Privacy Policy

Last Updated: February 9, 2026

1. Who We Are

This Privacy Policy applies to:

Bellus Medical ND (“Bellus Medical”)
3108 S. Broadway
Minot, ND 58701
701-509-5614
https://bellusmedicalnd.com

Bellus Medical is a licensed healthcare provider operating in the State of North Dakota.

This public website is hosted and managed by Indak Media, which acts as the website and marketing administrator. Website forms are provided by HIPAA-compliant software, Plains.io.

This Privacy Policy governs information collected from:

  • Website visitors

  • Prospective patients

  • Current patients

  • Individuals submitting forms through our website

Bellus Medical complies with all applicable federal and state privacy laws, including the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and North Dakota healthcare privacy regulations.

2. Website Platform and Secure Medical Systems

Bellus Medical’s public website is intended for informational and marketing purposes only.

The website does not directly collect, store, or maintain Protected Health Information (PHI).

When a user:

  • Schedules an appointment

  • Completes medical intake forms

  • Accesses patient-specific services

  • Enters health history information

  • Uses the patient portal

They are securely redirected to OptiMantra, Bellus Medical’s HIPAA-compliant Electronic Medical Record (EMR), scheduling system, and patient portal.

All PHI, including medical intake forms, appointment details related to care, clinical documentation, lab results, prescriptions, and patient communications, is collected, processed, stored, and retained exclusively within OptiMantra.

OptiMantra:

  • Operates as a HIPAA-compliant platform

  • Utilizes encryption and secure data transmission

  • Implements role-based access controls

  • Maintains required Business Associate Agreements (BAAs)

  • Retains records in accordance with federal and North Dakota regulatory requirements

Bellus Medical does not store medical records within website hosting platforms, marketing systems, or advertising tools.

Website forms and electronic communications are not monitored continuously and should not be used for medical emergencies.

3. Information We Collect

A. Website and Marketing Information (Non-PHI)

Through Plains.io, WordPress, and analytics tools, we may collect:

  • Name

  • Email address

  • Phone number

  • Company or industry information (if submitted)

  • Custom form responses that do not include medical information

  • IP address

  • Browser and device information

  • Pages visited and interactions

If visitors leave comments, we may collect:

  • Data shown in the comment form

  • IP address

  • Browser user agent (for spam detection)

If images are uploaded to the website, embedded EXIF GPS data may be accessible to other visitors.

This information is used for communication, appointment requests, marketing, analytics, and website functionality.
Unless submitted through OptiMantra, this information is not considered Protected Health Information.

Marketing communications are based solely on non-medical contact information and do not include or reference Protected Health Information.

B. Medical and Protected Health Information (PHI)

All medical intake forms, health history, appointment scheduling related to medical care, treatment records, lab results, prescriptions, and clinical communications are collected and maintained exclusively within OptiMantra.

PHI is:

  • Protected under HIPAA Privacy, Security, and Breach Notification Rules

  • Retained in accordance with federal and North Dakota medical record retention laws

  • Accessible only to authorized personnel

  • Protected through reasonable administrative, technical, and physical safeguards

4. How We Use Your Information

Website and Marketing Data

Non-medical website data may be used to:

  • Respond to inquiries

  • Process appointment requests

  • Send newsletters or promotional communications (you may unsubscribe at any time)

  • Analyze website usage and performance

  • Moderate and display user comments

  • Improve services and website functionality

Medical Information (PHI)

PHI is used to:

  • Provide medical evaluation and treatment

  • Coordinate care

  • Process billing and payments

  • Maintain accurate medical records

  • Comply with legal and regulatory obligations

PHI is used and disclosed only as permitted or required by HIPAA.

5. HIPAA and Regulatory Compliance

Bellus Medical complies with:

  • HIPAA Privacy Rule

  • HIPAA Security Rule

  • HIPAA Breach Notification Rule

  • Applicable North Dakota healthcare privacy laws

We implement reasonable safeguards designed to protect personal and medical information, including:

  • Secure EMR systems

  • Role-based access controls

  • Secure hosting environments

  • Encrypted data transmission, where applicable

  • Staff HIPAA training

  • Business Associate Agreements with vendors handling PHI

  • Secure authentication protocols

This Privacy Policy does not replace Bellus Medical’s HIPAA Notice of Privacy Practices, which governs the use and disclosure of Protected Health Information. Our Notice of Privacy Practices is available in-office and upon request.

6. Sharing and Disclosure

We do not sell patient data.

A. Service Providers

Website and marketing services may be provided by:

  • Plains.io

  • Indak Media

  • CRM and email communication systems

  • Analytics providers

  • Spam-filtering services

Medical data may be shared only with:

  • OptiMantra (HIPAA-compliant EMR)

  • Payment processors

  • Laboratories

  • Healthcare partners, as permitted by law

All vendors handling PHI are required to maintain HIPAA compliance and execute Business Associate Agreements where applicable.

B. Legal and Regulatory Disclosures

We may disclose information when required:

  • In response to subpoenas, court orders, or lawful requests

  • To public health authorities

  • For regulatory oversight and compliance

  • To prevent serious threats to health or safety

7. Cookies and Tracking Technologies

Our website may use:

  • Meta (Facebook) Pixel for conversion tracking and remarketing

  • Google Analytics 4 for traffic measurement

  • Plains.io form cookies for form functionality and reminders

WordPress cookies may include:

  • Comment cookies (retained for one year)

  • Login cookies (retained for two days or two weeks if “Remember Me” is selected)

  • Screen option cookies (retained for one year)

  • Post-edit cookies (retained for one day)

Session cookies may be disabled through browser settings.

Opt-out options:

8. Embedded Content from Other Websites

Articles or media on this site may include embedded content such as videos or images. Embedded content behaves in the same way as if you visited the originating website and may collect data according to that third party’s privacy policy.

9. Data Retention

  • Comments and related metadata are retained indefinitely to facilitate moderation.

  • Website and lead data is retained as necessary for follow-up or until deletion is requested.

  • Medical records are retained exclusively within OptiMantra in accordance with HIPAA and North Dakota medical record retention laws. Medical records cannot be deleted upon request.

10. Your Rights

You may request to:

  • Access your medical records (HIPAA right of access)

  • Request corrections to your medical records

  • Request restrictions on certain disclosures

  • Receive an accounting of disclosures

  • Obtain an export of website form data

  • Opt out of marketing communications

  • Request deletion of non-medical website data

Requests may be submitted to:
admin@bellusmedicalnd.com

You may also file a complaint with the U.S. Department of Health and Human Services without fear of retaliation.

11. Where Your Data Is Sent

  • Visitor comments may be checked through automated spam detection services.

  • Website data is shared only with providers listed in this Privacy Policy.

  • Medical data is maintained exclusively within OptiMantra’s secure HIPAA-compliant systems.

12. Changes to This Policy

We may update this Privacy Policy periodically. Any changes will be reflected by an updated “Last Updated” date at the top of this page.

13. Contact Information

Bellus Medical ND
3108 S. Broadway
Minot, ND 58701
701-509-5614
admin@bellusmedicalnd.com

Website Administration:
Indak Media
info@indakmedia.com