Last updated · September 4, 2026
Dermatologic Services, PLLC ("Dermatologic Services," "we," "us," or "our") operates GibranShaikh.com, DermatologicServices.com, and related scheduling, intake, telemedicine, and patient-support workflows (collectively, the "Services").
This Privacy Policy describes personal information handled through the public-facing and operational portions of the Services. Protected Health Information ("PHI") created or maintained by Dermatologic Services as a health care provider is also governed by HIPAA, applicable state law, and our Notice of Privacy Practices.
1. Information We Collect
- Contact and identifying information, including name, email address, telephone number, date of birth, mailing address, and other information you provide.
- Scheduling information, including appointment type, requested date and time, time zone, and the jurisdiction where you expect to be physically located during the appointment.
- Payment information necessary to process a transaction. Payment cards are processed through Stripe or another approved payment processor. The public website does not store full payment card numbers.
- Technical information such as IP address, device type, browser type, operating system, server logs, and security-related event data.
- Non-clinical referral and attribution information, such as whether you arrived from a clinician, Thea, media page, or campaign.
- Communications you send to us.
- Clinical information that you submit through the designated intake, telemedicine, or medical-record workflow, including photographs, medical history, medications, allergies, prior treatment, pharmacy information, and uploaded records.
2. PHI, Tracking Technologies, and Analytics
Our digital infrastructure and analytics configurations prohibit the disclosure of PHI to unauthorized advertising, tracking, or analytics vendors. We do not permit diagnoses, medication requests, clinical photographs, intake responses, free-text clinical information, appointment details linked to an identifiable patient, or other PHI to be sent to advertising platforms.
Booking, booking-confirmation, intake, consent, and clinical pages do not use advertising pixels or session-replay technologies. Third-party technologies that create, receive, maintain, or transmit PHI on our behalf may be used only when the disclosure is permitted by law and any required Business Associate Agreement is in place.
Public marketing pages may use limited analytics that are segregated from clinical workflows. URLs, query strings, form fields, and analytics events must not contain diagnoses, requested medications, photographs, intake data, or free-text clinical information.
Where IP address or approximate geolocation is used for security or licensure-verification purposes in connection with patient care, that information is handled within an approved clinical or security workflow and is not disclosed to advertising vendors.
3. How We Use Information
- To determine whether telemedicine may be available based on the patient's physical location at the time of care.
- To schedule, confirm, reschedule, or cancel appointments.
- To process payments, receipts, refunds, and billing questions.
- To provide, coordinate, document, and support health care.
- To verify identity and patient location.
- To communicate about appointments, intake requirements, laboratory monitoring, prescriptions, records, billing, and other operational or care-related matters.
- To protect the security, integrity, and availability of our systems.
- To comply with legal, licensing, regulatory, professional, and recordkeeping obligations.
- To conduct limited analytics on public pages without disclosing PHI to unauthorized vendors.
4. Clinical Systems
The clinical workflow may use Google Workspace tools configured for Dermatologic Services, including Google Calendar, Google Meet, Google Forms, and Google Drive. Office Ally / Practice Mate is used as the formal medical record system for the direct-care workflow. Stripe may be used for payment processing. Vendors that handle PHI on our behalf are subject to HIPAA and contractual requirements when applicable.
No electronic system is immune from all security risk. Dermatologic Services uses administrative, technical, and physical safeguards and maintains policies designed to prevent unauthorized access, use, disclosure, alteration, or destruction of PHI.
5. Disclosure of Information
We may disclose information only as permitted or required by law and as reasonably necessary for treatment, payment, health care operations, administration, security, or other lawful purposes. Recipients may include:
- Treating clinicians, pharmacies, laboratories, and other health care providers involved in your care.
- Business associates and service providers supporting hosting, scheduling, communications, payments, records, cybersecurity, legal, accounting, and administrative functions.
- Government agencies, regulators, courts, or law enforcement when disclosure is required or permitted by law.
- A lawful successor in connection with a merger, reorganization, or transfer of practice assets, subject to applicable confidentiality requirements.
- Other persons when you authorize or direct the disclosure.
We do not sell PHI. We do not sell personal information for monetary consideration.
6. Electronic Communications
Dermatologic Services may use email or SMS for appointment reminders, scheduling links, intake links, receipts, operational messages, and limited care-related communications. Reasonable safeguards are used, including limiting sensitive content when an unencrypted channel is used.
If you affirmatively elect to receive unencrypted email or SMS communications, you acknowledge the specific privacy and cybersecurity risks described in the separate Unencrypted Electronic Communication Consent. You may revoke that election prospectively and request another reasonable communication method.
Dermatologic Services will not require you to accept unencrypted transmission of medical records as a condition of exercising a legal right to access your records.
7. Third-Party Services
The Services may link to independent third-party services. Thea is a separate service. Information collected by Thea is governed by Thea's own privacy practices. Dermatologic Services' comprehensive consultation is separately provided and billed by Dermatologic Services.
Institutional and insurance referrals may be routed to DermatologicServices.com and handled through a separate workflow.
8. Adults Only for Direct-to-Consumer Booking
The direct-to-consumer online booking pathway is limited to individuals age 18 or older. Individuals under 18 may not use the direct-pay booking pathway. Any care involving a minor must occur, if offered at all, through a separate workflow with legally sufficient consent and identity verification.
9. Data Retention
We retain information for periods reasonably necessary to provide care, meet legal and regulatory obligations, maintain medical and business records, resolve disputes, and protect patient safety. Medical-record retention periods are determined by applicable law and may vary by jurisdiction and patient age.
10. Your Rights
Depending on applicable law, you may have rights to access, amend, correct, restrict, or obtain information about certain uses or disclosures of your information. HIPAA rights relating to PHI are described in our Notice of Privacy Practices. State privacy laws may provide additional rights for information not governed by HIPAA.
11. Security Incidents
If we determine that a breach or other incident requires notice, we will provide notice as required by applicable law.
12. Changes
We may update this Privacy Policy. The current version will be posted with its effective date.
13. Contact
Privacy questions or requests may be directed to Dermatologic Services, PLLC at manager@dermatologicservices.com, 347-291-1877, or 20 W Spring Ave, Ardmore, PA 19003.