Legal
Privacy Policy
How AccessPro HealthCare collects, uses, and protects your information.
Effective: June 27, 2026
HIPAA Compliant
Section 01
Overview
AccessPro HealthCare LLC (“AccessPro”) operates a HIPAA-compliant EHR and home health agency management platform. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Platform.
HIPAA Notice
PHI handled through this Platform is governed by HIPAA (45 CFR Part 164) and our Business Associate Agreement (BAA). This Privacy Policy supplements but does not replace HIPAA requirements.
Section 03
Protected Health Information (PHI)
As a Business Associate under HIPAA, AccessPro handles PHI on behalf of Covered Entities. PHI is never sold or shared for marketing. Access is strictly controlled through role-based permissions and audit logging. All PHI transmission occurs over TLS 1.2+ encrypted connections.
Your agency retains ownership of and primary responsibility for all PHI entered into the Platform. AccessPro acts solely as a data processor on your behalf.
Section 04
How We Use Information
- Provide, operate, and maintain the Platform and all features
- Process and submit claims to Medicare, Medicaid, and commercial payers
- Send transactional communications including security alerts and invoices
- Monitor security, detect fraud, and prevent unauthorized access
- Comply with legal obligations including CMS reporting requirements
- Improve Platform performance using anonymized, aggregated data only
Section 05
Information Sharing & Disclosure
AccessPro does not sell your data. We share information only with:
- Service Providers: AWS, Stedi (EDI), Twilio (SMS), Amazon SES (email), PayPal (billing) — all under data processing agreements
- Payers & Clearinghouses: Claims transmitted as directed by your agency
- Legal Requirements: When required by law, subpoena, or regulatory authorities including CMS and OIG
- Business Transfers: In mergers or acquisitions, with HIPAA compliance maintained and users notified
Section 06
Data Security
- 256-bit AES encryption for all data stored in AWS RDS
- TLS 1.2+ for all data transmitted to and from the Platform
- Multi-factor authentication (TOTP) for administrative accounts
- Comprehensive audit logging of all PHI access with user, timestamp, and IP
- Automated backups with point-in-time recovery
- AWS CloudFront with WAF and DDoS protection
- Multi-tenant data isolation ensuring no cross-agency data access
In the event of a PHI breach, we will notify affected agencies within 60 days as required by the HIPAA Breach Notification Rule.
Section 07
Data Retention
- Active Account Data: Duration of subscription
- Clinical Records (PHI): Minimum 6 years per HIPAA
- Billing Records: 7 years per Medicare requirements
- Audit Logs: 6 years per HIPAA Security Rule
- Post-Termination: 30 days for data export, then permanent deletion
Section 08
Your Rights
- Access: Request a copy of information we hold about your account
- Correction: Request correction of inaccurate account information
- Deletion: Request deletion of your account and non-PHI data
- Data Export: Request an export of your agency data in standard format
- Opt-Out: Unsubscribe from non-transactional communications anytime
Patient PHI rights (access, amendment, accounting of disclosures) are governed by HIPAA and must be handled by your agency as the Covered Entity.
Section 09
Cookies & Tracking
- Authentication Tokens: JWT tokens in localStorage to maintain your session
- No Advertising Networks: We do not use tracking pixels or behavioral targeting
- No Third-Party Analytics: No Google Analytics or similar services on the clinical platform
The public marketing website may use anonymized analytics to measure page performance, not linked to individual users or PHI.
Section 10
Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email to active subscribers with a revised effective date. Continued use of the Platform constitutes acceptance. Changes affecting PHI handling will include BAA updates with advance notice as required by HIPAA.