This Policy applies to information collected through the Site and related digital interactions.
It does not replace the AOS Enterprise Joint Notice of Privacy Practices (“Joint NPP”), which describes how participating HIPAA covered health care providers may use and disclose protected health information (“PHI”).
If information is PHI, the Joint NPP and applicable health-privacy law govern to the extent they provide different or additional protections.
1. Who Is Responsible for the Site
The Site is owned and operated for the AOS enterprise and supports legally separate health care providers, facilities, and affiliated service organizations operating under the AOS/AOSC brand.
The entities currently covered by this Policy are:
- AOS Institute, LLC — professional and public education, courses, events, training, educational content, and related operations.
- AOS Miami, PLLC — medical and dental practice.
- AOS ASC, LLC — ambulatory surgery center.
- Alfi Oral Surgery, PA — medical and dental practice.
- Airway Outpatient Surgical Center, LLC — ambulatory surgery center.
The entity responsible for a particular interaction may depend on whether you select education, a course or event, a clinical location, a health care service, a provider, or another form.
A current list of participating health care entities and service-delivery locations is available upon request.
AOS Institute, LLC is not identified in this Policy as a HIPAA covered health care provider or as a Participant in the AOS Organized Health Care Arrangement. Its ownership or operation of the Site does not by itself make AOS Institute, LLC a HIPAA covered entity, place it within the OHCA, or permit it to access PHI.
2. Scope and Relationship to Health Information
General Website Information
Personal information collected while you browse public pages—such as device information, page views, cookie identifiers, or a general inquiry—may not be PHI merely because the Site concerns health care.
It remains subject to this Policy and other applicable privacy laws.
Appointment Requests and Patient Information
Information you submit while requesting an appointment, describing a condition, communicating with a provider, completing an intake form, or otherwise seeking or receiving health care may become PHI when it is created or received by a HIPAA covered AOS Participant or its business associate.
Such information may be used and disclosed as described in the Joint NPP and as permitted or required by law.
Education, Courses, and Events
Information collected by AOS Institute, LLC for education, courses, conferences, webinars, training, publications, or other educational activities generally is not PHI merely because the subject concerns health care.
Educational registration and participation information is governed by this Policy and other applicable law unless AOS Institute, LLC receives or maintains the information as a business associate of a HIPAA covered entity or the information is otherwise subject to a specific health-privacy law.
Emergencies and Sensitive Information
Do not use a general website form, chat, email address, or text message for a medical emergency. Call 911 or seek emergency care.
Unless a form is specifically identified as a secure patient or intake form, do not submit medical records, detailed clinical information, Social Security numbers, payment-card details, or other highly sensitive information through it.
3. Information We Collect
Depending on how you use the Site and which services are enabled, we may collect the following categories of information:
- Identifiers and contact information, such as name, postal address, email address, telephone number, date of birth, account or contact identifiers, and communication preferences.
- Appointment and service information, such as requested location, provider, specialty, service, preferred date and time, referral source, and scheduling status.
- Health-related information that you choose to submit, such as a reason for visit, symptoms, diagnosis or treatment interests, insurance information, referral information, uploaded records, images, or form responses.
- Communications, including form submissions, chat messages, emails, SMS/MMS messages, call details, voicemail, and, where lawfully recorded with required notice or consent, audio or call recordings.
- Account and transaction information, such as portal or form-account credentials, invoices, payment status, and limited transaction information. Payment-card information may be processed directly by a payment processor rather than stored by AOS.
- Device and network information, including Internet Protocol address, browser type, device type, operating system, language, approximate location derived from an IP address, referring URLs, and identifiers associated with cookies or similar technologies.
- Website activity, including pages viewed, links clicked, forms started or completed, campaign or referral information, search terms, interactions, session timing, and conversion events.
- Professional or employment information when you inquire about a job, professional relationship, referral relationship, or business opportunity.
- Education and event information, such as course or program selections, registrations, attendance, participation, learning progress, assessments, certificates, continuing-education information, professional license or credential information, organization, specialty, dietary or accessibility requests, and feedback.
- Information from other sources, such as referring providers, advertising or analytics partners, social-media platforms, public sources, data vendors, scheduling or communications providers, and other AOS entities, where permitted by law.
- Inferences or classifications generated from the information above, such as service interests, location preferences, lead status, communication history, or likely next steps.
We do not necessarily collect every category from every visitor. We collect information based on your interactions, the features deployed, and the choices you make.
4. HighLevel / GoHighLevel and LeadConnector
We use the HighLevel platform, which may be branded or technically presented as HighLevel, GoHighLevel, LeadConnector, or through an AOS-branded interface.
HighLevel may support functions such as:
- Website and landing-page hosting
- Forms and surveys
- Contact and lead management
- Appointment calendars
- Pipelines and workflow automation
- SMS/MMS
- Calling and voicemail
- Chat
- Attribution
- Reviews
- Related reporting
When you interact with a HighLevel-enabled page or feature, information may be transmitted to and stored in HighLevel systems and made available to authorized AOS personnel, participating AOS entities, and service providers that administer the platform.
HighLevel and its subprocessors may process information on our behalf in accordance with our agreements and applicable law.
Where HighLevel will create, receive, maintain, or transmit PHI, AOS will use it only after required HIPAA functionality is activated for the relevant account and sub-account, an appropriate Business Associate Agreement is in effect, access controls and security settings are configured, and the intended workflow has passed privacy and security review.
HighLevel configuration is controlled by AOS and may change the data collected. This Policy should remain reconciled with the production account’s forms, custom fields, calendars, workflows, tracking, integrations, recordings, retention settings, and subprocessors.
5. How We Use Information
We may use personal information to:
- Operate, maintain, secure, troubleshoot, and improve the Site and digital services.
- Respond to inquiries and requests and provide customer or technical support.
- Schedule, confirm, reschedule, and manage appointments and referrals.
- Coordinate treatment, payment, and health care operations when information is PHI and the use is permitted by law.
- Provide intake, registration, eligibility, authorization, financial, billing, and patient-communication services.
- Send administrative messages, reminders, instructions, service announcements, and policy updates.
- Manage contacts, inquiries, leads, pipelines, follow-up tasks, and communications across authorized AOS entities.
- Register participants for courses, conferences, webinars, training, and events; deliver educational content; administer attendance, assessments, certificates, and continuing-education records; and communicate about AOS Institute programs.
- Measure Site performance, understand how visitors use the Site, diagnose errors, and improve content and navigation.
- Measure outreach and advertising effectiveness, attribute inquiries to campaigns, and—only where lawfully configured—personalize communications or advertising.
- Request feedback and manage reviews, subject to applicable privacy and professional requirements.
- Detect, investigate, and prevent fraud, abuse, security incidents, and unlawful activity.
- Comply with legal, regulatory, licensure, accreditation, records, reporting, and contractual obligations.
- Establish, exercise, or defend legal claims and protect patients, visitors, AOS, and others.
We will not use PHI for marketing or another purpose requiring HIPAA authorization unless we obtain a valid authorization or another legal permission applies.
6. Cookies, Tracking Technologies, and Cookie Notice
This Section serves as the Site’s cookie notice and explains how AOS uses cookies and similar technologies.
A cookie is a small text file or data element stored on or accessed from your browser or device when you visit a website or use certain online features.
Similar technologies may include local storage, pixels, tags, software development kits, session identifiers, and other tools that recognize a browser or device or record activity.
The technologies used on the Site depend on the pages, domains, platforms, features, integrations, and choices that are active at the time of your visit.
They may be operated by AOS or by service providers and third parties, including HighLevel/GoHighLevel/LeadConnector, LearnWorlds, hosting and security providers, analytics services, communications providers, embedded-content providers, payment processors, or advertising and measurement partners.
Categories of Cookies and Similar Technologies
HighLevel and LeadConnector
AOS websites, landing pages, forms, surveys, calendars, chat features, and related digital services may be hosted or supported through HighLevel, GoHighLevel, or LeadConnector.
Depending on configuration, these services may use cookies or similar technologies for core website operation, consent management, security, session continuity, contact attribution, form and survey analytics, calendar functions, chat, and optional tracking or advertising integrations.
HighLevel provides a cookie-consent tool that can classify technologies as essential, functional, analytics, performance, advertising, or uncategorized and can allow visitors to accept all cookies, accept essential cookies only, reject nonessential cookies, or save category preferences.
AOS will configure and use that tool, or another consent-management mechanism, as appropriate for the Site and applicable law.
AOS Institute and LearnWorlds
AOS Institute educational pages and services may be delivered through LearnWorlds or another learning-management platform.
Depending on the features used, the learning platform may use cookies or similar technologies for login and session management, security, learner preferences, course progress, payment processing, embedded video, chat or support tools, affiliate attribution, and analytics.
Examples identified in the LearnWorlds template supplied to AOS include XSRF-TOKEN, DPSettings, slim_session, affiliate, Stripe, Vimeo, Cloudflare, Google Analytics, and optional chat, analytics, or marketing cookies.
That template is not itself a verified inventory of the AOS production environment. Only technologies actually detected and enabled on AOS domains should be listed in the final production cookie inventory.
Information Collected Through These Technologies
Depending on the technology, information collected may include an Internet Protocol address, browser and device type, operating system, language, approximate location derived from an IP address, online identifiers, referring URLs, pages viewed, links selected, form or survey interactions, session timing, campaign information, and conversion events.
Some third parties may combine this information with data collected through other websites or services under their own privacy notices when they act independently rather than solely as an AOS service provider.
Health Information and Tracking Restrictions
AOS does not authorize a tracking-technology provider to receive PHI unless the disclosure is permitted by HIPAA and any required Business Associate Agreement is in place.
Advertising pixels, session-replay tools, and similar nonessential technologies should not be configured to receive medical details, form contents, patient identifiers, portal activity, appointment information, or other PHI unless counsel and compliance have confirmed a lawful basis and appropriate safeguards.
Representative Cookie Inventory
A current, production-based cookie and tracking inventory will be maintained through the Site’s cookie-preference interface.
The inventory should identify, as applicable, the cookie or technology name, provider, purpose, category, domain, and duration.
Because vendors and configurations change, the inventory may be updated without revising every other portion of this Policy.
7. Cookie Consent and Your Tracking Choices
Cookie Banner and Preference Center
Where a cookie banner or preference center is presented, you may be able to accept all cookies, permit only essential cookies, or select among available categories.
Strictly necessary cookies may remain active because they are required for security or core Site functions.
Your choices may be stored in a cookie or similar technology so the Site can remember them.
Browser and Device Controls
Most browsers allow you to block, restrict, or delete cookies through browser settings.
Mobile devices may also provide controls for advertising identifiers, location data, or application tracking.
Blocking or deleting cookies may remove saved preferences and may cause some features, forms, calendars, accounts, videos, or other embedded services to function differently or not at all.
Opt-Out Preference Signals
Where required by applicable law and supported by our systems, we will honor legally recognized opt-out preference signals, such as Global Privacy Control, for processing that applicable law treats as a sale, sharing, or targeted advertising.
Changes to Cookie Use
AOS may add, remove, or change cookies and similar technologies as Site features, vendors, or legal requirements change.
We will update the production inventory, preference center, or this Policy as appropriate.
8. Communications, Email, Telephone, and Text Messages
If you provide contact information, we may communicate with you by mail, email, telephone, voicemail, SMS/MMS, portal message, or another method about inquiries, appointments, referrals, care, billing, account activity, forms, and other services.
Email and ordinary text messaging may not be fully secure and may be accessible to persons who use or view your device or account.
Patients may request reasonable confidential communications as described in the Joint NPP.
Consent to receive marketing or automated communications is not a condition of receiving health care except where permitted by law.
Any consent language presented with a form controls the particular communication program and should identify the sender, message purpose, expected frequency, carrier charges, opt-out method, and other disclosures required by law.
SMS Terms
When you opt in to an AOS text-message program, message frequency may vary and message and data rates may apply. Reply STOP to opt out of the applicable program and HELP for assistance, or contact [email protected].
We may send one confirmation after an opt-out request.
Opting out of one program may not opt you out of another separately authorized program or prevent nonmarketing communications permitted by law.
Mobile opt-in information and consent records will not be sold or shared with third parties or affiliates for their own marketing or promotional purposes.
We may disclose such information to service providers that help deliver the messaging program and are contractually restricted from using it for independent marketing.
9. How We Disclose Information
We may disclose personal information to:
- AOS entities and authorized personnel that need the information to respond to your request, coordinate services, administer the enterprise, or perform permitted health care functions.
- AOS Institute, LLC and education-service providers for course, event, training, credentialing, accreditation, attendance, certificate, payment, communications, and related educational administration.
- Health care providers, facilities, pharmacies, laboratories, health plans, clearinghouses, and other parties involved in treatment, payment, or health care operations when permitted by law.
- Service providers and business associates supporting website hosting, HighLevel administration, cloud services, security, analytics, communications, forms, calendars, call routing, payment processing, billing, records, legal, accounting, and other operational functions.
- Advertising or analytics providers, but only for information and purposes permitted by applicable law and our configuration.
- Professional advisors, auditors, insurers, accreditation organizations, and financing or transaction counterparties subject to appropriate confidentiality protections.
- Government authorities, courts, regulators, law enforcement, or other persons when required or permitted by law.
- A successor or prospective successor in a merger, acquisition, restructuring, financing, transfer, or sale, subject to applicable law.
- Other persons at your direction or with your consent or authorization.
We may also disclose aggregated or de-identified information that does not reasonably identify you.
If a recipient is not subject to HIPAA or another confidentiality law, information disclosed to that recipient may no longer receive the same legal protection.
10. Sale, Sharing, and Targeted Advertising
AOS does not sell PHI.
We do not knowingly sell personal information for money.
Some state privacy laws define “sale,” “sharing,” or “targeted advertising” broadly enough to include certain disclosures through advertising cookies, pixels, or similar technologies even when no money changes hands.
We do not use personal information for cross-context behavioral or targeted advertising and do not sell or share personal information as those terms are defined by applicable state privacy laws.
We do not knowingly sell or share for targeted advertising the personal information of individuals we know are under the age at which affirmative authorization is required.
11. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including to provide services, maintain business and clinical records, document communications and consent, resolve disputes, enforce agreements, satisfy legal and regulatory requirements, maintain security, and support audits or legal holds.
Retention periods vary by the type of information, the AOS entity involved, whether the information is part of a medical or dental record, and applicable law.
We do not represent that all website or CRM information is deleted after a fixed 12-month period.
When information is no longer required, we may delete, de-identify, or securely isolate it, subject to backup, archival, and legal-retention requirements.
12. Security
We use administrative, physical, and technical safeguards designed to protect personal information, taking into account its nature and the risks involved.
These safeguards may include:
- Access controls
- Authentication
- Encryption
- Logging and monitoring
- Workforce training
- Vendor management
- Backups
- Incident-response procedures
No website, transmission, or storage system can be guaranteed completely secure.
Use secure patient-facing channels when available, protect your credentials and devices, and notify us if you suspect unauthorized activity.
13. Children and Minors
The Site is intended for adults and for parents or legal guardians seeking services for minors.
We do not knowingly use the Site to market directly to children in violation of applicable law.
A parent, guardian, or other authorized person may submit information concerning a minor when permitted by law.
AOS Institute educational programs may have separate age or eligibility requirements.
If a program permits participation by a minor, AOS Institute will obtain parental or guardian information or consent when required by applicable law.
Health care and privacy rights involving minors vary by state and by the service involved.
A parent or guardian may not always have access to information concerning services to which a minor lawfully consented. Contact the Privacy Officer with questions about patient records.
14. State Privacy Rights
Depending on your state of residence, the nature of the information, and whether a particular law applies to an AOS entity, you may have rights to:
- Confirm whether we process your personal information and obtain access to it.
- Request correction or deletion of personal information.
- Obtain a portable copy of certain information.
- Opt out of certain sales, sharing, targeted advertising, or profiling.
- Limit certain uses or disclosures of sensitive personal information.
- Withdraw consent where processing depends on consent.
- Appeal a denial of a consumer privacy request.
- Receive equal service and not be discriminated against for exercising a privacy right.
These rights are subject to definitions, applicability thresholds, exemptions, verification requirements, and exceptions.
Information governed by HIPAA or other health-privacy laws may be exempt from some state consumer-privacy laws.
Rights concerning PHI should be exercised under the Joint NPP.
To submit a non-PHI consumer privacy request, email [email protected] or call 305-701-3901.
We may verify your identity and authority and may ask an authorized agent for proof of authority.
If applicable law provides a right to appeal, submit an appeal through the same channel and label it “Privacy Appeal.”
15. Third-Party Sites and Embedded Services
The Site may link to or embed services operated by other parties, such as maps, videos, social-media pages, payment services, patient portals, review sites, and external scheduling or content providers.
Their privacy practices may differ from ours.
This Policy does not govern a third party acting independently, and a link does not constitute an endorsement.
16. International Visitors
The Site is operated for health care and related services in the United States.
If you access it from another country, your information may be transferred to and processed in the United States, where privacy laws may differ.
AOS does not intentionally offer, advertise, or market its services to individuals located outside the United States, including the European Economic Area, the United Kingdom, Switzerland, and Canada.
17. Changes to This Policy
We may revise this Policy to reflect changes in law, technology, vendors, Site features, or our practices.
The “Last Updated” date identifies the current version.
If a change is material, we may provide additional notice through the Site or another appropriate method.
Prior versions will be retained as required by our document-control procedures.
18. Contact Us
For questions about this Policy or non-PHI privacy requests, contact:
AOS Enterprise Privacy Office
Zachary Higham
Chief Legal and Compliance Officer and Enterprise Privacy Officer
Email: [email protected]
Telephone: 305-701-3901
Mailing Address:
2801 NE 213th St, Ste 1206
Aventura, FL 33180
For rights involving medical or dental records or other PHI, consult the AOS Enterprise Joint Notice of Privacy Practices .