This notice covers the records a storefront and a managed service generate. Protected health information is treated separately, under the business associate agreement executed before anything is installed, and that distinction is drawn explicitly below rather than left to inference.
Fortify 24x7 operates MediSafe Networks and answers for the records described below. Anything on this page can be raised at support@medisafenetworks.com, and it reaches people who are able to do something about it.
What follows describes the ordinary business records a storefront and a managed service throw off. It is not the document that governs protected health information. Wherever the work touches protected health information, what binds us is the business associate agreement signed ahead of provisioning, read alongside the HIPAA Privacy and Security Rules.
The line matters in practice. We have no appetite for your patient records, we do not copy them into our systems for purposes of our own, and where a service unavoidably touches them it is that agreement rather than this page that decides what may happen next.
To run the preparations you bought. To take payment and hold the account records a business is required to hold. To answer what you write to us. To spot, look into and respond to security events across the estate you nominated. To satisfy legal and regulatory duties that fall on us.
Not one line of it is for sale. Nothing gets rented, traded or handed to an advertiser, and no part of it goes into a profile assembled for anybody else.
Every one of those is held by contract to the sole purpose its material was handed over for. Wherever protected health information enters the picture, a business associate arrangement is layered above that.
While an account exists, so do its account and billing records; afterwards they last for whichever stretch of years tax and company law set. Operational records generated by the preparations last for the retention written into your scope, which is agreed before provisioning. Enquiry threads last while they are still useful to supporting you. At the end of a retention period a record is deleted or aggregated beyond recovery.
Ask and you can have: a copy of your holdings here, a correction, a deletion where no duty compels us to keep something, an export in a portable shape, or an objection lodged against one specific use. Send it to support@medisafenetworks.com and we answer inside the window the applicable law sets, and sooner where we can.
Requests about patient records held inside your practice belong with your own privacy officer. Those are your records under your program, and we act on them only when you instruct us to.
Fortify 24x7 works from the United States and holds records there. Some vendor platforms process in other regions under their own contractual safeguards. Where you need the specifics for one platform we will put them in writing for you rather than leave you guessing.
Reaching a customer record requires a business reason and is limited to staff doing that work. Administrative access carries multi factor authentication. Records are encrypted while moving and while stored on the platforms we run. We sell these controls, so we expect to be asked to evidence them on ourselves, and we would rather be asked.
This counter serves organisations and is not aimed at children. We do not knowingly gather information from a child through this site. Records concerning minors held inside your practice fall under your own program and under any business associate agreement between us.
Substantive alterations reach this page carrying a new revision date, and a holder whose live account is affected hears from us directly on top of that. If a sentence on this page is unclear, or you want the detail underneath it, write to support@medisafenetworks.com and ask. A person will answer.