Cookie Policy
Cookie Policy
How HomeHealth TX Uses Cookies and Similar Technologies
Last Updated: January 28, 2026
Table of Contents
1. Introduction
HomeHealth TX ("we," "our," or "us") uses cookies and similar technologies on our website (www.homehealth-tx.ai) and web applications. This Cookie Policy explains what cookies are, how we use them, and your choices regarding their use.
This policy should be read in conjunction with our Privacy Policy and Terms of Service.
Healthcare Platform Notice: As a HIPAA-compliant healthcare platform, we use only essential and functional cookies necessary for secure operation. We do not use advertising, marketing, or tracking cookies.
2. What Are Cookies?
Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites work more efficiently, provide a better user experience, and give website owners information about how users interact with their sites.
2.1 Types of Cookies by Duration
- Session Cookies: Temporary cookies that are deleted when you close your browser. These are essential for our platform's security and HIPAA compliance.
- Persistent Cookies: Cookies that remain on your device for a specified period or until you delete them. We use these minimally and only for legitimate purposes.
2.2 Types of Cookies by Origin
- First-Party Cookies: Cookies set by HomeHealth TX directly.
- Third-Party Cookies: Cookies set by our trusted service providers (such as WorkOS for authentication).
3. Cookies We Use
HomeHealth TX uses a minimal set of cookies focused exclusively on security, authentication, and core functionality. We categorize our cookies as follows:
| Category | Purpose | Required |
|---|---|---|
| Essential | Authentication, session management, security | Yes |
| Functional | User preferences, language settings | No (but recommended) |
We do NOT use:
- Advertising or marketing cookies
- Social media tracking cookies
- Analytics cookies that identify individuals
- Cross-site tracking cookies
4. Essential Cookies
Essential cookies are strictly necessary for the operation of our platform. Without these cookies, services you have requested cannot be provided. These cookies do not require consent under most privacy laws, including GDPR, because they are necessary for the platform to function.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
session_id |
Maintains your authenticated session | 15 minutes (HIPAA requirement) | HomeHealth TX |
csrf_token |
Protects against cross-site request forgery attacks | Session | HomeHealth TX |
wos-session |
WorkOS authentication session | 15 minutes | WorkOS |
org_id |
Identifies your organization for multi-tenant access | Session | HomeHealth TX |
secure_flag |
Ensures HTTPS-only transmission | Session | HomeHealth TX |
4.1 Security Features
All essential cookies are configured with the following security attributes:
- HttpOnly: Cannot be accessed by JavaScript, preventing XSS attacks
- Secure: Only transmitted over HTTPS connections
- SameSite=Strict: Not sent with cross-site requests, preventing CSRF attacks
- Domain-restricted: Only sent to homehealth-tx.ai and subdomains
5. Functional Cookies
Functional cookies allow us to remember choices you make and provide enhanced, personalized features. While not strictly necessary, they improve your experience.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
theme_preference |
Remembers your light/dark mode preference | 1 year | HomeHealth TX |
timezone |
Stores your timezone for accurate time display | 1 year | HomeHealth TX |
sidebar_state |
Remembers sidebar expanded/collapsed state | 30 days | HomeHealth TX |
6. Third-Party Cookies
We use a limited number of third-party services that may set cookies. All third-party providers are carefully vetted and, where they handle PHI, have signed HIPAA Business Associate Agreements.
6.1 WorkOS (Authentication)
WorkOS provides our enterprise authentication, including single sign-on (SSO) and multi-factor authentication. WorkOS may set cookies for:
- Session management
- Authentication state
- MFA verification status
Learn more: WorkOS Privacy Policy
6.2 Microsoft Azure (Hosting)
Our platform is hosted on Microsoft Azure, which may use cookies for load balancing and security. These are essential infrastructure cookies.
7. HIPAA and Healthcare Compliance
As a HIPAA-covered platform, our cookie practices are designed with healthcare compliance in mind:
7.1 Session Timeout
HIPAA requires automatic session termination after periods of inactivity. Our session cookies enforce a 15-minute timeout with a 2-minute warning notification before automatic logout.
7.2 No PHI in Cookies
We never store Protected Health Information (PHI) in cookies. Cookies contain only:
- Session identifiers (random tokens)
- Security tokens
- User preferences (non-PHI)
7.3 Audit Logging
Session cookie usage is logged for security and compliance purposes. Audit logs are retained for 6 years as required by HIPAA.
7.4 Secure Deletion
When you log out, all session cookies are securely invalidated on both the client and server side to ensure complete session termination.
8. Managing Your Cookie Preferences
8.1 Essential Cookies
Essential cookies cannot be disabled as they are required for the platform to function. If you block these cookies, you will not be able to access the platform.
8.2 Browser Settings
You can control cookies through your browser settings. Most browsers allow you to:
- View cookies stored on your device
- Delete some or all cookies
- Block third-party cookies
- Block all cookies (note: this will prevent platform access)
Instructions for common browsers:
- Chrome: Settings > Privacy and security > Cookies
- Firefox: Settings > Privacy & Security > Cookies
- Safari: Preferences > Privacy > Cookies
- Edge: Settings > Cookies and site permissions
8.3 Clearing Cookies
If you clear your cookies, you will be logged out of the platform and will need to log in again. Your preferences (such as theme settings) may be reset.
9. Mobile Applications
Our mobile applications (Caregiver and Family apps) do not use browser cookies. Instead, they use:
9.1 Secure Token Storage
- iOS: Keychain Services with AES-256 encryption
- Android: Android Keystore with hardware-backed security
9.2 Session Management
Mobile apps implement the same 15-minute session timeout as the web platform, using secure token refresh mechanisms.
9.3 Biometric Authentication
If enabled, biometric data (Face ID/fingerprint) is handled by the device operating system and never transmitted to our servers.
10. Updates to This Policy
We may update this Cookie Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons.
When we make changes:
- We will update the "Last Updated" date at the top of this policy
- Material changes will be communicated via email or in-app notification
- Previous versions will be archived and available upon request
11. Contact Us
If you have questions about our use of cookies or this Cookie Policy, please contact us:
HomeHealth TX
Website: https://www.homehealth-tx.ai
For Privacy and Cookie Questions:
Email: privacy@homehealth-tx.ai
For Technical Support:
Email: support@homehealth-tx.ai
Last Reviewed: January 28, 2026
Version: 1.0
Document ID: HHX-COOKIE-2026-001
Related Policies:
For the most current version of this Cookie Policy, visit: https://www.homehealth-tx.ai/cookie-policy