Privacy Notice
Patient Privacy Policy
This policy explains how Dr. Shira Fishman's practice collects, uses, protects, and retains your personal and medical information across our website, telehealth booking system, video visits, and patient portal.
Scope of this policy
This policy applies to the informational website, the telehealth booking and intake system, video visits conducted through our platform, the patient portal, and all associated communications (email and WhatsApp). It applies to all patients, including minors whose parent or legal guardian manages their account.
Information we collect
We collect: identifying information (full name, date of birth, and a government-issued ID document or number, which is encrypted before storage); contact details (email, phone); the reason for your visit and any medical history, lab results, or imaging you choose to upload; video, audio, and an automatically generated transcript of your telehealth session; payment method details, which are tokenized by our payment processor and never stored in full on our servers; messages you send through the patient portal; and limited technical data (such as IP address and device type) used for security and fraud prevention. We also use anonymous, cookie-free website analytics (aggregate page-visit counts only) to understand how the site is used; this does not identify you individually and does not track you across other websites. Some of this information is required to provide care, verify your identity, process payment, issue invoices, and maintain legally required medical records — if you do not provide it, or do not consent to processing that is necessary for the requested telehealth service, we may be unable to provide that service. Uploads beyond what is required are optional unless Dr. Fishman determines they are clinically necessary for your care.
How we use your information
We use your information to schedule and deliver your care, verify your identity before a telehealth visit, process payment for services rendered, send appointment confirmations and reminders, maintain an accurate medical record, generate legally required tax invoices, and meet our recordkeeping and reporting obligations under Israeli law. We do not use your medical information for marketing, and we do not sell your information to any third party.
How your information is protected
Because health and identifying information are highly sensitive, we apply safeguards appropriate to sensitive medical information and at least the security measures required for the applicable classification of this data under Israel's Privacy Protection Law 5741-1981 and the Protection of Privacy (Data Security) Regulations, 5777-2017: identifying fields such as your ID number are encrypted at the database level; access to your record is restricted by role and logged in a permanent access audit log; files are served only through private, time-limited signed links rather than public URLs; and your consents are recorded with a version and timestamp so we always know exactly what you agreed to.
Database owner/controller: Dr. Shira Fishman, Osek Murshe No. 347985863. Dr. Fishman is responsible for the patient-record, booking, intake, and telehealth databases used by the practice.
Who we share information with
We share information only with the service providers necessary to deliver your care, each bound by confidentiality and security obligations: Zoom (video visits and session recording), our payment processor (payment processing only — we do not receive your full card number), Google Calendar (appointment scheduling only — no medical detail is shared), and Resend and Twilio (email and WhatsApp appointment notifications). We also use Vercel Web Analytics, a cookie-free analytics tool that records aggregate website usage statistics — such as pages viewed and an approximate country derived from IP address — and does not identify individual visitors. Some of these providers process data outside Israel. Cross-border transfers are made only where a lawful transfer basis applies, including written data-processing undertakings requiring the recipient to protect the data, use it only for the authorized service, maintain confidentiality and security controls, and not transfer it onward except as legally and contractually permitted. We otherwise share information only when required by law or with your explicit consent.
Minor patients
A patient under 18 is booked and managed exclusively through a parent or legal guardian's account for telehealth; minors do not log in independently. Consents for a minor's telehealth care are recorded as given by their guardian, and the guardian's identity is linked to the minor's record. Care that a minor patient is legally entitled to receive on a confidential basis is provided in person rather than by telehealth, so that it is not visible through a guardian's account.
How long we keep your information
Medical records, including session recordings and transcripts, are retained for the period required for continuity of care and by applicable Israeli medical recordkeeping requirements, and for as long afterward as needed to cover the applicable statute-of-limitations period for medical claims (which runs longer for records relating to a minor patient). Tax invoices are retained for seven years as required by Israeli tax law. Non-clinical records, such as failed bookings, technical logs, and payment tokens, are retained only as long as needed for security, accounting, or operational purposes. If you close your patient account, your medical records are retained as required by law rather than deleted, but your ability to log in is removed. Deletion requests are reviewed case by case and honored where the practice is not legally or clinically required to retain the data.
Your rights
You may request access to, or correction of, your personal information at any time. You may request deletion of information that we are not separately required to retain for legal, medical-record, or tax purposes. To exercise any of these rights, contact the practice directly.
If your data is affected by a security incident
If a breach affecting your personal information occurs, we will notify you and, where required, the Israeli Privacy Protection Authority, in accordance with Israeli law.
Changes to this policy
If this policy changes in a way that materially affects how your information is used, we will post the updated policy here and, where appropriate, ask for renewed consent before your next telehealth visit.
Questions about this policy or requests regarding your information can be sent to
drshirafishman@gmail.com. In a medical emergency, do not use email — call 101 or go to the nearest emergency room.