Privacy Policy
Effective September 9, 2026
This Privacy Policy describes how Wire Briar LLC, a Utah limited liability company located in Mapleton, Utah ("Wire Briar," "we," "us," or "our"), collects, uses, and shares information through our website at dermhipaa.com and our related tools at check.dermhipaa.com and checkup.dermhipaa.com (together, the "Website"). By using the Website, you agree to the collection and use of information as described in this Privacy Policy.
- Scope of This Policy
- Do Not Submit Protected Health Information
- Information We Collect
- The Email Security Check
- The HIPAA Checkup
- How We Use Information
- Cookies and Analytics
- Do Not Track and Global Privacy Control
- How We Share Information
- Email Marketing
- Data Retention
- Your Choices and Rights
- Security
- Children's Privacy
- Links to Other Websites
- Changes to This Privacy Policy
- Contact Us
1. Scope of This Policy
This Privacy Policy applies only to the Website: the publicly available marketing and informational pages at dermhipaa.com, the email security check at check.dermhipaa.com, and the HIPAA Checkup course and self-assessment at checkup.dermhipaa.com, including any contact forms and requests for written results.
This Privacy Policy does not apply to any DermHIPAA client portal or client environment, including app.dermhipaa.com. Information processed in the course of providing services to a client is governed exclusively by the written agreements between Wire Briar and that client, including any Master Services Agreement, Service Order, and Business Associate Agreement (collectively, "Client Agreements"). In the event of any conflict between this Privacy Policy and a Client Agreement, the Client Agreement controls with respect to those services.
2. Do Not Submit Protected Health Information
The Website is not intended or designed to receive protected health information ("PHI") as defined under HIPAA, or any other patient, medical, or health information about any identifiable individual. Do not include PHI or patient information in any form, email, checkup answer, or other communication submitted through the Website.
Your use of the Website does not create a business associate relationship with Wire Briar, and no Business Associate Agreement applies to information submitted through the Website. If PHI is submitted through the Website in violation of this Section, we may delete it without notice.
3. Information We Collect
Information you provide to us. We collect information you voluntarily provide when you:
- request the written results of the email security check or the HIPAA Checkup (your name, if you give one, and your email address, together with the results being sent);
- tell us that your practice uses Microsoft 365 rather than Google Workspace, where a form offers that option;
- enter a domain name into the email security check; or
- email us, or otherwise communicate with us.
Information collected automatically. When you visit the Website, we and our service providers automatically collect certain technical information, such as your browser type, device type, operating system, referring pages, pages visited, and the dates and times of your visits. This information is collected through server logs, cookies, and similar technologies, including the analytics tools described in Section 7. Our hosting infrastructure may keep standard, short-lived server logs, including IP addresses, for security and operational purposes; we do not use those logs to identify visitors, and our own application records do not store IP addresses.
We do not collect sensitive personal information through the Website, and we ask that you not submit any (see Section 2).
4. The Email Security Check
The email security check at check.dermhipaa.com reads publicly available Domain Name System (DNS) records for a domain name you enter, and reports what those public records say. It does not send email to or from the domain, does not attempt to access any system, and does not require or use any credential.
We keep a record of the domain names checked and the date and time of each check, so that we can understand how the tool is used and respond if you later contact us about a check you ran. That record does not include your IP address. If you ask us to email you the written results, we also store your email address, any name you provide, and a copy of the findings we sent you, so that we have a record of what we sent and to whom.
5. The HIPAA Checkup
Your answers stay in your browser unless you ask us for the report. As you work through the HIPAA Checkup, your answers are stored only on your own device so you can leave and come back. They are not transmitted to us.
If, and only if, you ask us to email you the written results, your answers are sent to us at that moment together with your email address, and we store them as a record of what we sent you. If you never request the report, we never receive your answers.
We will not contact you about a checkup you took unless you asked us to send you the results.
The HIPAA Checkup is a self-assessment that you complete about your own organization. It is not an audit, an inspection, a certification, or a legal or compliance determination, and its result is a count of the items you told us are in place rather than an evaluation of your compliance. See our Terms & Conditions, which explain that we do not provide legal or compliance advice through the Website.
We may use answers submitted with report requests in aggregate and de-identified form, to understand which safeguards dermatology practices most often lack and to improve our course and our services. We will not publish or disclose the answers, results, or identity of any individual practice.
6. How We Use Information
We use the information we collect to:
- generate and send you the written results you request;
- respond to your inquiries;
- send you email about DermHIPAA if you have asked to hear from us, which you may opt out of at any time (see Section 10);
- operate, analyze, and improve the Website, our course, and our services;
- protect the security and integrity of the Website; and
- comply with applicable laws and legal processes.
7. Cookies and Analytics
The Website uses cookies, local browser storage, and similar technologies. A cookie is a small data file stored on your device by your browser. We use the following categories:
- Essential. Used to operate the Website and its basic functions, and to remember your analytics choice. The HIPAA Checkup uses your browser's local storage to hold your answers on your own device so that you can leave and return; that storage is not transmitted to us.
- Analytics. We use Google Analytics 4 to understand how visitors use the Website, for example which pages are visited and for how long. Google Analytics uses cookies and collects information such as your IP address and device identifiers. You can learn how Google uses this data at policies.google.com/technologies/partner-sites, and you can opt out of Google Analytics using Google's browser opt-out add-on at tools.google.com/dlpage/gaoptout.
Your choices. A notice on the Website lets you decline analytics cookies at any time, and declining disables Google Analytics on your device. Most browsers also allow you to refuse or delete cookies through browser settings, though some Website features may not function correctly without them.
We do not use advertising cookies, and we do not run advertising on the Website.
8. Do Not Track and Global Privacy Control
Some browsers transmit "Do Not Track" signals or Global Privacy Control (GPC) preferences. Because there is no consistent industry standard for interpreting these signals, the Website does not currently respond to them. You can manage tracking through the analytics controls described in Section 7.
9. How We Share Information
We do not sell your personal information, and we do not share your personal information with third parties for their own marketing purposes.
We share information only in the following circumstances:
- Service providers. We use third-party service providers to operate our business, and they may process your information on our behalf. These include providers of website hosting, cloud infrastructure and productivity tools (such as Google Workspace, Google Cloud, and Cloudflare), email delivery, video hosting, and analytics services as described in Section 7. Service providers are authorized to use your information only to perform services for us.
- Legal compliance. We may disclose information to comply with applicable law, regulation, legal process, or governmental request; to enforce our Terms & Conditions; or to protect the rights, property, or safety of Wire Briar, our users, or others.
- Business transfers. If Wire Briar is involved in a merger, acquisition, financing, or sale of all or a portion of its business or assets, your information may be transferred to the successor or acquirer as part of that transaction, subject to this Privacy Policy or a policy that is at least as protective.
10. Email Marketing
We comply with the federal CAN-SPAM Act. Every marketing email we send includes an unsubscribe mechanism, and you may opt out of marketing email at any time by using that mechanism or by emailing legal@dermhipaa.com. If you opt out of marketing email, we may still send you transactional or administrative messages, such as the written results you specifically requested or a reply to your inquiry.
Because email is not a fully secure form of communication, please do not include sensitive information, and never PHI, in email you send to us.
We do not currently send marketing text messages.
11. Data Retention
We retain personal information collected through the Website for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, for example to respond to your inquiry, to keep a record of results we sent you, or to meet legal, accounting, or reporting obligations, and then delete or anonymize it. You may request deletion of your information at any time as described in Section 12.
12. Your Choices and Rights
Regardless of where you live, we extend the following choices to all visitors. You may contact us at legal@dermhipaa.com to:
- request access to the personal information we hold about you;
- request that we correct inaccurate personal information;
- request that we delete your personal information, including any checkup answers you sent us; or
- opt out of marketing communications.
We will respond to verifiable requests within a reasonable timeframe. We may need to verify your identity before fulfilling a request, and we may decline requests where retention is required by law.
13. Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect the information collected through the Website, including encryption in transit (HTTPS) and access controls on our internal systems. However, no method of transmission over the Internet or method of electronic storage is fully secure, and we cannot guarantee absolute security.
14. Children's Privacy
The Website is not directed at children, and we do not knowingly collect personal information from children under 13 years of age, consistent with the Children's Online Privacy Protection Act (COPPA). The Website is intended for users who are at least 18 years old. If you are a parent or guardian and believe a child under 13 has provided personal information through the Website, please contact us at legal@dermhipaa.com and we will delete it.
15. Links to Other Websites
The Website may contain links to third-party websites, including primary sources such as government regulations and reports that we cite in our course. These websites are not under our control and are not subject to this Privacy Policy. We have no responsibility for the content or privacy practices of third-party websites, and we encourage you to review their privacy policies.
16. Changes to This Privacy Policy
We may modify this Privacy Policy from time to time to reflect changes in privacy laws or our business practices. When we do, we will post the updated policy on this page and revise the Effective Date above. Material changes may also be announced by a notice on the Website. Your continued use of the Website after an updated Privacy Policy is posted constitutes your acceptance of the changes. We encourage you to review this page periodically.
17. Contact Us
Questions or requests regarding this Privacy Policy may be directed to:
Wire Briar LLC
Mapleton, Utah
Email: legal@dermhipaa.com