Privacy Policy & HIPAA Disclosure
Last Updated: August 28, 2026 • Version 2.1
1. Privacy Commitment
At YourMedSoft ("YourMedSoft," "we," "us," or "our"), safeguarding your operational data, healthcare provider information, and Protected Health Information (PHI) is our primary responsibility. This Privacy Policy outlines how we collect, process, protect, and store information across our healthcare staffing SaaS platform.
2. HIPAA Compliance & Business Associate Agreement (BAA)
2.1 BAA Execution: YourMedSoft operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the HITECH Act. We execute formal Business Associate Agreements (BAAs) with all covered entities and staffing agency customers.
2.2 Technical Safeguards: All electronic Protected Health Information (ePHI) and sensitive clinician identity documents (licenses, TB test results, background checks, client home addresses) are protected by:
- 256-bit AES encryption at rest across all databases and file storage buckets.
- TLS 1.3 encryption in transit for all web traffic and API endpoints.
- Role-based access controls (RBAC) and strict multi-tenant Firestore security isolation.
- Immutable security audit logging tracking all record views, edits, and exports.
3. Information We Collect
3.1 Account Information: Name, professional email address, agency name, billing address, and payment credentials (processed securely via Stripe).
3.2 Staffing Records: Clinician contact details, professional licenses, specialty certifications, time and attendance punch records, and facility assignments.
3.3 Platform Usage & Logs: IP addresses, browser types, audit trail actions, and session timestamps used strictly for security monitoring and compliance verification.
4. Zero Data Selling Policy
YourMedSoft never sells, rents, monetizes, or shares customer data, clinician profiles, or patient visit records with third-party data brokers or advertising networks. Your data is used exclusively to deliver the platform services requested by your agency.
5. Data Retention & Deletion
We retain staffing records and compliance audit logs in accordance with statutory healthcare record retention requirements. Upon account termination, customers may request a complete data archive or certified cryptographic purge of their tenant organization records.
6. Contact Our Data Protection Officer
If you have questions regarding our privacy practices, security certifications, or wish to execute a BAA, please contact our Compliance & Security Team at privacy@yourmedsoft.com.