Privacy Policy

TRK Health, LLC · Effective Date: August 15, 2026

1. Introduction

TRK Health, LLC ("we," "us," or "our") operates the TRK Health platform. This Privacy Policy describes how we collect, use, and protect information in connection with the Platform. Because TRK Health serves licensed healthcare organizations, much of the information processed on the Platform constitutes protected health information (PHI) governed by HIPAA and our Business Associate Agreements with covered entities.

2. Information We Collect

We collect: (a) account information provided during onboarding (name, email, role, organization); (b) clinical data entered by authorized users or received from connected EMR systems, including patient records, episode and operation tracking, care documentation, and outcome measurements; (c) technical data including IP addresses, device identifiers, browser type, and usage logs for security and performance purposes.

3. How We Use Information

We use information solely to: (a) provide, maintain, and improve the Platform; (b) authenticate users and enforce role-based access controls; (c) send transactional communications such as password resets and care coordination notifications; (d) comply with legal obligations. We do not use PHI for marketing, advertising, or sale to third parties.

4. HIPAA and Protected Health Information

We operate as a Business Associate under HIPAA. PHI is processed only as directed by covered entity organizations under executed Business Associate Agreements. We implement administrative, physical, and technical safeguards consistent with the HIPAA Security Rule, including encrypted data transmission, access controls, and audit logging of PHI access.

5. Data Sharing

We do not sell personal information. We may share information with: (a) cloud infrastructure providers (Google Cloud Platform) under appropriate data processing agreements; (b) connected EMR systems that you authorize, solely to provide the integration you request; (c) email, messaging, or facsimile service providers for transactional communications; (d) law enforcement or regulatory authorities when required by law. All subprocessors are contractually bound to confidentiality and security obligations.

6. Text Message Communications

Where a patient has provided consent, the Platform may send text messages on behalf of a provider organization for care coordination purposes, such as confirming whether ordered imaging was completed or asking the patient to report how a treatment is going. Consent is recorded per patient and is not a condition of treatment. Patients may opt out at any time by replying STOP, and may request assistance by replying HELP. Message frequency varies; message and data rates may apply. Mobile opt-in data and consent status are not sold or shared with third parties for marketing purposes.

7. Data Retention

We retain account and clinical data for the duration of the organization's active subscription and for a period thereafter as required by applicable law or as specified in the Business Associate Agreement. Organizations may request deletion of their data upon contract termination.

8. Security

We employ industry-standard security measures including TLS encryption in transit, encrypted storage, private network database access, role-based access controls, application-level PHI access logging, and regular security reviews. No system is completely secure; in the event of a breach affecting PHI, we will notify affected organizations as required by HIPAA.

9. Children's Privacy

The Platform is not directed to or used by individuals under 18 as end users. Patient records managed on the Platform may include information about minors; such records are entered and managed exclusively by authorized personnel of the covered entity and are subject to HIPAA and applicable state-law protections.

10. Your Rights

Requests regarding access to, correction of, or deletion of personal information should be directed to your organization's administrator. For PHI-related requests, your organization as the covered entity is the appropriate first contact.

11. Changes to This Policy

We may update this Privacy Policy periodically. We will notify organizations of material changes. Continued use of the Platform following notice constitutes acceptance.

12. Contact

For privacy inquiries, contact us at info@trk-health.com.