PRIVACY POLICY

Flourish Cognitive HealthLast Updated: March 2026

Our Commitment to Your Privacy

At Flourish Cognitive Health, your privacy is not an afterthought. It is a foundational part of the care relationship we are building with you. This policy explains what information we collect, how we use it, and how we protect it - in plain language, because you deserve to understand exactly how your information is handled.

Flourish Cognitive Health operates as a direct specialty care practice. This means we do not bill insurance directly and we do not participate in insurance networks. This model exists by design — it allows us to provide the depth, time and clinical integrity that meaningful dementia prevention requires. It also shapes how we handle your health information, as described below.

1. Who We Are

Flourish Cognitive Health is a direct specialty care practice located at:

4198 Cox Road Glen Allen, Virginia 23060

Physician: Dr. Amy Paul, MD, DipIBLM Contact: dramy@flourishcognitivehealth.com Website: www.flourishcognitivehealth.com

2. Information We Collect

We collect information in two ways — information you provide to us directly, and information collected automatically when you use our website.

Information you provide directly:

When you book a consultation, complete our intake forms, or contact us, we may collect:

  • Your name, email address, phone number and mailing address

  • Date of birth and demographic information

  • Health and medical history relevant to your brain health and cognitive risk

  • Information about family members with cognitive or memory conditions

  • Payment information processed through our secure payment partners

  • Communications you send to us by email, phone or through our website contact form

Information collected automatically:

When you visit our website, standard web technologies may collect:

  • Your IP address and browser type

  • Pages visited and time spent on the site

  • Referring website or search terms that brought you to us

  • Device type and operating system

We use this information solely to understand how our website is being used and to improve the experience for our visitors. We do not sell this data or use it for advertising purposes.

3. How We Use Your Information

We use the information we collect to:

  • Provide, coordinate and improve the clinical services you have requested

  • Communicate with you about your appointments, results and care plan

  • Send you health education content and brain health resources you have opted into

  • Process payments for services rendered

  • Comply with applicable laws and professional obligations

  • Respond to your questions and requests

We will never use your information to sell you products unrelated to your care, and we will never sell your personal information to third parties.

4. HIPAA and Your Health Information

As a physician-led specialty care practice, Flourish Cognitive Health is a covered entity under the Health Insurance Portability and Accountability Act (HIPAA). Your protected health information (PHI) — including your medical history, cognitive assessment results, and care plan — is protected under federal law.

Your rights under HIPAA include the right to:

  • Access and receive a copy of your health information

  • Request corrections to your health information

  • Know how your health information has been shared

  • Request restrictions on how your information is used or disclosed

  • Receive this notice of our privacy practices

How we may share your health information

As a direct specialty care practice, we do not submit claims to insurance companies. However, we may share your health information in the following limited circumstances:

  • With your consent — when you ask us to share your Brain Health and Prevention Plan or assessment results with your primary care physician or another provider

  • For treatment purposes — when coordinating your care with other healthcare professionals involved in your treatment

  • As required by law — including mandatory reporting obligations and legal proceedings

  • For public health activities — such as reporting communicable diseases as required by Virginia law

  • In a medical emergency — to protect your health or safety

We will not share your health information for marketing purposes without your explicit written consent.

5. Our Website and Third-Party Services

Our website is hosted on Squarespace. Our appointment booking is managed through Google Calendar. Our email list is managed through Kit (formerly ConvertKit). Our supplement partnership is through Thorne.

Each of these services maintains their own privacy policies. We encourage you to review them:

  • Squarespace: squarespace.com/privacy

  • Google: policies.google.com/privacy

  • Kit: kit.com/privacy

  • Thorne: thorne.com/privacy-policy

Our brain health quiz (hosted at flourish-brain-health-quiz.netlify.app) collects your name and email address when you opt in to receive your results and the MEMORY™ Brain Health Guide. This information is added to our email list through Kit. You may unsubscribe at any time.

6. Email Communications

If you subscribe to our email list — through our website, our brain health quiz, or by providing your email during a consultation — you will receive:

  • Your requested resources, such as the MEMORY™ Brain Health Guide

  • Brain health education content from Dr. Amy Paul

  • Updates about Flourish Cognitive Health services and events

You may unsubscribe at any time by clicking the unsubscribe link at the bottom of any email. We will process your request promptly. Unsubscribing from our email list does not affect clinical communications related to your care.

7. Data Security

We take reasonable and appropriate measures to protect your personal and health information from unauthorized access, disclosure, alteration and destruction. These measures include:

  • Encrypted communications for clinical information

  • Secure, password-protected systems for patient records

  • Limited access to your information on a need-to-know basis

  • Regular review of our security practices

No method of electronic transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security. If you have concerns about the security of your information, please contact us directly.

8. Children's Privacy

Our services are designed for adults aged 18 and older. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child, please contact us immediately and we will delete it.

9. Your Rights and Choices

Access and correction: You may request access to the personal information we hold about you and ask us to correct any inaccuracies.

Deletion: You may request that we delete your personal information, subject to our legal and professional obligations to retain certain records.

Opt-out: You may opt out of non-clinical email communications at any time by using the unsubscribe link in any email or by contacting us directly.

Data portability: You may request a copy of your personal information in a commonly used format.

To exercise any of these rights, contact us at: dramy@flourishcognitivehealth.com

We will respond to all requests within 30 days.

10. Virginia Privacy Rights

Virginia residents have additional rights under the Virginia Consumer Data Protection Act (VCDPA), including the right to:

  • Confirm whether we process your personal data

  • Access your personal data

  • Correct inaccuracies in your personal data

  • Delete your personal data

  • Obtain a copy of your personal data in a portable format

  • Opt out of the processing of your personal data for targeted advertising

To exercise your Virginia privacy rights, contact us at dramy@flourishcognitivehealth.com. We will respond within 45 days, with the possibility of a 45-day extension when reasonably necessary.

11. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices, legal requirements or technology. When we make significant changes, we will update the "Last Updated" date at the top of this policy and notify active patients by email.

We encourage you to review this policy periodically.

12. Contact Us

If you have questions, concerns or requests related to this privacy policy or the handling of your information, please contact us:

Flourish Cognitive Health Dr. Amy Paul, MD, DipIBLM 4198 Cox Road, Glen Allen, VA 23060 dramy@flourishcognitivehealth.comwww.flourishcognitivehealth.com