Privacy Policy

Last Modified: April 2, 2026

This notice describes how medical information about you may be used and disclosed and how you can obtain access to this information. Please review it carefully.

Introduction

This Privacy Policy describes how Bariatric Centers of America, LLC collects and uses Personal Data about you through the use of our Website, and through email, text, and other electronic communications between you and Bariatric Centers of America, LLC or our partnered bariatric clinics.

Bariatric Centers of America, LLC (“Bariatric Centers of America,” or “we,” “our,” or “us”) respects your privacy, and we are committed to protecting it through our compliance with this policy.

This Privacy Policy (our “Privacy Policy”) describes the types of information we may collect from you or that you may provide when you visit the website bcofa.com or baritotalcare.com (our “Websites”) and our practices for collecting, using, maintaining, protecting, and disclosing that information.

This policy applies to information we collect:

  • on our Website;
  • in email, text, and other electronic messages between you and our Website;
  • when you interact with our advertising and applications on third-party websites and services, if those applications or advertising include links to this policy;
  • when you interact with a Bariatric Centers of America partnered bariatric clinic’s website;
  • when you or your provider uses BariLead, our patient engagement and marketing platform; and
  • when you use BariSuccess, including data collected through integrated remote patient monitoring devices such as connected scales.

It does not apply to information collected by:

  • us offline or through any other means, including on any other website operated by any third party;
  • any third party, including through any application or content (including advertising) that may link to or be accessible from or on the Website;

Note: Bariatric Centers of America is not a medical group. Any consult requests submitted or obtained through our Website are provided by independent (i.e. not employed or paid by Bariatric Centers of America) medical practitioners at the partnered bariatric clinic, which are independent medical groups within a network of United States-based bariatric surgeons, medical weight loss physicians, health coaches, and other healthcare professionals (each, a “Provider”).  Your own medical provider is responsible for providing you with a Notice of Privacy Practices describing its collection and use of your health information, not Bariatric Centers of America. If you do not agree to be bound by those terms, you are not authorized to access or use our Website, and you must promptly exit our Website.

Please read this policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is to not use our Website. By accessing or using our Website, you agree to this Privacy Policy. This Privacy Policy may change from time to time (see below for Changes to Our Privacy Policy). Your continued use of our Website after we make changes is deemed to be acceptance of those changes, so please check this Privacy Policy periodically for updates.

Personal Information We Collect From You

We collect different types of information about you, including information that may directly identify you, information that is about you but individually does not personally identify you, and information that we combine with our other users. That includes information that we collect directly from you or through automated collection technologies. Data will be collected, stored and used in a manner that ensures it is relevant, timely, accurate, coherent, transparent and accessible. It is your responsibility to provide us with quality data when asked so we can appropriately serve you. 

We may also collect biometric data (e.g., body weight) when using integrated digital health tools (e.g., remote patient monitoring devices such as connected scales provided through BariSuccess) through our Website or connected third-party platforms.

Generally

We collect several types of information from and about users of our Website, specifically information:

  • by which you may be personally identified, such as name, address, e-mail address, telephone numbers, date of birth, your medical history, health information, and health insurance coverage (“Personal Data”) when you submit a website form;
  • that is about you but individually does not identify you, such as traffic data, logs, referring pages/links, date and time of your visit to our Website, error information, clickstream data (third-party tracking apps such as Google analytics), and other communication data and the resources that you access and use on the Website; or
  • about your Internet connection, the equipment you use to access our Website, IP Address, location of where you access our Website, and other usage details.

We collect this information:

  • directly from you when you provide it to us;
  • from our partnered bariatric clinics when they enter information into our system;
  • automatically as you navigate through the Website. Information collected automatically may include usage details, IP addresses, and information collected through cookies and other tracking technologies;
  • through connected devices such as Withings-integrated smart scales used as part of the BariSuccess program; and
  • from third parties, for example, our business partners and Providers.

Information You Provide to Us

The information we collect on or through our Website is:

  • information that you provide by filling in forms on our Website. This includes information provided when you request an appointment, using our Provider consultation services, purchasing products, or requesting further services. We may also ask you for information when you report a problem with our Website;
  • records and copies of your correspondence (including mobile phone for text messages and email addresses), if you contact us; and
  • details of transactions you carry out through our Website via Stripe if purchasing a digital scale for RPM. You may be required to provide financial information before placing an order through our Website.

Information We Collect Through Automatic Data Collection Technologies

As you navigate through and interact with our Website, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns, specifically:

  • details of your visits to our Website, such as traffic data, location, logs, referring/exit pages, date and time of your visit to our Website, error information, clickstream data (third-party tracking apps such as Google analytics), and other communication data and the resources that you access and use on the Website; and
  • information about your computer, Internet connection, specifically your IP address and browser type.

The information we collect automatically may include Personal Data or we may maintain it or associate it with Personal Data we collect in other ways or receive from third parties. It helps us to improve our Website and to deliver a better and more personalized service by enabling us to:

  • estimate our audience size and usage patterns;
  • store information about your preferences, allowing us to customize our Website according to your individual interests; and
  • recognize you when you return to our Website.

The technologies we use for this automatic data collection may include:

  • Cookies (or browser cookies). We and our service providers may use cookies, web beacons, pixels, and other technologies to receive and store certain types of information whenever you interact with our Website through your computer or mobile device. A “cookie” is a small file placed on the hard drive of your computer or mobile device. On your computer, you may refuse to accept browser cookies by activating the appropriate setting on your browser, and you may have similar capabilities on your mobile device in the preferences for your operating system or browser. However, if you select this setting you may be unable to access certain parts of our Website. Unless you have adjusted your browser or operating system setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our Website.
  • Google Analytics. We use Google Analytics, a web analytics service provided by Google, Inc. (“Google”) to collect certain information relating to your use of the Website. Google Analytics uses cookies to help the Website analyze how users use the site. You can find out more about how Google uses data when you visit our Website by visiting “How Google uses data when you use our partners’ sites or apps”, (located at google.com/policies/privacy/partners/ ). We may also use Google Analytics Advertising Features or other advertising networks to provide you with interest-based advertising based on your online activity. For more information regarding Google Analytics please visit Google’s website, and pages that describe Google Analytics, such as www.google.com/analytics/learn/privacy.html .

BariLead – AI Powered Patient Marketing Campaigns

Bariatric Centers of America offers BariLead, a patient engagement and marketing platform available to our partnered bariatric clinics. If your clinic uses BariLead, certain information about you may be used to deliver AI-powered marketing campaigns designed to support your care journey and inform you of relevant services and programs.

What Information Is Used

For patients whose clinics have enrolled in BariLead, we may use the following categories of your information in connection with AI marketing campaigns:

  • Contact and identification information: your name, email address, phone number, and similar contact details.
  • Behavioral and engagement data: information about how you interact with communications, our Website, and related digital touchpoints (e.g., whether you have opened an email, clicked a link, or scheduled a consultation).

We do not use your medical records, diagnoses, clinical notes, or detailed health information for AI marketing campaign targeting within BariLead.

How This Information Is Used

The information described above may be processed by AI-driven tools to:

  • personalize outreach communications about bariatric care services relevant to your stage of the patient journey;
  • determine the timing, channel (e.g., email or SMS), and content of marketing messages sent on behalf of your clinic; and
  • analyze engagement patterns to improve the effectiveness of patient communications.

Marketing campaigns sent through BariLead are conducted on behalf of your partnered bariatric clinic, not by Bariatric Centers of America for its own commercial benefit. Your contact information is not sold to third parties, and your opt-in consent is not shared with any third-party organizations.

Your Choices Regarding BariLead Communications

You may opt out of AI-powered marketing communications at any time by:

  • clicking the unsubscribe link at the bottom of any email communication;
  • replying STOP to any SMS message; or
  • contacting us directly at care@bcofa.com.

Opting out of marketing communications will not affect your receipt of appointment reminders, care notifications, or other service-related messages necessary to your care.

BariSuccess – Remote Patient Monitoring and Withings Integration

BariSuccess is our remote patient monitoring (RPM) program, which may include a connected smart scale (currently provided through an integration with Withings, a third-party digital health platform). If you or your clinic participates in BariSuccess, the following applies to how your data is collected, used, and shared.

How Data Flows Through the BariSuccess Integration

When you use a BariSuccess-connected smart scale, body weight and related biometric measurements are collected by the device. That data flows as follows:

  • From the scale, your biometric data is transmitted to Withings’ platform and mobile application, where it is stored and displayed in accordance with Withings’ own privacy policy.
  • Withings then transmits your biometric data (such as weight measurements) into the Bariatric Centers of America system, where it becomes part of your patient record accessible to your care team.

Bariatric Centers of America does not control Withings’ collection, storage, or use of your data on the Withings platform. We encourage you to review Withings’ Privacy Policy at withings.com/us/en/legal/privacy-policy to understand how they handle your information.

What Biometric Data Is Collected

Through the BariSuccess Withings integration, we may collect and store the following types of data in our system:

  • body weight and weight trend data;
  • date and time of each measurement; and
  • device identifiers associated with the connected scale.

This data is used by your care team to monitor your progress, provide clinical support, and improve your care outcomes.

Withings as a Third-Party Service Provider

Withings operates as a third-party technology provider in connection with BariSuccess. Data shared with Withings is subject to a data processing arrangement consistent with applicable privacy and health data regulations, including HIPAA where applicable. Withings is required to maintain appropriate security standards for any health-related data processed on our behalf.

If you do not wish your scale data to be transmitted into the Bariatric Centers of America system, please contact your care team or reach us at care@bcofa.com to discuss alternative monitoring arrangements.

Permitted Use of Your Information and Disclosures

We use your Personal Data for various purposes described below, including to:

  • provide our Website to you;
  • provide products and services to you;
  • provide you with the information you request from us;
  • enforce our rights arising from contracts;
  • notify you about changes;
  • provide you with notices about your account;
  • enable the delivery of health-related services through third-party integrations, including remote patient monitoring (RPM) systems such as BariSuccess;
  • deliver AI-powered patient engagement campaigns through BariLead on behalf of your partnered clinic; and
  • Improve user experience by analyzing trends and user activity through advanced data aggregation tools.

We use information that we collect about you or that you provide to us, including any Personal Data:

  • to present our Website and its contents to you;
  • to provide you with information, products, or services that you request from us;
  • to contact you in response to a request;
  • to fulfill any other purpose for which you provide it;
  • to carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection;
  • to notify you about changes to our Website or any products or services we offer or provide through them;
  • in any other way we may describe when you provide the information; and
  • for any other purpose with your consent.

We may also use your information to contact you about goods and services that may be of interest to you, including through newsletters. If you wish to opt-out of receiving such communications, you may do so at any time by clicking unsubscribe at the bottom of these communications. We do not share the opt-in consent to any 3rd party organizations.

Disclosures Related To Communications With You Or Your Family

We do not share, sell, or otherwise disclose your Personal Data for purposes other than those outlined in this Privacy Policy. We disclose your Personal Data to a few third parties, including:

  • to your bariatric provider whom you are working with;
  • to third-party service providers that we use to support our business, including patient engagement platforms (BariLead) and remote patient monitoring technology providers (Withings via BariSuccess);
  • to third-party service providers that we use to support our business;
  • to a company we merge, acquire, or that buys us, or in the event of a change in the structure of our company of any form;
  • to comply with our legal obligations;
  • to enforce our rights; and
  • with your consent.

We do not share, sell, or otherwise disclose your Personal Data for purposes other than those outlined in this Privacy Policy. However, we may disclose aggregated information about our users, and information that does not identify any individual, without restriction.

We may disclose Personal Data that we collect or you provide as described in this privacy policy:

  • to contractors, service providers, and other third parties we use to support our business, including IT and infrastructure support services, patient navigation, digital marketing, remote patient monitoring (RPM) platforms, and AI-powered patient engagement tools;
  • to a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Bariatric Centers of America about our Website users are among the assets transferred;
  • to fulfill the purpose for which you provide it. For example, we may disclose your personal information to your bariatric surgeon and bariatric care team;
  • for any other purpose disclosed by us when you provide the information with your consent.

We may also disclose your Personal Data:

  • to comply with any court order, law, or legal process, including to respond to any government or regulatory request;
  • to comply with applicable laws, including those requiring specific handling of health data under HIPAA, as well as other relevant U.S. and international data protection laws;
  • to facilitate patient data portability for clinic transitions with explicit consent provided in advance;
  • to enforce or apply our Terms of Service and other agreements, including for billing and collection purposes; and
  • if we believe disclosure is necessary or appropriate to protect the rights, property, or safety of Bariatric Centers of America, our customers, or others. This includes exchanging information with other companies and organizations for the purposes of fraud protection.

Your Rights and Choices About How We Use and Disclose Your Information

You can review and change your Personal Data by emailing us at care@bcofa.com and we will make any changes to any Personal Data we have about you to ensure that it is complete, accurate, and as current as possible. We cannot delete certain types of personal information (such as your email or name) except by also deleting your account within our system. We may also not be able to accommodate your request if we believe it would violate any law or legal requirement or our agreement with your bariatric provider.

We offer you choices on how you can opt-out of our use of tracking technology, disclosure of your Personal Data for our advertising to you, and other targeted advertising.

We do not control the collection and use of your information collected by third parties described above in Disclosure of Your Information. These third parties may aggregate the information they collect with information from their other customers for their own purposes.

In addition, we strive to provide you with choices regarding the Personal Data you provide to us. We have created mechanisms to provide you with control over your Personal Data:

  • Tracking Technologies and Advertising. You can set your browser or operating to refuse all or some cookies or to alert you when cookies are being sent. If you disable or refuse cookies, please note that some parts of our Website may then be inaccessible or not function properly
  • Promotional Offers from Bariatric Centers of America. If you do not wish to have your email address used by Bariatric Centers of America to promote our own products and services, you can opt-out at any time by clicking the unsubscribe link at the bottom of any email or other marketing communications you receive from us. This opt-out does not apply to information provided to Bariatric Centers of America as a result of a product purchase, or your use of our services.
  • BariLead Marketing Campaigns. You may opt out of AI-powered marketing communications from BariLead at any time by clicking unsubscribe in any email, replying STOP to any SMS, or contacting care@bcofa.com.
  • BariSuccess Biometric Data. If you wish to discontinue transmitting scale data to our system through the Withings integration, please contact your care team or email care@bcofa.com.
  • Targeted Advertising. To learn more about interest-based advertisements and your opt-out rights and options, visit the Digital Advertising Alliance and the Network Advertising Initiative websites (aboutads.info and www.networkadvertising.org ). Please note that if you choose to opt-out, you will continue to see ads, but they will not be based on your online activity. We do not control the third-party collection or use of your information to serve interest-based advertising. However, these third parties may provide you with ways to choose not to have your information collected or used in this way. You can also opt-out of receiving targeted ads from members of the NAI on its website.

Retention and Disposal of Records

For Patients

Patient data is retained for as long as the account is in active status. Data enters an “expired” state when the account is voluntarily closed by the patient. Expired account data will be retained for 30 days. After this period, the account and related data will be removed.

If a patient account is involuntarily suspended, then there is a 30-day grace period during which the account will be inaccessible but can be reopened if the patient meets their payment obligations and resolves any terms of service violations.

For Clients

Client’s patient data is retained for as long as their account is in active status. Data enters an “expired” state when the client’s account is voluntarily closed by the client. Expired account data will be retained for 45 days. After this period, the account and related data will be removed. A client that wishes to voluntarily close an account can download their data manually prior to closing the account. Bariatric Centers of America will notify the client of the status of their account prior to the 45 days so the client can retrieve all necessary data.

If a client account is involuntarily suspended, then there is a 30-day grace period during which the account will be inaccessible but can be reopened if the client meets their payment obligations and resolves any terms of service violations.

If a client wishes to manually back up their data in a suspended account, then they must ensure that their account is brought back to good standing so that the user interface will be available for their use. After 90 days, the suspended account will be closed, and the data will enter the “expired” state. It will be permanently removed 45 days thereafter (except when required by law to retain).

Withings and BariSuccess Data

Biometric data transmitted from a Withings-connected scale into our system is subject to the same retention schedule as other patient data described above. Data that resides on the Withings platform is governed by Withings’ own data retention policies; please refer to their privacy policy for details.

Data Quality and Security

We have implemented administrative, technical, and physical safeguards designed to protect against the risk of accidental, intentional, unlawful, or unauthorized access, alteration, destruction, disclosure, or misuse. We also require third-party service providers, including cloud storage vendors, AI platform providers, and remote monitoring integrations, to maintain security certifications such as SOC 2 Type II or ISO 27001.

We have taken steps and implemented administrative, technical, and physical safeguards designed to protect against the risk of accidental, intentional, unlawful, or unauthorized access, alteration, destruction, disclosure, or unauthorized  use or misuse. We also require third-party service providers, including cloud storage vendors, to maintain security certifications such as SOC 2 Type II or ISO 27001.

The Internet is not 100% secure and we cannot guarantee the security of information transmitted through the Internet; however all personal information is accessed and stored via a third-party cloud infrastructure. Where you have been given or you have chosen a password, it is your responsibility to keep this password confidential.

The sharing and disclosing of information via the internet is not completely secure. We strive to use best practices, maintaining compliance with governmental HIPAA regulations and other industry standard security measures and tools to protect your data. However, we cannot guarantee the security of Personal Information transmitted to, on, or through our systems. Any transmission of Personal Information is at your own risk. We are not responsible for the circumvention of any privacy settings or security measures contained on our Platform, in your operating system, or mobile device.

SMS Messaging Terms & Mobile Policy

By providing your mobile number, you agree to receive SMS messages from Bariatric Centers of America (BCA), including appointment updates, notifications, and responses to your inquiries. This messaging program may include appointment reminders, care-related notifications, and responses to inquiries, and message frequency may vary based on your interactions with us.

Message and data rates may apply. For assistance, reply HELP or contact us at support@bcofa.com. You may opt out of SMS messages at any time by replying STOP.

Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes, and all categories above exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. Carriers are not liable for any delayed or undelivered messages.

Changes to Our Privacy Policy

We monitor and review this Privacy Policy quarterly and may change this Privacy Policy at any time, which changes will be reflected on this page. If we make material changes to how we treat our users’ Personal Data, we will notify you by email to the email address specified in your account or through a notice on the Website’s home page. The date this Privacy Policy was last revised is identified at the top of the page. It is your obligation to ensure we have an up-to-date active and deliverable email address for you, and for periodically visiting our Website and reviewing this Privacy Policy to check for any changes.

Complaints and Contact Information

If you believe that your privacy rights have been violated, you should immediately contact us at care@bcofa.com. All complaints must be submitted in writing through our website or via email. We will not take action against you for filing a complaint. This privacy policy has been compiled to better serve those who are concerned with how their Personally Identifiable Information (PII) is being used online. PII, as described in US privacy law and information security, is information that can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context. Please be sure you have read our privacy policy carefully to get a clear understanding of how we collect, use, protect or otherwise handle your Personally Identifiable Information in accordance with our website.

How to Contact Us:

For general inquiries:

AttnInformation Security Officer
Bariatric Centers of America, LLC
2801 Washington Road, Suite 107 #290
Augusta, GA 30909

Email: care@bcofa.com

TAKE THE NEXT STEP
See if this is right for you.
Schedule a consult