Privacy Policy
Privacy Policy
HomeHealth TX Caregiver Mobile Application
Last Updated: December 23, 2025
Table of Contents
- 1. Introduction
- 2. HIPAA Compliance
- 3. Information We Collect
- 4. How We Use Your Information
- 5. Data Security Measures
- 6. Data Retention and Deletion
- 7. Third-Party Services and Business Associates
- 8. Your Privacy Rights
- 9. Data Sharing and Disclosure
- 10. Mobile Application-Specific Privacy Practices
- 11. California Privacy Rights (CCPA/CPRA)
- 12. International Data Transfers
- 13. Children's Privacy
- 14. Changes to This Privacy Policy
- 15. Contact Information
- 16. Legal Basis for Processing (HIPAA)
- 17. Data Processing Addendum
- 18. Effective Date and Acknowledgment
1. Introduction
HomeHealth TX ("we," "our," or "us") provides a HIPAA-compliant mobile application designed for caregivers employed by home health agencies to document patient care, track visits, and communicate with care teams. This Privacy Policy explains how we collect, use, disclose, and safeguard Protected Health Information (PHI) and other personal information when you use the HomeHealth TX Caregiver mobile application (the "App").
This Privacy Policy applies to all users of the App, including caregivers, clinical staff, and administrators of home health agencies that have contracted with HomeHealth TX.
By using the App, you acknowledge that you have read and understood this Privacy Policy and agree to be bound by its terms. If you do not agree with this Privacy Policy, you should not use the App.
2. HIPAA Compliance
HomeHealth TX is a HIPAA-covered entity and complies with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), including the Privacy Rule (45 CFR Part 160 and Part 164, Subparts A and E) and the Security Rule (45 CFR Part 164, Subparts A and C).
We maintain appropriate administrative, technical, and physical safeguards to protect PHI from unauthorized access, use, or disclosure. Our HIPAA compliance program includes:
- Business Associate Agreements with all third-party service providers who handle PHI
- Comprehensive security risk assessments conducted annually
- Documented policies and procedures for PHI handling
- Workforce training on HIPAA requirements
- Incident response procedures for potential breaches
- Audit controls and monitoring of PHI access
3. Information We Collect
3.1 Patient Health Information (Protected Health Information)
The App collects and processes PHI as necessary for treatment, payment, and healthcare operations. Types of PHI collected include:
- Patient Identifiers: Names, dates of birth, addresses, phone numbers, Social Security numbers (when required for billing)
- Medical Information: Diagnoses, medications, allergies, clinical assessments (including OASIS assessments), vital signs, care plans, physician orders
- Visit Documentation: Services provided, visit notes, time tracking data, clinical observations
- Financial Information: Insurance details, billing codes, payment information related to services rendered
- Emergency Contacts: Family member and emergency contact information
3.2 Location Data
The App collects precise geolocation data during home visits to:
- Verify caregiver arrival and departure times at patient residences
- Generate timestamps for visit documentation
- Support mileage reimbursement calculations
- Comply with payer requirements for visit verification
Location data is collected only when you have granted location permissions to the App and are actively clocked in for a scheduled visit. You may disable location permissions in your device settings, but this will prevent you from using visit documentation features that require location verification.
3.3 Photos and Visual Documentation
The App allows you to capture photos as part of visit documentation, including wound care documentation, home safety assessments, medication verification, and visual evidence of care provided. All photos captured through the App are encrypted immediately upon capture, associated with the specific patient visit, transmitted securely to our encrypted database, and subject to the same PHI protections as other health information.
3.4 Caregiver Account Information
We collect information about caregivers to manage access and ensure proper authentication:
- Professional Information: Name, professional license numbers, certifications, employment status
- Authentication Data: Email address, phone number (for multi-factor authentication), encrypted password
- Role and Permissions: Job title, access level, assigned patients
- Employment Records: Hire date, agency affiliation, training completion status
3.5 Biometric Authentication Data
The App supports biometric authentication (Face ID on iOS, fingerprint on Android) for secure access. Biometric templates are stored only on your device using iOS Keychain or Android Keystore. We do not have access to your actual biometric data. The operating system handles biometric verification and returns only a success/failure result to the App.
3.6 Device and Technical Information
We automatically collect certain technical information to maintain security and improve App performance, including device type, operating system version, unique device identifiers, app version, IP addresses, session identifiers, error logs, network information, battery level, and device orientation. This technical information is used solely for security monitoring, troubleshooting, and service improvement.
4. How We Use Your Information
4.1 Treatment Purposes
We use PHI to support the delivery of patient care, including displaying patient care plans, medications, and physician orders to caregivers, recording visit notes and clinical observations, facilitating communication between caregivers and clinical supervisors, alerting care team members to changes in patient condition, and supporting clinical decision-making through access to patient history.
4.2 Payment and Billing
We process PHI for billing and reimbursement purposes, including generating billing records for services provided, submitting claims to Medicare, Medicaid, and private insurers, verifying insurance eligibility and coverage, processing payments and managing accounts receivable, and supporting audits and recoupment investigations.
4.3 Healthcare Operations
We use PHI for legitimate healthcare operations, including quality assurance and performance improvement activities, regulatory compliance (including OASIS submissions to CMS), training caregivers and evaluating their performance, managing credentials and licenses, conducting internal audits and security monitoring, and business planning and development.
4.4 Legal and Regulatory Requirements
We may use and disclose PHI as required by law, including compliance with court orders and subpoenas, reporting to public health authorities, reporting suspected abuse or neglect to appropriate authorities, cooperation with law enforcement in specific circumstances defined by HIPAA, and workers' compensation claims processing.
5. Data Security Measures
We implement comprehensive security controls to protect PHI from unauthorized access, use, or disclosure in compliance with the HIPAA Security Rule (45 CFR §164.312).
5.1 Encryption
Data at Rest Encryption
- Database Encryption: Azure PostgreSQL Transparent Data Encryption (TDE) with AES-256
- Mobile Device Storage: iOS AES-256 encryption via iOS Data Protection, Android AES-256 encryption via Android Keystore
- File Storage: Azure Blob Storage with server-side encryption (SSE)
Data in Transit Encryption
- TLS 1.3: All API communications use TLS 1.3 with perfect forward secrecy
- Certificate Pinning: Prevents man-in-the-middle attacks
- HSTS: HTTP Strict Transport Security enforced
5.2 Authentication and Access Controls
Multi-Factor Authentication (MFA)
We require MFA using WorkOS AuthKit for enterprise-grade authentication. Authentication factors include passwords (minimum 12 characters with complexity requirements), mobile device with authenticator app or SMS code, and optional biometric authentication (Face ID/fingerprint).
Session Management
- Session Timeout: 15 minutes of inactivity (HIPAA requirement)
- Warning Notification: 2-minute warning at 13-minute mark with countdown timer
- Automatic Logout: At 15 minutes with queued uploads for next login
5.3 Audit Logging
We maintain comprehensive audit logs to track all PHI access and system activity. Logged events include authentication events, PHI access events, administrative actions, and mobile-specific events. Audit logs are retained for 6 years minimum (HIPAA requirement), are immutable (write-once, cannot be modified or deleted), and use cryptographic integrity (SHA-256 hash chain prevents tampering).
5.4 Backup and Disaster Recovery
We perform automated backups including daily full backups at 2:00 AM UTC, differential backups every 6 hours, and transaction log backups every 15 minutes. All backups are encrypted with AES-256 using separate keys. We maintain geographic redundancy with primary region in Azure South Central US (Texas) and secondary region in Azure East US (Virginia).
6. Data Retention and Deletion
6.1 Retention Periods
We retain data according to the following schedules:
- Patient Medical Records: 6 years from date of service (HIPAA requirement)
- Audit Logs: 6 years from creation date
- Billing Records: 7 years from final claim payment (Medicare requirement)
- Caregiver Employment Records: 3 years after employment termination
- Technical Logs: 90 days (unless involved in security incident)
6.2 Secure Deletion
When data retention periods expire, PHI is permanently deleted using secure deletion methods, encrypted database records are overwritten using cryptographic erasure, backup copies are purged according to backup rotation schedules, and deletion is logged in audit trails for compliance verification.
7. Third-Party Services and Business Associates
We share PHI with carefully vetted third-party service providers who assist with our operations. All third parties handling PHI sign HIPAA Business Associate Agreements.
7.1 Authentication Services
WorkOS (WorkOS, Inc.) - Purpose: Multi-factor authentication, single sign-on, identity management. Data Shared: Email addresses, authentication tokens, login timestamps. Location: United States. BAA Status: Executed.
7.2 Cloud Hosting
Microsoft Azure (Microsoft Corporation) - Purpose: Database hosting (Azure PostgreSQL), application hosting (Azure Container Apps), file storage. Data Shared: All PHI stored in application database. Location: United States (South Central US region). BAA Status: Executed (Microsoft HIPAA BAA).
7.3 Mobile Application Services
- Expo (Expo, Inc.) - Purpose: Mobile app development platform, over-the-air updates, push notifications. Data Shared: Device identifiers, app version, update status, push notification tokens. BAA Status: Not required (no PHI transmitted).
- Sentry (Functional Software, Inc.) - Purpose: Error monitoring and crash reporting (de-identified only). Data Shared: Stack traces, device info, app version, error messages (PHI stripped). BAA Status: Not required (only de-identified technical data).
7.4 Business Associates We Do NOT Use
For transparency, we explicitly do not share PHI with social media platforms, advertising networks, data brokers or aggregators, consumer analytics services, third-party AI/ML training platforms, cloud storage services outside our HIPAA-compliant infrastructure, marketing automation platforms, or non-HIPAA-compliant CRM tools.
8. Your Privacy Rights
As a user and individual whose information we maintain, you have specific rights under HIPAA and applicable state laws.
8.1 Right to Access (45 CFR §164.524)
You have the right to inspect and obtain a copy of PHI we maintain about you, request copies in electronic format when feasible, and direct us to transmit PHI to a third party. Requests should be submitted in writing to privacy@homehealth-tx.ai. We will respond within 30 days (with one possible 30-day extension).
8.2 Right to Request Amendment (45 CFR §164.526)
You may request corrections to PHI you believe is inaccurate or incomplete. We will respond within 60 days (with one possible 30-day extension), accept or deny the request with written explanation, and if denied, allow you to submit a statement of disagreement.
8.3 Right to an Accounting of Disclosures (45 CFR §164.528)
You may request an accounting of PHI disclosures we have made, excluding disclosures for treatment, payment, and healthcare operations, disclosures you specifically authorized, disclosures to you or your personal representative, and disclosures for national security or intelligence purposes.
8.4 Right to Request Restrictions (45 CFR §164.522)
You may request restrictions on how we use or disclose your PHI. We are not required to agree to all restrictions, but if we agree, we will comply (except in emergencies). We must agree to restrictions on disclosures to health plans if the disclosure is for payment or healthcare operations and you have paid out-of-pocket in full for the service.
8.5 Right to Notification of Breach (45 CFR §164.404)
If a breach of your unsecured PHI occurs, we will notify you without unreasonable delay, but no later than 60 days after discovery, by first-class mail, or by email if you have agreed to electronic notice, including a description of the breach, types of information involved, steps you should take, and our investigation.
8.6 Right to File a Complaint
If you believe your privacy rights have been violated, you may file a complaint with us at privacy@homehealth-tx.ai or with the U.S. Department of Health and Human Services Office for Civil Rights at 1-877-696-6775 or online at https://www.hhs.gov/hipaa/filing-a-complaint/index.html. We will not retaliate against you for filing a complaint.
9. Data Sharing and Disclosure
9.1 Within Your Home Health Agency
PHI is shared among your agency's workforce members on a minimum necessary basis. Clinical supervisors can view documentation for patients they oversee, billing staff can access information needed for claims submission, administrators can view aggregated reports without individual patient identifiers, and quality assurance staff can audit visits for compliance.
9.2 With Other Healthcare Providers
With proper authorization or as permitted by HIPAA, we may share PHI with physicians who have ordered home health services, hospitals coordinating patient discharges, specialty care providers involved in the patient's treatment, and hospice agencies for continuity of care.
9.3 With Payers and Regulatory Agencies
We disclose PHI to Medicare and Medicaid for claims processing and OASIS data submission, private insurance companies for billing and eligibility verification, state health departments for regulatory compliance, and CMS for quality reporting programs.
9.4 Uses and Disclosures Requiring Authorization
We will not use or disclose PHI for marketing purposes, sale of PHI, psychotherapy notes (if applicable), or other uses not described in this Privacy Policy without your written authorization. You may revoke any authorization in writing at any time. Revocation does not affect disclosures already made in reliance on the authorization.
10. Mobile Application-Specific Privacy Practices
10.1 Device Permissions
The App requests various device permissions for specific purposes:
- Location Services: Required for Electronic Visit Verification (EVV) compliance with Medicare/Medicaid reimbursement requirements
- Camera: Required for wound care documentation, home safety assessments, medication verification
- Microphone: Optional for voice notes during patient visits
- Biometric Authentication: Optional for Face ID (iOS) or fingerprint (Android) login
- Calendar Access: Optional to add scheduled visits to device calendar
- Push Notifications: Recommended for visit reminders and session timeout warnings
10.2 Offline Access and Data Synchronization
The App supports offline functionality for caregivers working in areas with poor cellular coverage. Cached data is limited to patients assigned to your next 7 days of scheduled visits, encrypted with AES-256, and automatically synced when internet connection is restored. Cached data for past visits is removed after 48 hours.
10.3 Remote Wipe and Device Security
If your device is lost or stolen, report to your agency supervisor or IT department within 1 hour. Agency administrators can remotely invalidate your authentication tokens within 5 minutes. After 3 failed authentication attempts, cached data auto-deletes. Device encryption and passcode/biometric protection provide additional security layers.
10.4 App Updates and Security Patches
Non-critical bug fixes are delivered via Expo over-the-air (OTA) updates. Major features and critical security fixes require App Store/Google Play updates. Versions 3+ releases behind current version are blocked from accessing PHI with 30-day advance notice before version deprecation.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). However, note that HIPAA-covered information is exempt from CCPA.
For non-PHI personal information, California residents have rights to know what personal information is collected and how it is used, request deletion of personal information, opt out of the sale of personal information (we do not sell personal information), and non-discrimination for exercising privacy rights.
To exercise these rights for non-PHI information, contact privacy@homehealth-tx.ai.
12. International Data Transfers
The App and services are designed for use in the United States. All data is stored on servers located in the United States (Microsoft Azure South Central US region).
If you access the App from outside the United States, your data will be transferred to and processed in the United States. U.S. privacy laws may differ from those in your jurisdiction. By using the App, you consent to this data transfer.
We do not knowingly collect information from individuals in the European Economic Area (EEA) or United Kingdom. If you are located in the EEA or UK, you should not use this App.
13. Children's Privacy
The App is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you are under 18, you must not use the App or provide any information to us. If we learn that we have collected information from a child under 18, we will delete it promptly.
Note: The App may contain PHI about pediatric patients, but those patients are not users of the App themselves.
14. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or service offerings.
When we make changes, we will update the "Last Updated" date at the top of this policy. Material changes will be communicated through in-app notifications or email. Continued use of the App after changes constitutes acceptance of the updated policy. Previous versions will be archived and available upon request.
We recommend reviewing this Privacy Policy periodically to stay informed about our information practices.
15. Contact Information
Privacy Officer
HomeHealth TX
Email: privacy@homehealth-tx.ai
Website: https://www.homehealth-tx.ai/privacy
Phone: [To be added]
Mail: [Address to be added]
For Technical Support:
Email: support@homehealth-tx.ai
For Security Incidents:
Email: security@homehealth-tx.ai
Phone: [24/7 hotline to be added]
For HIPAA Compliance Questions:
Email: compliance@homehealth-tx.ai
16. Legal Basis for Processing (HIPAA)
Our legal basis for collecting and processing PHI is:
- Treatment, Payment, and Healthcare Operations: HIPAA permits covered entities to use and disclose PHI for these purposes without individual authorization (45 CFR §164.506)
- Legal Obligations: We process PHI to comply with federal and state laws, including Medicare Conditions of Participation, state home health licensing requirements, CMS OASIS reporting requirements, and fraud and abuse prevention laws
- Legitimate Interests: For non-PHI data, we process information based on legitimate business interests in maintaining App security, improving user experience, and conducting internal business analytics
- Consent: For uses not covered by HIPAA permissions, we obtain your written authorization before processing PHI
17. Data Processing Addendum (For Business Associates)
If your home health agency has engaged us as a business associate:
- We will use and disclose PHI only as permitted by our Business Associate Agreement
- We will not use or disclose PHI in ways that would violate HIPAA if done by your agency
- We will implement appropriate safeguards to protect PHI
- We will report any security incidents or breaches as required
- We will make PHI available for amendment and accounting of disclosures as required
- We will make our internal practices, books, and records available for HHS inspection
18. Effective Date and Acknowledgment
This Privacy Policy is effective as of December 23, 2025.
By using the HomeHealth TX Caregiver mobile application, you acknowledge that:
- You have read and understood this Privacy Policy
- You consent to the collection, use, and disclosure of information as described
- You understand your rights under HIPAA and applicable privacy laws
- You agree to comply with your agency's policies regarding PHI protection
- You will report any suspected privacy or security incidents immediately
If you do not agree to this Privacy Policy, you must discontinue use of the App and contact your supervisor.