Clear information. Thoughtful stewardship.
Your privacy should be as clear as our communication.
This notice explains how Nightingale Studios handles information submitted through this website and how we approach health information when working with healthcare and public-health clients.
Last updated: September 13, 2026
The public website and contact form are not designed to collect protected health information (PHI), medical records, or sensitive patient information. Please do not submit patient names, diagnoses, treatment information, medical record numbers, insurance information, or other sensitive health information through the public contact form or ordinary email.
1. Scope of this notice
This notice applies to information collected through nightingalestudios.info and direct website inquiries. Client engagements may be governed by separate contracts, data-processing terms, Business Associate Agreements, confidentiality obligations, or client privacy requirements.
2. Information we collect
When you contact Nightingale through the website, we may collect the information you choose to provide, such as your name, organization, email address, service interest, and project message. Our hosting provider may also process limited technical information such as IP address, browser type, device information, timestamps, and security logs as part of operating and protecting the website.
3. How we use information
We use website inquiry information to respond to requests, evaluate potential projects, communicate about services, maintain business records, protect the website from misuse, and meet legal or regulatory obligations. We aim to collect only information that is reasonably necessary for these purposes.
4. Contact-form email delivery
Please use our contact form to send website inquiries. Because ordinary website forms and email are not intended as a channel for PHI, the form requires users to confirm that they have not included sensitive patient or health information.
5. HIPAA and protected health information
HIPAA applies to covered entities and, in certain circumstances, their business associates. Nightingale's work with a healthcare organization does not automatically make every website interaction subject to HIPAA. When an engagement requires Nightingale to create, receive, maintain, or transmit PHI on behalf of a HIPAA-covered entity, Nightingale will use an appropriate written agreement, including a Business Associate Agreement when required, and an approved workflow designed for the engagement before receiving PHI.
This website notice is not a HIPAA Notice of Privacy Practices for a healthcare provider or health plan, and the public contact form should not be used to transmit PHI. Nightingale does not represent this public website or ordinary email as a HIPAA-compliant clinical communication channel.
6. Health data outside HIPAA
Some health-related information may be protected by laws other than HIPAA. Where applicable, Nightingale will evaluate obligations under consumer-protection and breach-notification laws, including the Federal Trade Commission Act and the FTC Health Breach Notification Rule. The specific law that applies depends on the information, the service, and Nightingale's role in the relevant engagement.
7. Sharing and service providers
We may share personal information with service providers that support website hosting, email delivery, security, or professional services, but only as reasonably necessary for those functions and subject to appropriate contractual or confidentiality protections where applicable. We do not currently sell personal information collected through this website, and we do not use website inquiry information for targeted advertising.
8. Retention
We retain website inquiry information only for as long as reasonably necessary to respond to the inquiry, evaluate or manage a business relationship, maintain appropriate business records, protect our legal interests, or satisfy legal requirements. Retention periods may vary depending on the nature of the inquiry and whether it becomes part of a client engagement.
9. Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the information and the nature of our services. No website, email system, or internet transmission can be guaranteed to be completely secure. Sensitive health information should be exchanged only through a secure workflow approved for the applicable engagement.
10. Consumer privacy rights
Depending on where you live and whether a particular privacy law applies, you may have rights to request confirmation of processing, access, correction, deletion, or portability of certain personal information, and to opt out of certain uses such as targeted advertising, sale of personal data, or certain profiling. Texas residents may have rights under the Texas Data Privacy and Security Act where that law applies.
To submit a privacy request, use our contact form and begin your message with Privacy Request. We may need to verify your identity before completing a request. If applicable law provides an appeal right and we deny your request, you may appeal using the same form and beginning your message with Privacy Appeal.
11. Children
This website is intended for organizations and adults seeking professional health-communication services. It is not directed to children under 13, and Nightingale does not knowingly seek personal information from children through this website.
12. Cookies and analytics
The current website does not include advertising cookies or third-party behavioral advertising trackers. A hosting provider may use essential technologies or server logs needed to deliver, secure, and maintain the site. If Nightingale adds analytics, advertising, or other tracking technologies in the future, this notice and any consent controls will be updated as required.
13. Changes to this notice
We may update this notice as our website, services, vendors, or legal obligations change. The date above identifies the most recent update. Material changes will be presented in a reasonably clear manner.
14. Contact
For questions about privacy or health-information handling, please use our contact form.
Regulatory reference points
Our privacy approach is informed by official guidance from the U.S. Department of Health & Human Services regarding HIPAA covered entities, business associates, and the Security Rule; Federal Trade Commission guidance regarding consumer health information and the Health Breach Notification Rule; and the Texas Attorney General's guidance regarding the Texas Data Privacy and Security Act. This notice is general information about Nightingale's website practices and is not legal advice.
HHS: Covered Entities & Business Associates · HHS: HIPAA Security Rule · FTC: Consumer Health Information · Texas Attorney General: Consumer Privacy Rights