110 lines
4.7 KiB
Markdown
110 lines
4.7 KiB
Markdown
# Signal Privacy Policy
|
|
|
|
**Effective Date:** June 7, 2026
|
|
**Product:** Signal — Documentation Readiness Platform
|
|
**Operated by:** STTIL Solutions LLC
|
|
|
|
---
|
|
|
|
## Who We Are
|
|
|
|
STTIL Solutions LLC ("STTIL", "we", "us") operates Signal, a documentation readiness tool for DMEPOS suppliers. Signal helps supplier staff identify patients whose documentation may need attention before supplies are shipped or claims are submitted.
|
|
|
|
This Privacy Policy describes how Signal handles the data uploaded to our platform and what we do (and do not) store.
|
|
|
|
---
|
|
|
|
## What Data Signal Processes
|
|
|
|
When your staff uploads a CSV file to Signal, we process the following fields:
|
|
|
|
| Field | Purpose |
|
|
|---|---|
|
|
| Patient identifier (internal) | Your internal MRN or account number — used as a de-identified tracking key only |
|
|
| Device type | CGM device type (e.g., Dexcom G7, FreeStyle Libre 3) |
|
|
| Shipment date | Most recent supply ship date |
|
|
| Payer name | Insurance type (e.g., Medicare, Medicaid, Commercial) |
|
|
| Quantity shipped | Number of units in the shipment |
|
|
| Documentation status fields (if present) | SWO status, PA status, PECOS verification, diagnosis flag — if included in your CSV |
|
|
|
|
Signal produces a prioritized documentation worklist as output.
|
|
|
|
---
|
|
|
|
## What Signal Does NOT Store
|
|
|
|
Signal is designed to operate without storing protected health information (PHI). We never store:
|
|
|
|
- Patient names
|
|
- Social Security numbers
|
|
- Dates of birth
|
|
- Home addresses
|
|
- Phone numbers or email addresses
|
|
- Diagnosis codes (ICD codes)
|
|
- Clinical notes or records
|
|
|
|
The connection between a patient identifier and a real patient identity stays with your staff. STTIL never holds that crosswalk.
|
|
|
|
---
|
|
|
|
## How We Store What We Do Collect
|
|
|
|
Patient identifiers are **hashed using SHA-256** before storage. This means we store a cryptographic fingerprint of the identifier, not the identifier itself. The hash cannot be reversed to recover the original patient identifier.
|
|
|
|
All stored data is associated with your organization's account and is protected by row-level security (RLS) policies in our database. Your data is not accessible to other Signal customers.
|
|
|
|
All data in transit is encrypted via HTTPS (TLS 1.2 or higher). All data at rest is encrypted using AES-256.
|
|
|
|
---
|
|
|
|
## Who Can Access Your Data
|
|
|
|
**Your organization's staff:** Users in your Signal account can view the worklist and documentation status for your patients.
|
|
|
|
**STTIL Solutions staff:** STTIL engineers may access system logs and aggregated platform metrics for operational purposes. Access to customer data is restricted and logged.
|
|
|
|
**No third parties:** STTIL does not sell, rent, or share your organization's data with any third party for commercial purposes.
|
|
|
|
**Law enforcement / legal process:** STTIL may disclose data if required by law, regulation, or court order. We will notify you to the extent permitted by law before complying with any such request.
|
|
|
|
---
|
|
|
|
## Data Retention
|
|
|
|
Your uploaded CSV data and scored records are retained for the duration of your subscription plus 90 days. Upon termination of your subscription or pilot agreement, all data associated with your account will be deleted within 10 business days of your written request, and we will confirm deletion in writing.
|
|
|
|
Audit logs (records of actions taken on the platform) are retained for a minimum of 6 years, consistent with 45 CFR §164.530(j), for compliance purposes.
|
|
|
|
---
|
|
|
|
## Patient Outreach
|
|
|
|
**Signal does not contact patients.** All outreach and supply decisions remain with your staff. Signal surfaces documentation conditions — your team acts on them. All prescriber outreach flags go to the prescriber office, never to the patient.
|
|
|
|
---
|
|
|
|
## HIPAA
|
|
|
|
Signal processes de-identified operational data. The architecture is designed so that the data is not protected health information under HIPAA. A Business Associate Agreement (BAA) may not be required for your engagement with Signal. We encourage you to consult your own compliance advisors to determine whether a BAA is needed for your use case before uploading any data.
|
|
|
|
---
|
|
|
|
## Security Incidents
|
|
|
|
In the event of a security incident affecting your organization's data, STTIL Solutions will notify you within 72 hours of discovery, consistent with our incident response obligations. We will provide a description of the incident, the data affected, and the steps taken to address it.
|
|
|
|
---
|
|
|
|
## Contact
|
|
|
|
Questions about this Privacy Policy or your data:
|
|
|
|
**STTIL Solutions LLC**
|
|
Email: <kisasttil@gmail.com>
|
|
Web: signal.sttilsolutions.com
|
|
|
|
---
|
|
|
|
## Changes to This Policy
|
|
|
|
We may update this Privacy Policy from time to time. We will notify active customers of material changes by email. Continued use of Signal following notice of changes constitutes acceptance of the updated policy.
|