Appointment request service
Appointment Request Privacy Policy
This Privacy Policy describes how Ear, Nose, Throat & Allergy Specialist collects, uses, discloses, and protects personal information through its online appointment request service.
- Effective:
- August 2, 2026
- Version:
- 2026-08-02
1. Scope and relationship to the Notice of Privacy Practices
This Appointment Request Privacy Policy (the “Privacy Policy”) applies to personal information collected through the online appointment request form and related scheduling features (the “Scheduler”) operated by Ear, Nose & Throat Specialist - Cherokee Sinus Center, P.C., doing business as Ear, Nose, Throat & Allergy Specialist (“ENTAS,” “we,” “us,” or “our”). It does not describe every ENTAS website, patient-portal, clinical, employment, or offline data practice.
This Privacy Policy supplements and does not replace ENTAS’s Notice of Privacy Practices. When information is protected health information (“PHI”), ENTAS’s Notice of Privacy Practices and applicable health-privacy law, including HIPAA, govern how ENTAS may use and disclose it. If this Privacy Policy conflicts with the Notice of Privacy Practices or applicable law concerning PHI, the Notice of Privacy Practices and applicable law control.
This Privacy Policy is a notice, not a consent to medical treatment and not an authorization for a use or disclosure that legally requires a separate authorization. You may request a copy of ENTAS’s Notice of Privacy Practices by calling 770-345-6600 or writing to the Privacy Officer, Ear, Nose, Throat & Allergy Specialist, 215 Riverstone Drive, Canton, GA 30114.
2. Information we collect
The information collected depends on the request, the patient, and the Scheduler features used. It may include the following categories:
- Identity and contact information, including patient and submitter names, dates of birth, mailing addresses, telephone numbers, email addresses, and the submitter’s relationship to the patient.
- Demographic and patient-matching information, including sex, preferred location, existing-patient status, and information used to locate or create the correct medical record.
- Appointment and health information, including requested service, clinician or location preferences, available dates and times, reason for visit, symptoms, answers to intake or eligibility questions, and appointment history relevant to the request.
- Insurance information, including health-plan details and images or PDF copies of insurance cards when you choose or are asked to upload them.
- Authorization and acknowledgment information, including representations that a submitter may act for the patient, checkbox selections, the legal-text version displayed, timestamps, and related audit evidence.
- Communications and verification information, including identity-verification status, text-message consent and opt-out records, delivery status, message metadata, and communications with ENTAS about the request.
- Device, network, and security information, including Internet Protocol address, browser and device characteristics, referral information, session identifiers, access times, error logs, and records used to prevent fraud or protect the Scheduler.
3. Sources of information
ENTAS collects information directly from you when you use the Scheduler or communicate about a request. If you submit a request for another person, ENTAS receives information about that patient from you. ENTAS may also receive or confirm information through its existing patient records, scheduling and electronic medical record systems, communications providers, identity-verification providers, insurers or health plans, authorized representatives, and device or browser interactions with the Scheduler, as permitted by law.
4. How we use information
ENTAS uses Scheduler information for the following purposes:
- To verify contact information, authenticate a scheduling session, and match the request with the correct patient record.
- To receive, review, route, coordinate, confirm, reschedule, cancel, and otherwise administer appointment requests.
- To communicate about identity verification, scheduling, confirmations, reminders, changes, support, and follow-up needed to complete the request.
- To prepare for administrative and clinical workflows, evaluate whether a requested appointment type or location is appropriate, and coordinate care as permitted by law.
- To review insurance information, support eligibility or authorization workflows, and administer payment or office policies when applicable.
- To maintain consent, acknowledgment, request, and audit records; investigate errors; prevent fraud and abuse; secure the Scheduler; and improve reliability and accessibility.
- To comply with law, respond to lawful process, protect patients and others, enforce the Appointment Request Terms of Service, and establish or defend legal claims.
5. How we disclose information
ENTAS discloses personal information only as reasonably necessary for the purposes described in this Privacy Policy, its Notice of Privacy Practices, or as otherwise permitted or required by law. Recipients may include:
- ENTAS clinicians, workforce members, and affiliated care locations that need the information to review or administer the request or provide healthcare operations and services.
- Service providers and business associates that support hosting, storage, communications, identity verification, scheduling, electronic medical records, insurance workflows, information technology, security, auditing, and professional services. They may use information only to perform authorized services or as otherwise permitted by law and contract.
- Health plans, insurers, clearinghouses, referring providers, and other healthcare participants when permitted for treatment, payment, healthcare operations, or at your direction.
- A patient, parent, legal guardian, personal representative, or other person authorized by law, after appropriate verification.
- Courts, regulators, law enforcement, emergency responders, public-health authorities, or other recipients when disclosure is required or permitted by law or reasonably necessary to protect rights, safety, or security.
- A successor or transaction participant in a lawful merger, acquisition, reorganization, financing, or transfer involving all or part of the practice, subject to applicable confidentiality and health-privacy requirements.
6. Transactional text messages
If you provide the separate text-message consent, ENTAS and its communications providers may use the mobile number you supply to send automated transactional messages about the appointment request, including identity-verification codes, scheduling communications, confirmations, reminders, and changes. The Scheduler consent does not authorize marketing messages.
Message frequency varies, and message and data rates may apply. Reply STOP to opt out or HELP for help. You may also call 770-345-6600 with a reasonable opt-out request. ENTAS retains consent and opt-out evidence as reasonably necessary to honor your choice and document compliance. Opting out of text messages does not cancel an appointment or request; call 770-345-6600 to cancel, reschedule, or confirm.
Text messages travel through mobile carriers and communications providers and may be unencrypted or visible to others with access to your device, account, or notifications. To request an appointment without text messages, call 770-345-6600.
8. No sale of Scheduler information
ENTAS does not sell personal information collected through the Scheduler for money or other consideration and does not share it for cross-context behavioral advertising. Disclosures to healthcare participants, business associates, and service providers for the purposes described in this Privacy Policy are not sales of personal information.
9. Retention
ENTAS retains Scheduler information according to the type of information and the purpose for which it was collected. Relevant criteria include medical-record and health-privacy requirements, the status of the request, ongoing treatment and administrative needs, consent and opt-out evidence, security and fraud-prevention needs, contractual obligations, applicable limitation periods, legal holds, and other legal requirements.
Session and technical records that are no longer needed may be retained for a shorter period than information incorporated into a medical, appointment, insurance, consent, or compliance record. When information is no longer reasonably needed, ENTAS deletes, destroys, or deidentifies it in accordance with its retention practices and applicable law. Backup copies may remain for a limited period before ordinary deletion or overwriting.
10. Security
ENTAS uses administrative, technical, and physical safeguards designed to protect Scheduler information, taking account of its sensitivity and the nature of the systems involved. Measures may include access controls, authentication, encryption in transit, logging, vendor oversight, workforce procedures, and secure disposal practices.
No Internet transmission, mobile carrier, device, or storage system can be guaranteed to be completely secure. You can help by using a trusted device and network, protecting access to your telephone and messages, closing the Scheduler when finished, and promptly reporting suspected unauthorized activity to 770-345-6600.
11. Your choices and rights
Depending on the information and applicable law, you may have rights to request access, correction, amendment, restriction, an accounting, a copy, or deletion of certain information; to receive confidential communications in a requested manner; to opt out of text messages; or to appeal a denied consumer-privacy request. HIPAA rights concerning PHI are described in ENTAS’s Notice of Privacy Practices.
Not every right applies to every record, and ENTAS may need to retain information for medical-record, treatment, payment, safety, fraud-prevention, legal, or compliance reasons. ENTAS may verify your identity and authority before acting on a request. To exercise a right or ask a privacy question, call 770-345-6600 or write to the Privacy Officer, Ear, Nose, Throat & Allergy Specialist, 215 Riverstone Drive, Canton, GA 30114. ENTAS will not unlawfully discriminate against you for exercising an applicable privacy right.
12. Minors and authorized representatives
The Scheduler is not intended for a child to use independently. A parent, legal guardian, or other legally authorized representative may submit a request for a minor and must provide accurate information about the patient and the representative’s authority. Privacy rights concerning a minor’s information may depend on applicable law, the type of care, and who is authorized to act for the minor.
An adult submitting information for another patient must be legally authorized to do so. ENTAS may require proof of authority before disclosing information or acting on a privacy request.
13. External services and links
The Scheduler may connect to or link to services operated by others, such as mobile carriers, mapping services, insurer resources, or websites outside ENTAS’s control. Their independent collection of information outside the Scheduler is governed by their own notices and terms. This Privacy Policy continues to govern ENTAS’s own handling of information received through the Scheduler.
14. Changes to this Privacy Policy
ENTAS may update this Privacy Policy to reflect changes in the Scheduler, information practices, or law. The current version will display its effective date. Material changes will apply prospectively unless applicable law permits or requires otherwise, and ENTAS will provide additional notice or obtain consent when legally required.
15. Contact us
For privacy questions, requests, concerns, or a copy of ENTAS’s Notice of Privacy Practices, call 770-345-6600 or write to: Privacy Officer, Ear, Nose, Throat & Allergy Specialist, 215 Riverstone Drive, Canton, GA 30114.
You may also submit a complaint about PHI to the U.S. Department of Health and Human Services Office for Civil Rights. ENTAS will not retaliate against you for filing a good-faith privacy complaint.