Privacy Policy

Effective Date: January 1, 2024
Last Updated: January 1, 2024

1. Introduction

Steracare ("we," "our," or "us") is committed to protecting your privacy and personal health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our home health care management platform and services.

This policy complies with the Health Insurance Portability and Accountability Act (HIPAA) and other applicable federal and state privacy laws.

2. Information We Collect

2.1 Protected Health Information (PHI)

  • Patient demographics (name, address, date of birth, Social Security number)
  • Medical history and diagnoses
  • Treatment plans and care coordination records
  • Medication lists and administration records
  • Insurance information and billing records
  • Caregiver assignments and visit records
  • Electronic visit verification (EVV) data

2.2 User Account Information

  • Email addresses and login credentials
  • Role-based access permissions
  • Activity logs and audit trails
  • Communication preferences

2.3 Technical Information

  • IP addresses and device identifiers
  • Browser type and version
  • Operating system information
  • Usage analytics and performance metrics
  • Cookies and similar tracking technologies

3. How We Use Your Information

3.1 Treatment, Payment, and Healthcare Operations (TPO)

  • Coordinating patient care and treatment plans
  • Processing insurance claims and payments
  • Managing caregiver schedules and assignments
  • Conducting quality assurance and improvement activities
  • Ensuring compliance with regulatory requirements

3.2 Platform Operations

  • Providing and maintaining our services
  • Authenticating user access and permissions
  • Generating reports and analytics
  • Improving system performance and functionality
  • Preventing fraud and ensuring security

4. Information Sharing and Disclosure

4.1 Authorized Disclosures

We may share your PHI with the following entities for treatment, payment, and healthcare operations:

  • Healthcare providers involved in your care
  • Insurance companies and payers for billing purposes
  • State agencies for EVV compliance and reporting
  • Business associates under HIPAA-compliant agreements
  • Legal authorities when required by law

4.2 Business Associates

We work with trusted business associates who help us provide our services. All business associates are bound by HIPAA-compliant agreements that require them to protect your information.

4.3 Legal Requirements

We may disclose your information when required by law, including:

  • Court orders and subpoenas
  • Public health reporting requirements
  • Law enforcement investigations
  • Regulatory compliance and audits

5. Data Security

We implement comprehensive security measures to protect your information:

  • Encryption of data in transit and at rest
  • Multi-factor authentication for user access
  • Regular security audits and vulnerability assessments
  • Role-based access controls and permissions
  • Secure data backup and disaster recovery procedures
  • Employee training on privacy and security practices

6. Your Rights

Under HIPAA, you have the following rights regarding your PHI:

  • Right to Access: Request copies of your health records
  • Right to Amend: Request corrections to your health information
  • Right to Restrict: Request limitations on how we use or disclose your information
  • Right to Confidential Communication: Request alternative communication methods
  • Right to Accounting: Request a list of disclosures we have made
  • Right to Complain: File complaints with us or the Department of Health and Human Services

7. Cookies and Tracking

We use cookies and similar technologies to enhance your experience and analyze platform usage. You can control cookie settings through your browser preferences.

For detailed information about our use of cookies, please see our Cookie Policy.

8. Data Retention

We retain your information for as long as necessary to provide our services and comply with legal requirements. Health records are typically retained for a minimum of 6 years from the last date of service, as required by law.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on our website and updating the "Last Updated" date.

10. Contact Information

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:

Steracare Privacy Officer
Email: privacy@steracare.com
Phone: (207) 555-0123
Address: 123 Healthcare Drive, Portland, ME 04101

This Privacy Policy is effective as of January 1, 2024, and complies with HIPAA, state privacy laws, and other applicable regulations.