of Treatment: Providing consent to receive text messages is never a condition of receiving medical care or services from our practice.

    How Consent is Obtained

    Express written consent to receive text messages is obtained through:

    • Our website consultation request form (opt-in checkbox with disclosure language)
    • New patient intake forms completed at our office
    • Verbal consent documented in your patient record by a staff member

    We maintain records of all SMS opt-in consents including the date, time, source, and phone number for compliance purposes.

    6Sharing & Disclosure of Information

    We do not sell, rent, or trade your personal information or PHI. We may share your information in the following limited circumstances:

    • Healthcare Providers: We may share PHI with referring physicians, specialists, hospitals, anesthesiologists, and other providers involved in your care.
    • Business Associates: We may share information with vendors who provide services on our behalf (e.g., EHR platforms, billing services, appointment reminder systems) under signed Business Associate Agreements.
    • Insurance & Billing: We may disclose information to your insurance company or Medicare/Medicaid for payment and claims adjudication.
    • Legal Requirements: We may disclose information when required by law, court order, subpoena, or government agency request.
    • Public Health & Safety: We may disclose information to prevent a serious threat to your health or safety, or that of others, as permitted by law.
    • Google Analytics & Advertising: We use Google Analytics (with IP anonymization enabled) to analyze website traffic. This service processes anonymized, non-PHI data subject to Google's Privacy Policy. We do not share PHI with advertising platforms.

    7Data Retention

    We retain medical records and PHI in accordance with Michigan law and HIPAA requirements. Under MCL 333.16213, medical records for adult patients are retained for a minimum of 7 years from the date of service. Records for minors are retained until the patient reaches age 18 plus an additional 7 years, or until the patient reaches age 28, whichever is later.

    Non-PHI website analytics data is retained per the retention policies of the respective analytics platform. SMS consent records are retained for a minimum of 5 years from the date of opt-in or opt-out.

    8Your Rights Under HIPAA

    You have the following rights with respect to your Protected Health Information:

    • Right of Access: You have the right to inspect and obtain a copy of your medical records and PHI maintained by our practice.
    • Right to Amend: You may request that we amend your PHI if you believe it is inaccurate or incomplete.
    • Right to an Accounting of Disclosures: You may request a list of disclosures of your PHI made outside of treatment, payment, and operations for the 6 years prior to your request.
    • Right to Request Restrictions: You may request restrictions on how we use or disclose your PHI, though we are not required to agree to your request in all cases.
    • Right to Confidential Communications: You may request that we communicate with you about your health in a specific way or at a specific location.
    • Right to a Paper Copy of This Notice: You may request a paper copy of this Notice of Privacy Practices at any time, even if you received it electronically.
    • Right to File a Complaint: If you believe your privacy rights have been violated, you may file a complaint with our Privacy Officer or with the U.S. Department of Health & Human Services (HHS) Office for Civil Rights at 1-800-368-1019 or www.hhs.gov/ocr/privacy. You will not be retaliated against for filing a complaint.

    To exercise any of these rights, please submit a written request to our Privacy Officer at the contact information in Section 15.

    9California Consumer Privacy Act (CCPA)

    While our primary operations are in Michigan, we respect the privacy rights of California residents. To the extent applicable, California residents have rights including the right to know what personal information we collect, the right to delete personal information, and the right to opt-out of the sale of personal information. We do not sell personal information. PHI collected in the course of providing medical services is exempt from CCPA under the HIPAA exemption. For non-PHI requests, please contact our Privacy Officer.

    10Cookies & Tracking Technologies

    Our website uses cookies and similar technologies to enhance your browsing experience. These include:

    • Essential Cookies: Required for core website functionality.
    • Analytics Cookies: Google Analytics (anonymized) to understand aggregate site usage.
    • Preference Cookies: To remember your settings and preferences.

    We do not use tracking technologies to collect PHI. You may disable cookies in your browser settings; however, some functionality may be limited. PHI is never stored in cookies.

    11Third-Party Links & Services

    Our website may contain links to third-party sites such as patient financing platforms (CareCredit), insurance portals, or informational medical resources. These sites operate under their own privacy policies. We are not responsible for the privacy practices or content of third-party sites and encourage you to review their policies before providing any personal information.

    12Children's Privacy (COPPA)

    Our website is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 without verifiable parental consent. If you believe a child under 13 has submitted personal information through our website, please contact us immediately at the information in Section 15, and we will promptly delete it. For pediatric patients, parents or legal guardians may exercise HIPAA rights on the minor's behalf as permitted by applicable law.

    13Security Measures

    We implement industry-standard administrative, physical, and technical safeguards to protect your PHI and personal information, including:

    • 256-bit SSL/TLS encryption for all data transmitted via our website
    • HIPAA-compliant EHR and practice management systems with audit logging
    • Access controls limiting PHI access to authorized personnel only
    • Regular risk assessments and security training for all staff
    • Signed Business Associate Agreements with all vendors handling PHI
    • Breach notification procedures compliant with HIPAA Breach Notification Rule (45 CFR §§ 164.400–414)

    No method of transmission or storage is 100% secure. In the event of a breach affecting your PHI, we will notify you in accordance with HIPAA requirements within the timeframes mandated by law.

    14Changes to This Policy

    We reserve the right to update or modify this Privacy Policy and Notice of Privacy Practices at any time. We will post the revised policy with an updated "Last Updated" date on this page. For material changes affecting PHI, we will provide notice as required by HIPAA. Continued use of our website or services after a posted change constitutes acceptance of the updated policy.

    15Contact Our Privacy Officer

    For questions, concerns, access requests, or to file a complaint regarding your privacy rights, please contact:

    Privacy Officer

    Dr. Hassan Nasser's Practice — Privacy Officer
    ADDRESSDearborn, MI 48124
    privacy@detroitfacemd.com

    File a Complaint with HHS

    If you feel your rights have been violated, you may also contact:

    U.S. Department of Health & Human Services
    Office for Civil Rights
    1-800-368-1019
    hhs.gov/ocr/privacy

    You will not be retaliated against for filing a complaint.

    For all other inquiries, please visit our contact page.