Privacy Policy
1. Introduction
This Privacy Policy describes how Aurelianware and its Cloud Health Office platform ("we," "us," or "our") collect, use, disclose, and protect information when you use our EDI integration services for HIPAA-covered healthcare workflows ("Services").
Cloud Health Office is designed for healthcare organizations and supports deployments that may process Protected Health Information (PHI). PHI processing begins only under an applicable agreement, including a Business Associate Agreement (BAA) where required, and is subject to the controls and responsibilities defined for that deployment.
2. Information We Collect
2.1 Customer Account Information
When you create an account or purchase our Services, we collect:
- Organization name and contact information
- Administrator names and email addresses
- Billing information and payment details
- Azure subscription and tenant information
- Technical configuration preferences
2.2 Protected Health Information (PHI)
If a contracted deployment is authorized to process PHI, Aurelianware acts in the role defined by the applicable agreement, including as a Business Associate where required. Data processed may include:
- Patient/Member identifiers (name, date of birth, member ID)
- Provider information (NPI, names, addresses)
- Clinical information (diagnosis codes, procedure codes, dates of service)
- Claim and prior authorization data
- Attachment contents (medical records, supporting documentation)
2.3 Usage Data
We automatically collect certain information about how you interact with our Services:
- API call logs (without PHI content)
- Feature usage patterns
- Performance and error metrics
- Session duration and frequency
2.4 Technical Data
- IP addresses (for security and access control)
- Browser type and version
- Device information
- Azure resource identifiers
3. How We Use Information
3.1 Service Delivery
- Provision and operate the Cloud Health Office platform
- Process EDI transactions (X12 275, 277, 278, 837)
- Provide FHIR R4 API services
- Maintain and improve service performance
- Provide customer support
3.2 HIPAA-Regulated Uses
PHI is processed solely for:
- Treatment, Payment, and Healthcare Operations (TPO) activities as directed by Covered Entities
- Compliance with legal and regulatory requirements
- Purposes authorized by the applicable Business Associate Agreement (BAA)
3.3 Analytics and Improvement
We use aggregated, de-identified data to analyze usage patterns, develop new features, benchmark performance, and conduct research and development.
3.4 Communications
We may use your contact information to send service notifications, product updates, respond to support requests, and send marketing communications (with consent).
4. Information Sharing and Disclosure
We do not sell, rent, or trade Protected Health Information under any circumstances.
4.2 Service Providers and Subcontractors
We may share information with service providers that assist in operating our Services. Any subcontractor authorized to process PHI must be subject to written terms that provide the protections required by HIPAA and the applicable customer agreement.
4.3 Legal Requirements
We may disclose information when required by law, including HIPAA-permitted disclosures, government audit requests, or court orders.
4.4 Business Transfers
In the event of a merger, acquisition, or asset sale, customer information may be transferred to the acquiring entity, subject to continued compliance with this Privacy Policy and applicable BAAs.
5. HIPAA-Regulated Deployments
5.1 Business Associate Agreement
Before Aurelianware processes PHI as a Business Associate, we execute a BAA with the applicable Covered Entity or Business Associate. The BAA defines permitted uses and disclosures, safeguards, breach-notification obligations, subcontractor requirements, and termination and data-return or destruction procedures.
5.2 Administrative Safeguards
- Designated privacy and security contacts for the engagement
- Role-appropriate HIPAA training before workforce access to PHI
- Documented policies and procedures for PHI handling
- Workforce-access and policy-enforcement procedures
5.3 Physical Safeguards
- Physical datacenter controls provided by the selected cloud provider
- Workstation, device, and media controls appropriate to personnel with access
- Customer-controlled deployment boundaries where the platform runs in the customer's cloud
5.4 Reference Technical Safeguards
Cloud Health Office provides reference architecture and configuration for safeguards including the following. Their operation and effectiveness must be validated for each production deployment:
- Encryption at rest (AES-256) and in transit (TLS 1.2+)
- Access controls and authentication
- Audit logging and monitoring
- Automatic session termination
- Emergency access procedures
5.5 Breach Notification
- Notification timelines and responsibilities are defined in the applicable BAA and by law
- We cooperate with the contracting organization in investigation and mitigation
- Required breach documentation is retained for the legally applicable period
- Regulatory reporting responsibility is assigned in the applicable agreement
6. Data Retention
6.1 PHI Retention
PHI retention is governed by customer policy, the applicable BAA, and legal requirements. The reference infrastructure supports configurable retention from 1 to 10 years; a 7-year claims and EDI archive policy is available but is not imposed on every deployment.
6.2 Account Information
Customer account information is retained during an active engagement and afterward only for the period required by contract, legitimate business need, or applicable law.
6.3 Application and Audit Logs
- Application logs: Configurable by deployment and customer policy
- Audit logs: Configurable for the contractual and regulatory retention period
- Log sanitization: Control characters are stripped to mitigate log forging; PHI redaction applied within PHI-aware logging components
6.4 Data Deletion
Upon termination, PHI is returned or securely deleted according to the applicable BAA and customer-approved retention schedule. Backup expiration and required audit-record retention are documented for the deployment. De-identified, aggregated data may be retained where permitted by contract and law.
7. Data Security
7.1 Security Measures
The reference architecture supports the following controls. The final control set depends on the customer's cloud, configuration, operating model, and contract and must be validated before production use:
- Deployment on Microsoft Azure infrastructure, including services covered by Microsoft's published compliance scope where applicable
- Key Vault and HSM-backed key options
- Private-endpoint network-isolation patterns
- Role-Based Access Control (RBAC)
- Identity-provider multi-factor authentication options
- Automated dependency, secret, and code scanning in the public repository
7.2 Third-Party Certifications
Microsoft publishes compliance documentation for Azure services, including applicable SOC 2 and ISO 27001 coverage. Those certifications apply to Microsoft's audited environment and do not constitute an Aurelianware or Cloud Health Office certification. Current assurance documentation and deployment responsibilities are reviewed during a production engagement.
7.3 Incident Response
We maintain incident classification, escalation, investigation, customer-communication, and post-incident review procedures appropriate to the contracted service. Coverage hours, response targets, and notification obligations are defined in the applicable service agreement and BAA; 24/7 coverage is not implied unless expressly contracted.
8. Your Rights
8.1 HIPAA Individual Rights
When acting as a Business Associate under a BAA, we support the contracting organization in fulfilling applicable individual-rights obligations, including access, amendment, accounting of disclosures, restrictions, and confidential communications. Individuals should contact their health plan or provider to exercise these rights.
8.2 Customer Rights
- Access your account information
- Update or correct your information
- Request data export in standard formats
- Close your account (subject to retention requirements)
- Opt out of marketing communications
8.3 California Privacy Rights (CCPA/CPRA)
California residents have additional rights:
- Right to Know — what personal information is collected, used, shared, and sold
- Right to Delete — delete personal information (subject to legal exceptions)
- Right to Opt-Out — opt out of sale or sharing (we do not sell or share personal information)
- Right to Correct — correct inaccurate personal information
- Right to Limit Use — limit use and disclosure of sensitive personal information
- Right to Non-Discrimination — no discriminatory treatment for exercising rights
To exercise rights, email privacy@cloudhealthoffice.com with subject "CCPA/CPRA Request". We respond to verified requests within 45 days.
9. Children's Privacy
Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. PHI of minors is processed solely as directed by Covered Entities in accordance with applicable law.
10. International Data Transfers and GDPR
10.1 Data Location
The reference architecture supports customer-selected cloud regions. The actual storage, telemetry, backup, support-access, and transfer locations for a production deployment are documented during architecture review and in the applicable agreement.
10.2 European Union and GDPR
Where the GDPR applies, the customer and Aurelianware document their respective controller and processor roles, applicable legal bases, data-subject request procedures, and required processing terms. Depending on the activity, a legal basis may include:
- Contractual necessity — processing to perform contractual obligations
- Legitimate interests — fraud prevention, security
- Legal compliance — HIPAA, tax laws
- Consent — marketing communications
EU Resident Rights: Applicable rights may include access, rectification, erasure, restriction of processing, data portability, objection, and protections related to automated decision-making.
Data protection inquiries: privacy@cloudhealthoffice.com
10.3 Cross-Border Transfers
If a deployment requires a restricted cross-border transfer, the parties select and document an applicable transfer mechanism, such as European Commission Standard Contractual Clauses where appropriate, together with any required supplementary safeguards.
10.4 UK GDPR
Where UK GDPR applies, the parties document the applicable roles, processing terms, individual-rights procedures, and international-transfer mechanism for the engagement.
11. Cookies and Tracking Technologies
11.1 Use of Cookies
Essential storage: Authenticated product surfaces may use storage needed for session management, security, and service operation.
Analytics: The public marketing site currently loads Google Analytics and Plausible Analytics to measure traffic, campaign attribution, and product interest. Depending on browser and analytics configuration, these services may use cookies or similar identifiers.
Advertising: We do not currently operate a separate behavioral-advertising cookie network on the public marketing site.
11.2 Cookie Management
You can restrict cookies and similar storage through your browser settings or privacy extensions. Blocking analytics may reduce the usage information available to us but does not prevent access to the public site.
11.3 Do Not Track (DNT)
Browsers do not implement a uniform Do Not Track standard, and the current site does not alter analytics loading solely in response to the DNT signal. Browser-level blocking and privacy controls remain available.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on our website at cloudhealthoffice.com/legal/privacy-policy with the updated effective date. Material changes will be communicated to customers via email at least 30 days before the effective date.
Your continued use of the Services after changes become effective constitutes acceptance of the updated Policy.
13. Contact Information
| Role | Contact |
|---|---|
| Privacy Office | privacy@cloudhealthoffice.com |
| HIPAA Privacy Inquiries | hipaa-privacy@cloudhealthoffice.com |
| HIPAA Security Inquiries | hipaa-security@cloudhealthoffice.com |
| Data Protection Inquiries | privacy@cloudhealthoffice.com |
| General Support | support@cloudhealthoffice.com |
Appendix A: Summary of PHI Handling
| Category | Data Elements | Use | Retention |
|---|---|---|---|
| Member Data | Name, DOB, Member ID | EDI processing | Per BAA |
| Provider Data | NPI, Name, Address | EDI processing | Per BAA |
| Clinical Data | Dx/CPT codes, DOS | EDI processing | Per BAA |
| Claim Data | Claim #, Status | EDI processing | Per BAA and deployment policy |
| Attachments | Medical records | 275 processing | Per BAA and deployment policy |
Appendix B: Potential Third-Party Service Providers
Service-provider use varies by deployment. The definitive subprocessor list, permitted data, regions, and contractual safeguards are documented for each production engagement. PHI must not be sent to a provider unless that use is authorized by the applicable BAA and architecture review.
| Provider | Service | Expected PHI Use | Assurance Note |
|---|---|---|---|
| Microsoft Azure | Cloud infrastructure, messaging, and monitoring | Only within approved services and configuration | Microsoft's published compliance scope applies to Microsoft, not Aurelianware |
| Stripe, Inc. | Payment Processing | Not intended for PHI | Used only for configured commercial payment flows |
| SendGrid (Twilio) | Transactional Email | Not intended for PHI unless expressly approved | Use and content restrictions are deployment-specific |
| Google Analytics and Plausible Analytics | Public-site analytics | Not intended for PHI | Used for aggregate traffic, attribution, and engagement measurement |
| Formspree | Marketing-site lead forms | Not intended for PHI | Visitors are asked for business contact and evaluation information only |
| Proton | Discovery-call scheduling | Not intended for PHI | Visitors choose what information to provide when booking |
Subprocessor notice periods and objection rights are defined in the applicable customer agreement. Questions may be sent to privacy@cloudhealthoffice.com.