Privacy Policy

Effective Date: June 1, 2026

Last Updated: June 1, 2026

At a Glance

This policy outlines how Core Function Health handles your personal information online. We prioritize your privacy: we do not sell your personal data, nor do we share it with third-party advertisers. Standard medical records are governed by our separate HIPAA Notice of Privacy Practices.

1. Introduction

Core Function Health Physician Assistant Corporation ("Core Function Health," "we," "us," or "our"), operates the website at corefunctionhealth.com (the "Site") and provides specialty wellness consultations to adults located in the state of California.


This Privacy Policy describes how we collect, use, share, and protect information when you visit the Site, take our Hormone Symptom Quiz, submit a form, schedule a Discovery Call, or otherwise interact with our online services. It does not apply to protected health information ("PHI") collected within an established clinician-patient relationship - that information is governed by our separate HIPAA Notice of Privacy Practices, provided at the time you become a patient.


By using the Site, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Site.

2. Information We Collect

Information you provide directly: Contact details (name, email, phone, mailing address) submitted through forms, quizzes, scheduling tools, or email; Health-related information you voluntarily share through the Hormone Symptom Quiz or other intake forms (symptoms, cycle stage, lab history, treatment goals); Information you send by email or messaging; Payment information, processed through our third-party payment processors.


Information collected automatically: Device and browser information (browser type, operating system, IP address, device identifiers); Site usage data (pages visited, time on site, referring URLs, click activity); Cookies and similar technologies (see Section 6).


Information collected from third parties:Information from our scheduling and EHR vendor (Optimantra) when you book a Discovery Call or appointment; Information from analytics providers; Information from social media platforms if you interact with us through their services.

3. How We Use Information

We use the information we collect to respond to inquiries, schedule appointments, and provide the services you request; send your personalized Hormone Symptom Quiz results and any educational follow-up emails you've opted in to receive; process payments and manage your account; operate, secure, and improve the Site; comply with legal obligations and protect our rights; and send service-related communications (e.g., appointment confirmations, important practice notices).


We do not sell your personal information. We do not share your information with advertisers, data brokers, or third parties for their own marketing purposes.

4. How We Share Information

We share information only in the following limited circumstances:


Service providers: who help us operate the practice and Site, including Quest Diagnostics (when laboratory orders are placed on your behalf), Optimantra (our electronic health records and scheduling platform), Fullscript (our professional supplement dispensary, only if you choose to use it), Hiveality (our website hosting and email marketing platform), Google Workspace (our business email provider), and Authorize.net and/or other payment processors (when payments are processed outside Optimantra including Stripe). Payment information may be shared with payment processors solely to process authorized transactions.


Legal compliance: when required by law, court order, subpoena, or to protect rights, property, or safety.


Business transfers: in the event of a merger, acquisition, or sale of practice assets, with appropriate confidentiality safeguards.


Each service provider is contractually obligated to use your information only as needed to perform services for us, in accordance with applicable law, and (for any provider handling protected health information) under a Business Associate Agreement.

5. Children's Privacy

The Site and our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at admin@corefunctionhealth.com and we will delete the information.

6. Cookies and Tracking Technologies

We use cookies and similar technologies to operate the Site, remember your preferences, and understand how the Site is used. You can manage cookies through your browser settings. Disabling cookies may limit certain Site functionality. We do not currently respond to "Do Not Track" browser signals. If we offer behavioral advertising in the future, this section will be updated and consent obtained where required.

7. Data Security

We maintain reasonable administrative, technical, and physical safeguards designed to protect your information from unauthorized access, disclosure, alteration, or destruction. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.


7A. Payment Information and Stored Payment Methods


For your convenience, Core Function Health may allow you to securely store a credit card, debit card, Health Savings Account (HSA) card, Flexible Spending Account (FSA) card, or other approved payment method within our electronic health record and practice management systems.

Payment information is processed and stored through secure, third-party payment processors and technology vendors that maintain industry-standard security safeguards, including encryption and Payment Card Industry Data Security Standards (PCI-DSS) compliance where applicable. Core Function Health does not store full payment card numbers on its own servers.

Stored payment methods may be used for authorized charges related to appointments, memberships, recurring services, products, laboratory testing, late cancellation fees, no-show fees, balances due, and other patient-authorized transactions in accordance with any signed financial agreements or payment authorizations.

Access to payment information is restricted to authorized personnel with a legitimate business need to perform billing, payment processing, customer service, compliance, or administrative functions.

We do not sell, rent, lease, or disclose payment card information to advertisers, data brokers, or unrelated third parties for marketing purposes.

To the extent payment information is associated with your patient account, appointment history, billing records, or other medical information, such information may be protected under applicable federal and California privacy laws, including HIPAA, the California Confidentiality of Medical Information Act (CMIA), and the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Core Function Health maintains administrative, technical, and physical safeguards designed to protect such information and limits its use and disclosure to purposes permitted by law.

You may request removal of a stored payment method at any time by contacting our office; however, removal of a payment method may affect your ability to participate in certain memberships, recurring services, automatic billing arrangements, or other programs requiring a valid payment method on file. Certain billing records and transaction information may be retained as required by law, accounting standards, contractual obligations, fraud prevention requirements, or healthcare record retention requirements.

8. Data Retention

We retain personal information for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Patient health records are retained in accordance with California medical record retention requirements.

9. Your Rights - California Residents

Under the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), California residents have the following rights: Right to Know(request information about the categories and specific pieces of personal information we have collected about you, the sources, the purposes of collection, and the categories of third parties with whom we share it);Right to Delete(request that we delete personal information we have collected from you, subject to certain exceptions including medical record retention requirements);Right to Correct(request that we correct inaccurate personal information);Right to Opt Out of Sale or Sharing(direct us not to sell or share personal information - we do not sell or share personal information for cross-context behavioral advertising);Right to Limit Use of Sensitive Personal Information(direct us to limit the use of sensitive personal information such as health information to what is necessary to provide our services - we already limit such use);Right to Non-Discrimination(we will not discriminate against you for exercising any of your privacy rights); andRight to Portability(receive a copy of certain personal information in a portable format).


To exercise any of these rights, contact us at admin@corefunctionhealth.com. We will verify your identity before responding. You may also designate an authorized agent to make a request on your behalf.


California Shine the Light Law: California residents may request information about our disclosure of personal information to third parties for those parties' direct marketing purposes. We do not currently share personal information for third-party direct marketing.

10. Health Information and HIPAA

Information shared in the course of clinician-patient care is "Protected Health Information" under the Health Insurance Portability and Accountability Act ("HIPAA"). PHI is governed by our separate Notice of Privacy Practices, which you will receive when you become a patient. The HIPAA Notice of Privacy Practices controls in any conflict between this Privacy Policy and our handling of PHI.


Information you submit through the Hormone Symptom Quiz or general Site forms (before becoming a patient) is governed by this Privacy Policy, not HIPAA.

11. Third-Party Links

The Site may contain links to third-party websites (such as Fullscript). Those sites have their own privacy practices. We are not responsible for the content or privacy practices of any linked third-party site.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last Updated" date at the top reflects the most recent revision. Material changes will be communicated through the Site or by email when appropriate.

13. Contact Us

If you have questions about this Privacy Policy or want to exercise any of your rights, contact:

Core Function Health Physician Assistant Corporation

909 Electric Ave, Suite 312C

Seal Beach, CA 90740

Email:admin@corefunctionhealth.com

Phone:562-248-6546