Signal/docs/compliance/privacy-policy.md

4.7 KiB

Signal Privacy Policy

Effective Date: June 7, 2026 Product: Signal — Documentation Readiness Platform Operated by: STTIL Solutions LLC


Who We Are

STTIL Solutions LLC ("STTIL", "we", "us") operates Signal, a documentation readiness tool for DMEPOS suppliers. Signal helps supplier staff identify patients whose documentation may need attention before supplies are shipped or claims are submitted.

This Privacy Policy describes how Signal handles the data uploaded to our platform and what we do (and do not) store.


What Data Signal Processes

When your staff uploads a CSV file to Signal, we process the following fields:

Field Purpose
Patient identifier (internal) Your internal MRN or account number — used as a de-identified tracking key only
Device type CGM device type (e.g., Dexcom G7, FreeStyle Libre 3)
Shipment date Most recent supply ship date
Payer name Insurance type (e.g., Medicare, Medicaid, Commercial)
Quantity shipped Number of units in the shipment
Documentation status fields (if present) SWO status, PA status, PECOS verification, diagnosis flag — if included in your CSV

Signal produces a prioritized documentation worklist as output.


What Signal Does NOT Store

Signal is designed to operate without storing protected health information (PHI). We never store:

  • Patient names
  • Social Security numbers
  • Dates of birth
  • Home addresses
  • Phone numbers or email addresses
  • Diagnosis codes (ICD codes)
  • Clinical notes or records

The connection between a patient identifier and a real patient identity stays with your staff. STTIL never holds that crosswalk.


How We Store What We Do Collect

Patient identifiers are hashed using SHA-256 before storage. This means we store a cryptographic fingerprint of the identifier, not the identifier itself. The hash cannot be reversed to recover the original patient identifier.

All stored data is associated with your organization's account and is protected by row-level security (RLS) policies in our database. Your data is not accessible to other Signal customers.

All data in transit is encrypted via HTTPS (TLS 1.2 or higher). All data at rest is encrypted using AES-256.


Who Can Access Your Data

Your organization's staff: Users in your Signal account can view the worklist and documentation status for your patients.

STTIL Solutions staff: STTIL engineers may access system logs and aggregated platform metrics for operational purposes. Access to customer data is restricted and logged.

No third parties: STTIL does not sell, rent, or share your organization's data with any third party for commercial purposes.

Law enforcement / legal process: STTIL may disclose data if required by law, regulation, or court order. We will notify you to the extent permitted by law before complying with any such request.


Data Retention

Your uploaded CSV data and scored records are retained for the duration of your subscription plus 90 days. Upon termination of your subscription or pilot agreement, all data associated with your account will be deleted within 10 business days of your written request, and we will confirm deletion in writing.

Audit logs (records of actions taken on the platform) are retained for a minimum of 6 years, consistent with 45 CFR §164.530(j), for compliance purposes.


Patient Outreach

Signal does not contact patients. All outreach and supply decisions remain with your staff. Signal surfaces documentation conditions — your team acts on them. All prescriber outreach flags go to the prescriber office, never to the patient.


HIPAA

Signal processes de-identified operational data. The architecture is designed so that the data is not protected health information under HIPAA. A Business Associate Agreement (BAA) may not be required for your engagement with Signal. We encourage you to consult your own compliance advisors to determine whether a BAA is needed for your use case before uploading any data.


Security Incidents

In the event of a security incident affecting your organization's data, STTIL Solutions will notify you within 72 hours of discovery, consistent with our incident response obligations. We will provide a description of the incident, the data affected, and the steps taken to address it.


Contact

Questions about this Privacy Policy or your data:

STTIL Solutions LLC Email: kisasttil@gmail.com Web: signal.sttilsolutions.com


Changes to This Policy

We may update this Privacy Policy from time to time. We will notify active customers of material changes by email. Continued use of Signal following notice of changes constitutes acceptance of the updated policy.