CVI Connect Privacy Policy
Effective date: August 24, 2026
CVI Connect (the “Portal”) is the online patient portal of Crown Valley Imaging (“CVI,” “we,” “us”). This policy explains, in plain language, what information the Portal handles when you use it to access your own imaging records, how that information is used and protected, and the choices and rights you have. It applies to connect.crownvalleyimaging.com and the services offered there.
1. This policy and our HIPAA Notice of Privacy Practices
CVI is a health care provider and a “covered entity” under the federal Health Insurance Portability and Accountability Act (HIPAA). How we use and disclose your protected health information (PHI) — including the imaging studies and reports you see in the Portal — is governed by our Notice of Privacy Practices (NPP), by HIPAA, and by the California Confidentiality of Medical Information Act (CMIA).
This Portal policy supplements the NPP; it never replaces or overrides it. If anything in this policy could be read to conflict with the NPP, HIPAA, or the CMIA with respect to PHI, the NPP and those laws control. You can request a copy of the NPP at any of our locations or by contacting us (Section 14).
Our other published policies remain in effect alongside this one:
- Notice of Privacy Practices — governs your medical record itself.
- Website Privacy Policy — covers crownvalleyimaging.com. That site uses analytics cookies with your consent; this Portal does not (Section 2).
- Financial Policy — governs billing and payment. Getting your own records through this Portal is free.
2. Information the portal collects
We collect only what the Portal needs to give you secure access to your own records:
- Account information. The email address you sign in with. Sign-in works by emailed one-time link; the Portal does not store a password for you.
- Identity-verification information. Before showing records we confirm you are who you say you are, using one of: a record-based quiz confirmed with a one-time code sent to the mobile number we already have on file, a clinic-issued access card, or review by our medical records staff. Your answers to record-based quiz questions are never stored in readable form — we record only whether verification passed or failed. We may in the future offer government-ID verification through a third-party identity processor; if we do, we will update this policy to describe exactly what data flows to that processor before we use it.
- Imaging and health information. The imaging studies, and in the future report documents and billing information, that you request through the Portal. This is PHI and is governed by the NPP (Section 1).
- Device and log information. Standard technical data such as IP address, browser type, timestamps, and the actions taken in your account. This is collected for security and for the audit records described in Section 5.
- Cookies. We use only the cookies and similar technologies necessary to keep you signed in and keep the Portal secure. We do not use advertising cookies, ad trackers, or third-party analytics.
3. How we use information
We use the information above to:
- provide the service — locating your imaging, showing it in the browser viewer, preparing downloads, and operating the sharing features you direct;
- verify identity and secure the Portal — preventing unauthorized access to records, detecting misuse, and investigating suspected security incidents;
- meet our audit and record-keeping obligations under HIPAA, the CMIA, and other applicable law;
- send transactional email — sign-in links, notices that your imaging is ready, and security notices. These emails contain minimal personal information (typically your first name and a link) and are never marketing.
4. When information is disclosed
- At your direction. When you download your imaging or create a shared link, you are directing a disclosure of your own records (see Section 8).
- Service providers. We use a small number of vendors to run the Portal, supporting functions such as cloud hosting, message delivery, and — when billing features launch — payment processing. Vendors that handle PHI do so under business associate agreements as required by HIPAA, and all vendors are limited to using information only to provide services to us.
- Legal requirements. We may disclose information when required by law — for example in response to a lawful subpoena, court order, or as otherwise permitted or required by HIPAA and the CMIA.
- What we never do. We do not sell your personal information or your medical information. We do not share it with advertisers or data brokers, and we do not use it for third-party advertising of any kind.
5. Audit logging
Every access to records through the Portal — viewing a study, downloading it, creating or using a shared link, and staff or system activity touching your records — is recorded in an audit log that identifies who accessed what, when, and under what authority. We keep these logs because the law requires it and because they protect you: they let us detect and investigate any access that should not have happened. Audit logs are retained for the period described in Section 12 and cannot be deleted on request during that period.
6. How we protect information
We use administrative, technical, and physical safeguards appropriate to medical information, including encryption of data in transit, role-based access controls, identity verification before any record access, single-use tokenized links for viewing and downloads, and the audit logging described above.
That said, no method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. If a breach of unsecured information affecting you occurs, we will notify you as required by HIPAA, the CMIA, and California’s breach notification laws.
7. Your security responsibilities
Because sign-in works through your email account, and because the Portal lets you take copies of your records, some security depends on you:
- Protect your email account. Anyone who can read your email can request a Portal sign-in link. Use a strong, unique password and two-factor authentication on your email, and tell us promptly if you believe your email or your Portal access has been compromised.
- Treat shared links like the records themselves. Send them only to people you intend to see your imaging.
- Downloaded copies are yours to protect. Once you download imaging (for example, a DICOM ZIP file) or a recipient obtains it through a link you shared, that copy is outside CVI’s systems and outside CVI’s control. We cannot secure, revoke, or delete copies that have left the Portal.
9. Text messages and your mobile number
If you ask us to text you a verification code, we send it to the mobile number already on your account. We use your mobile number only to confirm your identity and to support your use of the Portal.
We do not share, sell, or provide your mobile phone number or your text messaging consent data to third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. We do not send marketing or promotional text messages.
Message frequency. Messages are sent only when you request one — typically one message per verification attempt.
Message and data rates may apply. Crown Valley Imaging does not charge you for these messages; your mobile carrier's standard rates apply.
Reply STOP to any message to stop all texts from this program, or HELP for help. Stopping texts does not affect your access to your records. Full program details are on our text message program page and in Section 18 of our Terms of Use.
We share your number with our messaging provider (Twilio) solely to deliver the message you asked for. That is a service provider relationship, not a sale or a marketing disclosure.
10. Your California privacy rights
- Access to your records. California Health & Safety Code § 123110 and HIPAA (45 C.F.R. § 164.524) give you the right to inspect and receive copies of your medical records. The Portal exists to fulfill that right — electronically, at no charge to you. You may also request records in other formats through our front office.
- CMIA rights. The CMIA restricts how your medical information may be used and disclosed without your authorization, and gives you remedies if it is mishandled. Nothing in this policy limits your CMIA rights.
- CCPA/CPRA. Medical information governed by the CMIA, and PHI collected by a HIPAA covered entity, are generally exempt from the California Consumer Privacy Act (Cal. Civ. Code § 1798.145(c)). Because virtually all information the Portal handles is medical information held by a covered entity, the CCPA generally does not apply to it. If you believe we hold personal information about you that falls outside these exemptions, contact us (Section 14) and we will honor any applicable CCPA rights — including that we do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of.
11. Minors
Portal accounts are available only to individuals 18 or older, or to legally emancipated minors. Parents and legal guardians who need a minor’s records should contact our front office; those requests are reviewed by staff rather than self-served through the Portal. Records relating to care a minor may consent to on their own under California law (Cal. Fam. Code §§ 6920–6929, and similar protections) are never released through the Portal without individualized review, because a parent or guardian is not automatically entitled to them.
12. How long we keep information
- Medical records (including imaging) are retained according to California law, including Health & Safety Code § 123145, and our clinical retention policies. Deleting your Portal account does not delete your medical record — the medical record is maintained by CVI as your health care provider regardless of Portal use.
- Audit logs of record access are retained for at least 7 years.
- Account and technical data are kept as long as needed for the purposes in Section 3 and applicable legal requirements, then deleted or de-identified.
13. Changes to this policy
We may update this policy as the Portal, our practices, or the law change. The current version, with its effective date, will always be posted at this page. For material changes we will provide notice in the Portal or by email before the change takes effect. Your continued use of the Portal after the effective date of an updated policy means the update applies to you — though your rights over your PHI are always governed by the NPP and by law, not by this page.
14. Contact us
Questions about this policy, our privacy practices, or your records — or a privacy complaint — can be directed to:
Crown Valley Imaging — Privacy
Attn: Support
27401 Los Altos, Suite 150
Mission Viejo, CA 92691
Email: support@cvimaging.net
You also have the right to complain to the U.S. Department of Health and Human Services, Office for Civil Rights, and to the California Attorney General. We will never retaliate against you for raising a privacy concern.
See also the Terms of Use. Effective date: August 24, 2026
