top of page

Privacy Policy

1. Introduction

Direct Access Primary Care (“DAPC,” “we,” “our,” or “us”) provides direct primary care membership services to patients in and around Waco, Texas. This Privacy Policy describes how we collect, use, safeguard, and disclose information when you visit our website at directaccessdpc.com, complete a Meet & Greet or enrollment form, or become a member of the practice.

We designed this policy to be plain and specific to how DAPC actually operates: the vendors we use, the way we communicate with patients, and the protections we apply to health information, rather than a generic statement of practices.

2. Our Approach to Privacy and HIPAA

Direct Access Primary Care operates on a membership basis and does not bill insurance companies, Medicare, or Medicaid, and does not engage in the electronic billing transactions that typically make a healthcare practice a “covered entity” under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). As a result, DAPC is generally not required by law to comply with HIPAA in the same manner as a traditional, insurance-based medical practice.

Notwithstanding that distinction, DAPC has voluntarily adopted safeguards, vendor agreements, and internal practices consistent with HIPAA's privacy and security standards, because protecting patient health information is core to how we operate. Throughout this policy, references to protecting “protected health information” or “PHI” describe the categories of health information we choose to safeguard using HIPAA-consistent practices, not an acknowledgment that DAPC is a HIPAA covered entity.

3. Information We Collect

3.1 Health Information

In the course of providing care, we may collect:

  • Identifying information such as name, date of birth, address, phone number, and email

  • Medical history, conditions, medications, and treatment records

  • Information you provide during a Meet & Greet, intake, or visit

  • Billing and membership payment information

3.2 Other Personal Information

We may also collect information that is not health information, such as:

  • Account or membership portal credentials

  • Communication and contact preferences

  • Feedback, testimonials, or survey responses you choose to provide

3.3 Website and Technical Information

When you visit directaccessdpc.com, our website platform, Wix, automatically collects limited technical information, such as browser type, device type, approximate location derived from IP address, referring pages, and the pages you view. This information helps us understand how visitors use the site and is not used to identify you individually.

3.4 Cookies and Similar Technologies

Our website, built on Wix, uses cookies and similar technologies to support basic site functionality and to understand aggregate visitor activity. You can manage or block cookies through your browser settings; doing so may limit some website functionality.

4. How We Collect Information

We collect information directly from you (for example, when you submit a Meet & Greet request, complete an enrollment form, or speak with our staff), automatically through your use of our website, and, where applicable, from other healthcare providers involved in your care with your authorization.

5. How We Use Your Information

5.1 To Provide Care and Manage Membership

  • Delivering direct primary care services and coordinating your treatment

  • Managing your membership, scheduling, and billing

  • Communicating with you about appointments and follow-up care

5.2 To Operate Our Practice

  • Maintaining accurate records through our electronic medical record system

  • Improving our website and patient intake processes

  • Responding to inquiries submitted through our website or Meet & Greet form

5.3 For Marketing Communications (With Your Consent)

With your consent, we may send general newsletters, wellness information, or updates about DAPC through our email marketing platform, Mailchimp. Marketing communications sent through Mailchimp are limited to general, non-patient-specific content; we do not send protected health information through Mailchimp. You may unsubscribe from marketing emails at any time using the link included in each message.

6. Vendors and Service Providers

We rely on a small number of vendors to operate the practice, each limited to a specific role:

6.1 Atlas.md (Electronic Medical Record)

Atlas.md is our electronic medical record system, purpose-built for direct primary care practices, and is the only system in which we maintain clinical records, prescriptions, and health information. We maintain a signed Business Associate Agreement with Atlas.md, and access to patient records within the system is limited to authorized staff.

6.2 Google Workspace

We use Google Workspace, including Gmail, Google Drive, Google Calendar, and Google Meet, for secure communications, document storage, scheduling, and telehealth visits. We maintain a signed Business Associate Agreement with Google covering our use of Workspace services in connection with patient information.

6.3 Mailchimp

We use Mailchimp solely for general marketing emails and newsletters sent to patients and prospective patients who have opted in. Mailchimp is not used to store or transmit medical records, treatment information, or any other protected health information.

6.4 Wix

Our website, directaccessdpc.com, is built and hosted on Wix. Forms on our website are used to collect basic contact information only and are not used to collect or transmit protected health information.

7. Disclosure of Your Information

We do not sell your personal or health information. We may disclose information:

  • With your written authorization

  • To other healthcare providers involved in your care, at your request or with your consent

  • To our vendors described above, solely to the extent necessary for them to perform services on our behalf

  • When required by law, such as in response to a valid subpoena, court order, or public health reporting obligation

  • To prevent a serious and imminent threat to the health or safety of a person

8. Data Security

We apply administrative, technical, and physical safeguards designed to protect the information we hold, including:

  • Restricting access to health records within Atlas.md to authorized staff

  • Using Business Associate Agreements with vendors who may handle protected health information

  • Applying encryption and access controls available through our Google Workspace and Atlas.md environments

  • Keeping marketing communications (Mailchimp) and clinical records (Atlas.md) on entirely separate systems

9. Communication Preferences

By default, we communicate with patients about clinical or billing matters through secure channels such as the Atlas.md patient portal, Google Workspace email, or telephone. Patients may choose to receive appointment reminders or administrative communications by standard text message or unencrypted email for convenience; choosing these methods means accepting the reduced security of those channels compared to our secure portal. You may update your communication preferences at any time by contacting our office.

10. Your Privacy Choices

Because DAPC is not a HIPAA covered entity, the formal patient rights created by the HIPAA Privacy Rule do not apply to our practice by operation of law. However, as a matter of practice, we will honor requests consistent with those rights, including a request to:

  • Access or receive a copy of your medical records maintained in Atlas.md

  • Request a correction to information you believe is inaccurate

  • Request restrictions on how your information is used or shared

  • Withdraw consent to marketing communications at any time

To make any of these requests, contact our office using the information in Section 13 below.

11. Children's Privacy

Our website is intended for adults seeking or managing care for themselves or their family members. We do not knowingly collect personal information directly from children through our website. Information about minor patients is collected only through their parent or legal guardian in connection with the provision of care.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, vendors, or applicable law. The effective date below will be updated whenever this policy changes, and we encourage you to review it periodically.

13. Contact Us

If you have questions about this Privacy Policy or how we handle your information, please contact us at:

Direct Access Primary Care

711 Melrose Dr.

Waco, Tx 76710

14. Effective Date

This Privacy Policy is effective as of July 15, 2026.

bottom of page