Privacy Policy

image
image
image
image
image
image

Introduction

AIHCON is committed to safeguarding the privacy and security of our users' information on our TAPE-IT platform, a SaaS solution designed to streamline communication, referral management, and collaboration among healthcare providers in the United States. Our Privacy Policy provides a clear and transparent outline of how we collect, use, and protect user data, ensuring compliance with the Health Insurance Portability and Accountability Act (HIPAA). This policy is applicable to all users, including healthcare providers, patients, and other individuals interacting with the TAPE-IT platform. By using our platform, users acknowledge and agree to the terms and conditions stated in this Privacy Policy.

1.1. Purpose and Scope

At AIHCON, we prioritize the privacy and security of our users' information, especially when it comes to healthcare data. Our TAPE-IT platform is designed to facilitate seamless communication and referral management among healthcare providers in the United States. This Privacy Policy outlines the measures we take to ensure the protection of users' personal information and compliance with the Health Insurance Portability and Accountability Act (HIPAA).

The purpose of this Privacy Policy is to inform users about the types of information we collect, how we use and protect that information, and their rights and responsibilities concerning their data. This policy applies to all users, including healthcare providers, patients, and other parties who access and use the TAPE-IT platform.

1.2. Acceptance of Privacy Policy

By accessing and using the TAPE-IT platform, users agree to the terms and conditions set forth in this Privacy Policy. If you do not agree with any aspect of our policy, please discontinue using the platform immediately. We reserve the right to update or modify this Privacy Policy at any time, and it is the users' responsibility to review the policy periodically for any changes. Your continued use of the TAPE-IT platform following any modifications to the Privacy Policy constitutes your acceptance of those changes.

Information Collection and Usage

TAPE-IT collects and uses various types of information to deliver the best possible experience to our users and ensure the secure and efficient operation of our services. We strictly adhere to HIPAA regulations and handle all information with the utmost care and discretion. The following sections detail the types of information we collect and the purposes for which they are used.

2.1. Personal Information

Personal information refers to any data that can be used to identify an individual. This includes, but is not limited to, name, email address, phone number, mailing address, and professional credentials. We collect this information when users register for an account, update their profile, or participate in certain platform activities. During registration, we collect a minimal amount of personal information, specifically the user's email address and a chosen username. All other data related to our users, including personal and non-personal information, is securely protected within our platform, ensuring confidentiality and compliance with all applicable laws and regulations.

2.2. Non-Personal Information

Non-personal information is data that cannot be used to identify a specific individual. This type of information includes technical and usage data, such as browser type, device type, operating system, IP address, and other similar data. We use this information to analyze and optimize the performance of our platform and to identify trends and usage patterns that can help us improve the overall user experience.

2.3. Purpose of Information Collection

  • We collect and use personal and non-personal information for several purposes, including:
  • To provide and maintain our platform and services
  • To facilitate communication and collaboration between users
  • To improve the functionality, performance, and user experience of our platform
  • To ensure the security and integrity of our platform and services
  • To comply with legal and regulatory requirements, including HIPAA

Data Security and HIPAA Compliance

At AIHCON, we understand the critical importance of data security and privacy for our users on the TAPE-IT platform. Our commitment to protecting sensitive information is evident in our adherence to the Health Insurance Portability and Accountability Act (HIPAA) and the implementation of robust security measures and infrastructure. The following sections provide a comprehensive overview of our data security approach and our unwavering dedication to HIPAA compliance.

3.1. Security Measures and Encryption

To ensure the highest level of data protection, we utilize advanced security measures and encryption techniques. Our system employs a multi-layered encryption approach that combines AES-256, SHA-256, HASH, OpenSSL, and BASE-64 to secure all data, making it virtually impossible to compromise any Protected Health Information (PHI). Furthermore, we consistently monitor our platform for vulnerabilities, perform regular security assessments, and update our systems to address potential risks and stay ahead of emerging threats.

3.2. Hosting and Database Infrastructure

AIHCON's TAPE-IT platform is hosted on Amazon Web Services (AWS), a renowned cloud service provider recognized for its stringent security standards and reliable infrastructure. We leverage the Amazon Quantum Ledger Database (QLDB) for our database needs, which offers a secure, high-performance, and scalable solution to store and manage sensitive data. By partnering with AWS, we provide a stable, secure, and trustworthy environment for our users' data.

3.3. HIPAA Compliance Standards

Our platform is designed and operated to strictly comply with HIPAA regulations, which govern the management and handling of PHI in the United States. Our team is well-versed in HIPAA requirements and has implemented comprehensive policies, procedures, and technical safeguards to ensure compliance throughout our platform. To maintain our commitment to compliance, we conduct regular audits, assessments, and reviews, addressing any potential concerns and continuously improving our security posture.

3.4. Data Breach Notification Procedures

In the unlikely event of a data breach, AIHCON is committed to following all relevant data breach notification laws and HIPAA guidelines. We have established a robust procedure to promptly identify, contain, and mitigate the impact of any breach, while also ensuring timely notification to affected users and the appropriate authorities. Our proactive and transparent approach to data security minimizes the risk of breaches and guarantees the continued protection of our users' sensitive information.

User Consent and Privacy Rights

AIHCON's TAPE-IT platform is committed to upholding the privacy rights of our users and ensuring they have control over their personal information. By using our platform, users agree to the terms and conditions laid out in our Privacy Policy, including the collection and use of their data. The following sections detail the various aspects of user consent and privacy rights, as well as the actions users can take to maintain control over their information.

4.1. Consent to Information Collection and Usage

When users register for an account on the TAPE-IT platform, they provide consent for AIHCON to collect and use their personal information, as outlined in our Privacy Policy. This consent allows us to deliver our services, maintain a secure environment, and improve the overall user experience. Users have the right to withdraw their consent at any time, but doing so may impact their ability to access or use certain features of the platform.

4.2. Accessing and Updating Personal Information

Users have the right to access, review, and update their personal information on the TAPE-IT platform at any time. We encourage users to keep their information up-to-date to ensure accurate and efficient communication among healthcare providers. If users encounter any issues or require assistance in updating their information, they can contact our support team for guidance.

4.3. Opting Out of Communications

Users have the option to opt-out of receiving non-essential communications from AIHCON, such as promotional materials and newsletters. However, users cannot opt-out of receiving essential communications related to their account or the platform's operation, as these are necessary for providing our services. To opt-out of non-essential communications, users can follow the unsubscribe instructions provided in the relevant emails or contact our support team.

4.4. Data Portability

In accordance with HIPAA regulations, users have the right to request a copy of their personal information stored on the TAPE-IT platform. We will provide the requested data in a structured, commonly used, and machine-readable format, enabling users to transfer their information to another service provider if desired. To request data portability, users should contact our support team, who will assist with the process and ensure compliance with all applicable laws and regulations.

Third-Party Services and Integrations

AIHCON's TAPE-IT platform may interact with various third-party services and integrations to enhance the user experience, streamline processes, and facilitate seamless operation. While we ensure that these third-party services adhere to our high standards for security and privacy, it is important for users to understand the implications and responsibilities associated with using these services. The following sections provide a detailed overview of the different types of third-party services and integrations that users may encounter while using our platform.

5.1. Third-Party Service Providers

We may engage third-party service providers to perform specific functions on our behalf, such as data storage, analytics, or customer support. These providers are required to comply with our stringent security and privacy standards, as well as all applicable HIPAA regulations. We maintain strict oversight of these providers and monitor their adherence to our policies, ensuring the continued protection of our users' data.

5.2. Links to External Websites

Our platform may contain links to external websites for the convenience of our users. However, AIHCON is not responsible for the content, privacy practices, or security measures of these external sites. Users are encouraged to review the privacy policies and terms of use of any third-party websites they visit through links on our platform to understand their data handling practices.

5.3. Social Media Integrations

AIHCON's TAPE-IT platform may offer social media integrations, allowing users to interact with our platform through their social media accounts. While these integrations are designed to improve the user experience, users should be aware that their interactions with these social media platforms may be subject to the privacy policies and terms of use of the respective platforms. We encourage users to review the privacy settings and policies of their social media accounts to ensure their data is protected in accordance with their preferences.

5.4. Payment Processing

To facilitate secure and efficient payment processing, AIHCON has partnered with Stripe, a leading payment gateway provider. All payment-related information and transactions are handled by Stripe, and users are subject to their privacy policy and terms of service. AIHCON is not responsible for any issues that may arise during the payment process, and users are encouraged to review Stripe's policies to understand their rights and responsibilities when making payments through our platform.

Cookies and Tracking Technologies

AIHCON's TAPE-IT platform utilizes cookies and other tracking technologies to enhance the user experience, improve the platform's performance, and gather insights to better serve our users. While these technologies are essential to the smooth functioning of our platform, we are committed to maintaining user privacy and ensuring compliance with HIPAA regulations. The following sections offer an in-depth look at the cookies and tracking technologies used on our platform, their purposes, and how users can manage their preferences.

6.1. Types of Cookies Used

Our platform employs various types of cookies, including session cookies, which are temporary and expire when users close their browsers, and persistent cookies, which remain on users' devices until manually deleted or they reach their expiration date. We may also use first-party cookies, set by AIHCON, and third-party cookies, set by our partners and service providers, to deliver a seamless experience.

6.2. Purpose of Tracking Technologies

Tracking technologies, such as cookies, serve a range of purposes on our platform. They help us remember user preferences, enable essential features, facilitate secure authentication, and monitor platform performance. Additionally, these technologies allow us to gather insights about user behaviour, which we use to optimize our platform and deliver a better experience for our users.

6.3. Analytical Tools and Data Access Limitations

We may use analytical tools to monitor and analyze platform usage, generating reports that help us improve our services. These tools are not permitted to access or view any healthcare data, ensuring the continued privacy and security of our users' sensitive information. Furthermore, we maintain strict control over the access and handling of user data, in compliance with HIPAA regulations and our internal policies.

6.4. Managing Cookie Preferences

Users have the option to manage their cookie preferences and can choose to accept, decline, or delete cookies. Most browsers offer settings that allow users to control how cookies are stored on their devices. However, users should be aware that disabling or deleting cookies may impact the functionality and performance of our platform. To learn more about managing cookie preferences, users can consult their browser's help documentation or visit relevant online resources.

Data Retention, Deletion, and Disenrollment

AIHCON's TAPE-IT platform is committed to protecting user privacy and adhering to HIPAA regulations in all aspects of data retention, deletion, and disenrollment. Our policies are designed to ensure the secure handling and storage of user data while providing options for users to manage their information. The following sections detail our practices related to data retention, deletion, and the process of disenrollment from our platform.

7.1. Retention Period

We retain user data for the duration necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Our data retention periods are in accordance with HIPAA regulations and other applicable laws. Users can request the deletion of their data at any time, subject to certain limitations detailed in the following sections.

7.2. Deletion of Personal Information

Users have the right to request the deletion of their personal information stored on our platform. Upon receiving a deletion request, we will take all reasonable steps to delete the requested data, provided that the deletion does not conflict with any legal obligations, ongoing disputes, or other legitimate interests. Users should be aware that the deletion of certain information may affect their ability to use specific features of our platform.

7.3. Account Closure and Data Deletion

If a user decides to close their account on the TAPE-IT platform, we will delete their personal information and any associated data, as per HIPAA regulations and our internal policies. However, we may retain certain information to comply with legal obligations, resolve disputes, or enforce our agreements. Users should contact our support team for assistance with account closure and data deletion.

7.4. Data Storage after Disenrollment

In the event that a user disenrolls from the TAPE-IT platform, we will store their data for a period of 30 days. This retention period allows users and healthcare providers to access critical information if necessary. After the 30-day period, we will permanently delete the user's data from our servers, ensuring the continued protection of their privacy and adherence to HIPAA regulations.

International Data Transfers

AIHCON's TAPE-IT platform is designed to cater to healthcare providers within the United States. However, our platform may involve certain international data transfers in specific instances, such as when utilizing third-party service providers. In these cases, we are committed to ensuring the protection of user data and compliance with HIPAA regulations. The following sections detail our practices and policies related to international data transfers and the measures we take to safeguard user data.

8.1. Cross-Border Data Transfers

Though our primary focus is on the United States healthcare sector, certain aspects of our platform may necessitate cross-border data transfers. These transfers may occur when we engage with third-party service providers or as required by law. In such cases, we take all necessary precautions to ensure that the data being transferred is handled securely and in compliance with relevant regulations.

8.2. Data Protection in International Transfers

To maintain the security and privacy of user data during international transfers, we implement stringent measures that adhere to HIPAA regulations and other applicable data protection laws. We carefully assess the data protection policies and practices of our third-party service providers, ensuring they maintain compliance with our standards and the relevant legal requirements. Furthermore, we employ secure data transfer methods and technologies to minimize the risk of unauthorized access, disclosure, or alteration during transit. Our commitment to safeguarding user data remains paramount, regardless of where the data is transferred or processed.

Children's Privacy

AIHCON's TAPE-IT platform is committed to safeguarding the privacy of all users, including children, and ensuring compliance with HIPAA regulations and other applicable laws. Our policies are designed to protect the privacy of children and provide a secure environment for the collection and storage of their personal information. The following sections outline our approach to children's privacy, age restrictions, and the role of parental consent and control in our platform.

9.1. Age Restrictions

The TAPE-IT platform is intended for use by healthcare providers and other authorized users who are at least 18 years of age or older. We do not knowingly collect, store, or process personal information from children under the age of 18. In the event that we become aware of any personal information collected from a child under the age of 18, we will take appropriate steps to delete such information as quickly as possible and in accordance with applicable laws and regulations.

9.2. Parental Consent and Control

As our platform is not designed for users under the age of 18, we require that any personal information related to a child be provided by their parent or legal guardian. We encourage parents and guardians to be actively involved in their children's online activities and to monitor their use of our platform. In cases where personal information is collected for children under the age of 18, we seek the consent of their parents or legal guardians and provide them with the ability to control and manage their child's data. If a parent or guardian becomes aware that their child has provided personal information to our platform without their consent, they should contact us immediately so that we can take appropriate action to delete the information and ensure the child's privacy is protected.

Data Sharing and Disclosures

We understand the importance of maintaining the privacy and confidentiality of user data. However, in certain circumstances, we may be required to disclose personal information to comply with legal obligations, respond to government requests, or facilitate interactions with insurance companies and law firms. In all such instances, we adhere to HIPAA regulations and other applicable laws to ensure that user privacy remains protected. The following sections detail our policies and practices related to data sharing and disclosures under specific circumstances.

10.1. Legal Requirements and Government Requests

We may be required to disclose personal information in response to lawful requests from government authorities, such as subpoenas, court orders, or other legal processes. In these cases, we will only disclose the minimum amount of information necessary to comply with the request and will take all reasonable steps to protect the privacy of the affected users. We may also disclose personal information when necessary to protect our rights, investigate fraud, or respond to emergencies that we believe may pose a threat to the safety or security of our users or the public.

10.2. Insurance Companies

As a platform designed for healthcare providers, we may be required to share user data with insurance companies for purposes such as claim processing or verifying coverage. In these situations, we will share only the necessary information and will do so in compliance with HIPAA regulations and other applicable privacy laws. We are committed to ensuring that all data sharing with insurance companies is carried out securely and in a manner that respects user privacy.

10.3. Law Firms

There may be instances where we need to share personal information with law firms to comply with legal obligations or to protect our rights and interests. In such cases, we will share only the necessary information, taking care to adhere to HIPAA regulations and other relevant privacy laws. We will also require the law firms to maintain the confidentiality of the information shared and to use it solely for the purposes for which it was provided. Our commitment to user privacy remains paramount, even when sharing information with law firms under these specific circumstances.

User Responsibilities and Liability

We are dedicated to ensuring the security and privacy of user data. While we implement robust security measures to protect your information, users also play a critical role in maintaining the security of the platform. It is essential for users to understand their responsibilities and potential liabilities related to data security. The following sections outline user responsibilities, the importance of reporting security vulnerabilities, and the consequences of engaging in prohibited activities.

11.1. User's Role in Data Security

Users are responsible for maintaining the confidentiality of their account credentials and ensuring that their devices are secure. It is crucial to use strong, unique passwords and to update them regularly. Users should also enable multi-factor authentication when available and be vigilant in guarding against phishing attempts or other unauthorized access to their accounts. By adhering to best practices in data security, users can help protect their information and contribute to the overall security of the TAPE-IT platform.

11.2. Reporting Security Vulnerabilities

If a user discovers a security vulnerability or a potential data breach within the TAPE-IT platform, they are responsible for reporting the issue to us immediately. Prompt reporting allows us to investigate the issue and take appropriate action to address the vulnerability and safeguard user data. Users should not exploit the vulnerability or share information about the issue with others, as this may lead to further security risks.

11.3. Prohibited Activities and Penalties

Users are strictly prohibited from engaging in activities that compromise the security of the TAPE-IT platform or the privacy of other users. This includes, but is not limited to, attempting unauthorized access to user accounts, exploiting security vulnerabilities, or introducing malicious code into the platform. Users found to be engaging in such activities may face penalties, including account suspension, legal action, or other consequences as deemed appropriate. Our priority is to maintain a secure environment for all users, and we will take necessary action against those who jeopardize the platform's security.

AI Data Collection and Usage

AIHCON may implement artificial intelligence (AI) technologies within the Services to enhance user experience and improve the functionality of the Services. To facilitate this, our AI may collect non-personal data related to user behavior and patterns. Rest assured that no Protected Health Information (PHI) will be used in this process, as all PHI will be encrypted and secured using user credentials.

Changes to Our Privacy Policy

AIHCON's TAPE-IT platform is committed to remaining compliant with HIPAA regulations and other relevant privacy laws. As these regulations and the technology landscape evolve, we may need to update or revise our Privacy Policy to ensure continued compliance and alignment with best practices. The following sections describe our approach to updating the Privacy Policy and how we notify users of any changes to ensure transparency and maintain trust.

13.1. Updates and Revisions

We continually monitor changes in privacy regulations and industry best practices to ensure that our Privacy Policy remains current and compliant. As a result, we may periodically update or revise our Privacy Policy to reflect new requirements or advancements in technology. We are committed to maintaining a policy that is both comprehensive and easily understood, and we will ensure that any updates or revisions maintain these qualities.

13.2. Notification of Changes

When we make significant changes to our Privacy Policy, we will inform users by posting a notice on our platform and, if necessary, sending an email or other communication to affected users. We will provide ample notice before any changes take effect, giving users the opportunity to review the updated policy and make informed decisions about their continued use of the TAPE-IT platform. We encourage users to review our Privacy Policy regularly to stay informed of any changes and to ensure they understand their rights and responsibilities with respect to the protection of their personal information.

Contact Information for Privacy Concerns

AIHCON's TAPE-IT platform is dedicated to ensuring the privacy and security of our users' personal information, as well as compliance with HIPAA and other relevant privacy regulations. If you have any questions, concerns, or complaints about our Privacy Policy or our data handling practices, we encourage you to get in touch with us. The following sections provide contact information for our Privacy Officer and details about the regulatory authority responsible for overseeing privacy matters.

14.1. AIHCON's Privacy Officer Contact Details

To address any privacy concerns, inquiries, or to exercise your rights under this Privacy Policy, please reach out to our designated Privacy Officer. You can contact them using the following details:

Privacy Officer

AIHCON Inc.

New York, NY, United States

Email: [email protected]

Phone: +1 (347) 354 3546

Our Privacy Officer will respond to your inquiry in a timely and professional manner, addressing your concerns and providing any necessary assistance.

14.2. Regulatory Authority Information

If you believe that your privacy rights have been violated, or if you are unsatisfied with our response to your concerns, you may file a complaint with the appropriate regulatory authority responsible for overseeing privacy matters in your jurisdiction. For users in the United States, the regulatory authority is the U.S. Department of Health and Human Services (HHS). You can find more information about filing a complaint with HHS on their website at www.hhs.gov/hipaa/filing-a-complaint/index.html

Please note that contacting the regulatory authority should typically be a last resort after attempting to resolve your concerns directly with AIHCON's Privacy Officer. We are committed to addressing any privacy concerns you may have and will make every effort to resolve them to your satisfaction.