Privacy Policy
Last Updated: March 9, 2026 · Effective Date: March 9, 2026
HIPAA Notice: Vytier Health Technologies (“Vytier,” “we,” “our”) is committed to protecting your Protected Health Information (PHI) in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its subsequent amendments.
1. Information We Collect
1.1 Protected Health Information (PHI)
In the course of providing our Family Caregiving coordination platform, we may collect, process, and store the following categories of PHI:
- Patient demographic information (name, date of birth, contact details)
- Health conditions, diagnoses, and medical history
- Medication schedules, dosages, and administration records
- Vital signs and health metrics (blood pressure, heart rate, etc.)
- Care plans, treatment schedules, and caregiver notes
- Billing and insurance information
1.2 Personal Information
We also collect non-PHI personal information necessary for account creation and platform functionality:
- Name, email address, and phone number
- Account credentials (passwords are hashed and never stored in plaintext)
- Role designation (Patient, Caregiver, Guardian, or Well-Wisher)
- Device information and usage analytics
- Location data (for caregiver clock-in/clock-out verification only)
2. How We Use Your Information
Your information is used exclusively for the following purposes:
- Care Coordination: To facilitate communication, scheduling, and care tracking between authorized members of a care circle.
- Platform Operations: To maintain, improve, and secure the Vytier platform.
- Compliance: To meet legal obligations under HIPAA, state healthcare regulations, and applicable laws.
- Communication: To send service-related notifications, alerts, and updates you have opted into.
3. Data Security
3.1 Encryption Standards
All PHI is encrypted using AES-256 encryption both at rest and in transit. We use TLS 1.3 for all data transmissions and employ hardware security modules (HSMs) for cryptographic key management.
3.2 Access Controls
We implement role-based access controls (RBAC) ensuring that each user role (Patient, Caregiver, Guardian, Well-Wisher) can only access information appropriate to their designated level of authorization within a care circle.
3.3 SOC2 Type II Compliance
Vytier undergoes annual SOC2 Type II audits by independent third-party auditors, verifying our controls for security, availability, processing integrity, confidentiality, and privacy.
4. PHI Disclosure
We will never sell, rent, or trade your PHI. Disclosures are made only:
- To authorized members within your care circle, as configured by you
- To Business Associates under a signed Business Associate Agreement (BAA)
- As required by law, including court orders and regulatory investigations
- For public health activities as required by applicable law
- With your explicit written authorization
5. Data Retention
PHI is retained for the duration of your active account plus a period of 7 years following account closure, as required by federal and state record retention laws. Upon expiration of the retention period, all PHI is securely destroyed using NIST-approved methods.
6. Your Rights Under HIPAA
As a user of Vytier, you have the right to:
- Access: Request a copy of your PHI maintained by Vytier
- Amendment: Request corrections to inaccurate PHI
- Accounting of Disclosures: Receive a record of how your PHI has been shared
- Restriction: Request limitations on how your PHI is used or disclosed
- Confidential Communications: Request that we communicate with you through specific channels
- Breach Notification: Be notified within 60 days if your PHI is involved in a security breach
7. Breach Notification
In the event of a data breach involving unsecured PHI, Vytier will notify affected individuals within 60 calendar days of discovery, as required under the HITECH Act. Notifications will include a description of the breach, the types of information involved, steps taken to mitigate harm, and recommendations for affected individuals.
8. Children's Privacy
Vytier does not knowingly collect information from children under 13 without verifiable parental consent, in compliance with COPPA. For minor patients aged 13-17, a Guardian must authorize account creation and data processing.
9. Contact Us
For questions about this Privacy Policy, to exercise your HIPAA rights, or to report a privacy concern, please contact our Privacy Officer:
- Email: privacy@vytier.com
- Mail: Vytier Health Technologies, Privacy Office, [Address Placeholder]
- Phone: [Phone Number Placeholder]