Last Updated: 04 August 2026
Tiny Dental Company ('we,' 'us,' or 'our') operates https://www.tinydentalco.com/ and provides dental and oral healthcare services ('Services'). This Privacy Policy explains how we collect, use, disclose, and protect information about patients, responsible parties, and website visitors.
By accessing our Website, scheduling an appointment, or receiving care at our practice, you acknowledge that you have read and understood this Privacy Policy.
We are committed to protecting patient confidentiality and maintaining compliance with applicable federal and state law, including but not limited to:
The following terms are used throughout this Policy. Where context requires, words in the singular include the plural and vice versa.
We may collect information from patients, responsible parties, and visitors to our Website in order to provide dental care, process payments, comply with legal obligations, and improve our Services. The categories of information we may collect include but are not limited to the following:
3.1 Patient and Responsible Party Information
We may collect information necessary for diagnosis, treatment, billing, and follow-up, including but not limited to: full name, date of birth, gender, and contact details; dental and medical history, treatment plans, and imaging records; insurance details and billing information; payment methods; emergency contact details; and referral information from or to other healthcare providers. By providing your phone number, you consent to receive appointment reminders and practice-related communications by SMS text message, in addition to email. You may opt out of SMS communications at any time as described in Section 4.5.
3.2 Automatically Collected Website Information
When you visit our Website or use our online services, we and our Trusted Third Parties may automatically collect certain technical and usage information, including but not limited to:
3.3 Website Contact and Form Submissions
Our Website uses tools to help measure and improve the quality of our services. Calls to our practice and form submissions made through our Website may be recorded and accessed by Trusted Third Parties engaged by us for quality assurance and marketing performance purposes. Such recordings and submissions may be used to improve our services and assess the effectiveness of our marketing.
3.4 Information You Provide Voluntarily
Patients and visitors may voluntarily provide information through online appointment request forms, contact forms, feedback surveys, or direct communication with our staff by phone, email, or other means.
We may use information collected from patients, responsible parties, and website visitors for the purposes described below. Our use of information is guided by the principle of minimum necessity - we use only the information reasonably required for the stated purpose.
4.1 Primary Uses - Core Healthcare Functions
We may use your information for purposes including but not limited to: providing, coordinating, and managing dental care; appointment scheduling, confirmation, and reminders; billing, insurance processing, and payment collection; maintaining dental and medical records as required by law; and coordinating care with other healthcare providers, dental laboratories, and specialists involved in your treatment.
4.2 Marketing, Analytics, and Service Improvement
We may use website interaction data and similar information in anonymized and aggregated form to measure the effectiveness of our marketing, understand how visitors use our Website, and improve the services we offer. Trusted Third Parties engaged by us may also use such data on our behalf for reporting, benchmarking, and optimization purposes.
4.3 Legally Required Uses
We may be required by law to use or disclose information without your consent in certain circumstances, including but not limited to: public health reporting obligations; responding to court orders, subpoenas, or lawful requests from law enforcement; complying with dental board or regulatory oversight requirements; and insurance audit obligations.
4.4 Restrictions on Use
We do not sell, rent, or trade personal or health information. We do not use PHI for marketing purposes without your prior written authorization. We adhere to HIPAA's minimum necessary standard - we use only the information required for each stated purpose.
4.5 SMS / Text Message Communications
By providing your phone number and opting into SMS communications from us, you agree to receive text messages related to appointment reminders, scheduling updates, office notifications, billing alerts, and other practice-related communications. Message frequency varies based on your appointments and account activity. You may cancel SMS messages at any time by replying STOP to any message you receive from us. We will send a confirmation message once you have been unsubscribed, after which no further SMS messages will be sent. To re-subscribe, contact us directly or opt in again as you did the first time. If you experience issues with our messaging program or need assistance, reply HELP to any message, or contact us directly. Carriers are not liable for delayed or undelivered messages. Message and data rates may apply for messages sent to you from us and to us from you. If you have questions about your text or data plan, please contact your wireless provider.
We disclose information only as described in this Policy, as required by law, or with your authorization. All disclosures are made in accordance with HIPAA's minimum necessary standard. We do not sell patient data.
5.1 Disclosures for Dental Care and Operations
We may disclose information to third parties involved in your care or the operation of our practice, including but not limited to: treating providers and specialists; dental laboratories; pharmacies; insurance companies; billing service providers; and practice management technology vendors. Such disclosures are made only to the extent necessary for the relevant purpose.
5.2 Trusted Third-Party Service Providers
We may engage Trusted Third Parties to perform certain functions on our behalf. These functions may include but are not limited to: website hosting and management; appointment scheduling; payment processing; data analytics and marketing performance measurement; call quality assurance; and related administrative or operational services. Trusted Third Parties may access certain information only to the extent necessary to perform the specific services for which they have been engaged. They are contractually prohibited from using such information for their own independent purposes.
5.3 Call Recording and Website Submissions
Calls to our practice and form submissions made through our Website may be recorded or collected. These recordings and submissions may be accessed by Trusted Third Parties engaged by us for quality assurance and marketing performance purposes. They are not used for advertising targeting, are not used to identify individual patients for marketing purposes, and any Protected Health Information contained within them is handled in accordance with HIPAA.
5.4 Legal and Regulatory Disclosures
We may disclose information when required by applicable law, including but not limited to: court orders and subpoenas; valid law enforcement requests; regulatory oversight by dental boards or health departments; and mandatory public health reporting obligations.
5.5 De-Identified and Aggregate Data
We may use or share de-identified data or Aggregate Data for purposes including but not limited to practice management analytics, treatment outcome reporting, and marketing performance statistics. Such data cannot reasonably be used to identify any individual patient and does not constitute PHI.
Our Website uses a range of tracking technologies to support site functionality, analytics, and marketing. By using our Website, you consent to the use of these technologies as described below.
6.1 Cookies
Our Website uses cookies - small data files stored on your device - to improve site functionality, personalize your experience, and identify returning visitors. Cookie usage on this Website is not linked to individually identifiable health information. You may manage cookie preferences through your browser settings, though disabling certain cookies may affect the functionality of some areas of our Website.
6.2 Analytics Tools
We may use third-party analytics tools to understand how visitors interact with our Website. Information collected through analytics tools is used in aggregate and anonymized form and is not used to identify individual patients or to access Protected Health Information.
6.3 Advertising Measurement
Our Website may use advertising measurement tools to assess the effectiveness of our marketing campaigns. These tools measure whether visits to our website resulted from our advertising activity and are used for performance reporting purposes only. Any data collected through these tools is handled in accordance with the applicable platform provider's terms and our obligations under HIPAA.
6.4 Website Recording and Interaction Tools
Our Website may use tools that record visitor interactions including but not limited to mouse movements, scrolling behavior, and page clicks, for the purpose of improving website design and user experience. Where such tools are in use, they are configured to prevent the capture of information entered into form fields. They are not deployed on pages where patients submit health-related information.
We maintain administrative, technical, and physical safeguards designed to protect personal and health information against unauthorized access, use, disclosure, alteration, or destruction, in accordance with the HIPAA Security Rule and applicable state law.
We retain dental, medical, administrative, and communication records for as long as necessary to provide care, comply with applicable legal obligations, support claims resolution, and maintain accurate business and compliance records. Retention periods may vary based on applicable state dental board regulations and other legal requirements.
Categories of information we retain include but are not limited to:
9.1 Definition of a Breach
A breach is the unauthorized acquisition, access, use, or disclosure of Protected Health Information or Personal Information that compromises its privacy or security, as defined under HIPAA's Breach Notification Rule and applicable state law. Examples include but are not limited to: cyberattacks, ransomware, loss or theft of devices containing patient data, unauthorized employee access, and accidental disclosure.
9.2 Patient Notification
If a breach is confirmed, we will notify affected patients within 60 days of discovering the breach, in accordance with HIPAA's Breach Notification Rule and the Texas Identity Theft Enforcement and Protection Act (Texas Business & Commerce Code § 521.053).
9.3 Regulatory Notification
In addition to notifying affected patients, we will notify the relevant regulatory authorities as required by HIPAA's Breach Notification Rule and applicable state law, including but not limited to the U.S. Department of Health and Human Services, Office for Civil Rights.
Subject to applicable law, you may have the following rights regarding your information. To exercise any of these rights, please contact us using the details outlined at the end. We will respond within the timeframe required by applicable law.
Your rights under this Privacy Policy include but are not limited to:
Our Website uses tools to help us measure and improve the quality of our services. Calls to our practice and form submissions made through our Website may be recorded and accessed by Trusted Third Parties engaged by us for quality assurance and marketing performance purposes. Such information is used to improve our services and measure the effectiveness of our marketing. It is not used for advertising targeting and any Protected Health Information is handled in accordance with HIPAA.
12.1 Parental Consent and Authority
Where the practice treats minor patients, all collection, use, and disclosure of a minor patient's Protected Health Information is subject to the consent and authority of the minor's parent or legal guardian, except where applicable state law grants adolescents independent privacy rights for specific categories of care. Parents and legal guardians are recognized as personal representatives of minor patients under HIPAA and have the right to access, amend, and request restrictions on their child's Protected Health Information.
12.2 COPPA Compliance (Children Under 13)
We do not knowingly collect Personal Information directly from children under the age of 13 without verifiable parental or guardian consent. All online forms, scheduling tools, and appointment systems on our Website are designed for use by parents and guardians on behalf of minor patients. If we become aware that we have inadvertently collected information directly from a child under 13 without parental consent, we will delete that information promptly.
12.3 Adolescent Confidentiality (Ages 13-17)
We recognize that adolescent patients may have legally protected confidentiality rights for certain categories of care under applicable state law, including but not limited to mental health services, reproductive health, and substance use treatment. Where such rights apply, records relating to confidential services may be maintained separately from the general patient record to prevent unauthorized parental access. We follow the applicable confidentiality rules of the state in which care is provided.
12.4 Advertising and Marketing
Any marketing activity conducted on our behalf is configured to target parents, guardians, and adult prospective patients only. We do not engage in behavioral advertising directed at minors. Advertising measurement tools on our Website are not used to collect data from minors and are not deployed on pages where minor patients' health information may be submitted.
12.5 Call Recording - Parental Representative Context
Our Website uses tools to help us measure and improve the quality of our services. Calls to our practice and form submissions made through our Website may be recorded and accessed by Trusted Third Parties engaged by us for quality assurance and marketing performance purposes. If you are contacting us as a parent or legal guardian on behalf of a minor patient, your consent covers any discussion of your child's care. Such recordings and submissions are used to improve our services and measure the effectiveness of our marketing - they are not used for advertising targeting, and any Protected Health Information is handled in accordance with HIPAA.
12.6 Data Retention for Minor Patients
Records for minor patients are retained until the patient reaches the age of majority under applicable state law, plus the legally mandated minimum retention period for that state (typically 7 to 10 additional years). For example, where state law requires 7 years' retention and a patient is first seen at age 8, the record will be retained until the patient turns 25.
12.7 Age Transition
As minor patients reach the age of majority under applicable law, they assume independent rights over their own Protected Health Information. From that point, parental or guardian access to the patient's records requires the adult patient's own written authorization. Where a patient begins treatment as a minor and completes treatment as an adult, the applicable rights during each phase of treatment are determined by the patient's age at that time.
12.8 Mandatory Reporting
As licensed healthcare providers serving minor patients, we are mandated reporters under applicable federal and state law. We may disclose information about a minor patient without parental or guardian consent where required by law, including but not limited to: suspected or confirmed child abuse or neglect; threats of harm to the patient or others; and communicable disease reporting obligations. Such disclosures are limited to the minimum information necessary to fulfill the applicable legal obligation.
This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully.
Tiny Dental Company is committed to protecting the privacy of your health information. We are required by the Health Insurance Portability and Accountability Act of 1996 (HIPAA), its implementing regulations, and applicable Texas state laws — including the Texas Medical Records Privacy Act (TMRPA, Chapter 181 of the Texas Health and Safety Code) — to maintain the privacy of your Protected Health Information (PHI), to provide you with this Notice of our legal duties and privacy practices with respect to your PHI, and to abide by the terms of the Notice currently in effect.
In accordance with the Texas Medical Records Privacy Act (HB 300), we are required to inform you that your Protected Health Information may be disclosed electronically. Electronic disclosures of your PHI without your authorization are limited to purposes of treatment, payment, healthcare operations, and certain other purposes as permitted or required by law. Any electronic disclosure of your PHI beyond these permitted purposes requires your written authorization.
We may use and disclose your PHI for the following purposes:
Treatment: We may use your health information to provide, coordinate, or manage your dental care and any related services. For example, we may share your health information with a specialist or other healthcare provider to whom you have been referred for treatment.
Payment: We may use and disclose your health information to obtain payment for services we provide to you. For example, we may send information to your dental insurance company to receive payment for treatment.
Healthcare Operations: We may use and disclose your health information in connection with our healthcare operations, including quality assessment and improvement activities, reviewing the competence or qualifications of healthcare professionals, and conducting training programs.
As Required by Law: We will disclose your health information when required to do so by federal, state, or local law.
Public Health Activities: We may disclose your health information for public health activities, such as reporting diseases, injuries, and vital events as required by law.
Health Oversight Activities: We may disclose your health information to a health oversight agency for activities authorized by law, such as audits, investigations, and inspections.
Judicial and Administrative Proceedings: We may disclose your health information in response to a court or administrative order, subpoena, discovery request, or other lawful process.
Law Enforcement: We may disclose your health information for law enforcement purposes as required by law or in response to a valid court order.
To Avert a Serious Threat to Health or Safety: We may use and disclose your health information when necessary to prevent a serious threat to your health and safety, or the health and safety of the public or another person.
Marketing: We will not use or disclose your PHI for marketing purposes without your prior written authorization. Under Texas law, the sale of your PHI for marketing purposes is strictly prohibited.
Effective February 16, 2026, in compliance with updated federal regulations under 42 CFR Part 2, records related to substance use disorder (SUD) treatment from a federally assisted Part 2 program receive heightened confidentiality protections.
How we may receive SUD records: Our dental practice may receive substance use disorder treatment records as part of a patient's health history or through coordination of care with other providers.
General Consent: If we receive a Part 2 record accompanied by a general consent from the patient, we may use and disclose that information for purposes of treatment, payment, and healthcare operations as permitted by the HIPAA Privacy Rule and as described in this Notice.
Specific Consent: If we receive a Part 2 record accompanied by a specific consent, we may only use and disclose the information as expressly permitted in that consent.
Legal Proceedings: In no event will we use or disclose your Part 2 Program record, or testimony that describes the information contained in your Part 2 Program record, in any civil, criminal, administrative, or legislative proceedings by any Federal, State, or local authority, against you, unless authorized by your consent or the order of a court after it provides you notice of the court order.
Additional protections:
If you have questions about how your SUD records are handled, please contact us using the contact information below.
Some information may be entitled to special protections under federal and/or state law. These include but are not limited to:
Where applicable, we will apply the stricter protections required by these laws. Under both HIPAA and the Texas Medical Records Privacy Act, if a conflict exists between federal and state law, the more protective standard applies.
You have the following rights regarding the health information we maintain about you:
Right to Access: You have the right to inspect and obtain a copy of your health information maintained by our practice. Under Texas law, we will provide you with access to your electronic health records within 15 business days of your written request. We may charge only a reasonable, cost-based fee for copies; administrative or retrieval fees are not permitted under Texas law. To request access, please submit a written request to us.
Right to Request an Amendment: You have the right to request that we amend your health information if you believe it is incorrect or incomplete. If we decline your request, we will explain our reasons in writing. To request an amendment, please submit a written request to us explaining the reason for the amendment.
Right to an Accounting of Disclosures: You have the right to request a list of certain disclosures we have made of your health information. To request an accounting, please submit a written request.
Right to Request Restrictions: You have the right to request restrictions on certain uses and disclosures of your health information. We are not required to agree to your request, but if we do, we will comply with the agreed-upon restrictions except in emergency situations.
Right to Request Confidential Communications: You have the right to request that we communicate with you about health matters in a certain way or at a certain location. For example, you may request that we contact you only at a specific phone number or address.
Right to a Paper Copy of This Notice: You have the right to obtain a paper copy of this Notice at any time, even if you have previously agreed to receive it electronically.
Right to Be Notified of a Breach: You have the right to be notified in the event of a breach of your unsecured PHI. Breach notification will be provided in accordance with both HIPAA and applicable Texas law.
We are required by law to:
We reserve the right to change the terms of this Notice and to make the new provisions effective for all PHI we maintain. If we make a material change to this Notice, we will make the revised Notice available upon request, post it in our office, and update it on our website.
We may update our Website Privacy Policy and Notice of Privacy Practices from time to time. We advise you to review this page periodically for any changes. We will notify you of any changes by posting the updated policy on this page. These changes are effective immediately after they are posted on this page. For material changes to our Notice of Privacy Practices, we will make the revised Notice available upon request, post it in our office, and publish it on our website. Your continued use of our Services following notice of changes constitutes your acceptance of the revised Policy.
If you believe your privacy rights have been violated, you may file a complaint with our practice, the State of Texas, or the U.S. Department of Health and Human Services. You will not be penalized or retaliated against for filing a complaint.
Tiny Dental Company
26400 Kuykendahl Rd Suite c230, The Woodlands, TX 77375, United States
(281) 207- 5096
info@tinydentalco.com
Texas Attorney General — Consumer Protection Division P.O. Box 12548 Austin, TX 78711-2548 Phone: 1-800-621-0508 Website: www.texasattorneygeneral.gov/consumer-protection/health-care/patient-privacy
U.S. Department of Health and Human Services Office for Civil Rights — Region VI 1301 Young Street, Suite 1169 Dallas, TX 75202 Phone: 1-877-696-6775 Website: www.hhs.gov/ocr/privacy/hipaa/complaints/
Schedule your child’s dental appointment at Tiny Dental Company in The Woodlands, led by Dr. Sarah Arafat! We specialize in pediatric dental care in a friendly environment. Schedule today for expert care and a healthy smile that lasts a lifetime!
.gif)
.webp)
