Privacy and security notice
What this website collects, what it deliberately cannot do, and the law that governs the exchange it serves.
Federal law that applies
The data exchanged through the One Senior Care Trading Partner Exchange is protected health information. It is governed by the Health Insurance Portability and Accountability Act of 1996, its Privacy Rule at 45 CFR Part 160 and 45 CFR Part 164 Subparts A and E, and its Security Rule at 45 CFR Part 164 Subparts A and C, as amended by the Health Information Technology for Economic and Clinical Health Act (the HITECH Act), Public Law 111-5, Title XIII, and by the Breach Notification Rule at 45 CFR Part 164 Subpart D.
Disclosures are limited to the minimum information necessary for the stated purpose, as required by 45 CFR 164.502(b). Unauthorised access to, use of, or disclosure of protected health information carries civil penalties under 42 U.S.C. 1320d-5 and criminal penalties, including fines and imprisonment, under 42 U.S.C. 1320d-6. Documentation of who was granted access, on what basis and by whose approval is retained for six years in accordance with 45 CFR 164.316(b)(2).
What this website collects
- Your organisation name, your name, your work email address and your direct phone number.
- Whether a business associate agreement is signed -- recorded as context only, never used as a condition of anything.
- An SSH public key, its fingerprint, its type and its size.
- The public network addresses you connect from.
- The time and source address of a one-time private key download, if you use that option.
That is the complete list. There is no other field on any form here.
What this website cannot do
- It cannot accept a file. There is no file input, no drag-and-drop target and no image paste handler anywhere in it, and the software that would be needed to read a file upload is not installed. This is the single largest route by which patient data reaches a website by accident, and it is removed rather than restricted.
- It cannot create your SFTP account. This website holds no permission over the storage that carries the data. It records a request; a named person approves it and a separate, tightly restricted process acts on that approval.
- It cannot read any patient data. It has no access to any data file, in any direction, at any time.
- It cannot show you another organisation. There is no page here that lists trading partners, and no request that returns one.
- It runs no code in your browser. There is no JavaScript on this site, no analytics, no session recording and no error-reporting service. Nothing about your visit is sent to any third party, because there is no third party involved.
Storage and retention
Submissions relating to an approved account are retained for the life of the relationship plus six years, as the documentation of who was granted access and on what basis. Rejected or superseded submissions are retained for 90 days. A generated private key is held only until you download it, and is destroyed at that moment; if it is never collected it is purged. Passwords do not exist here, so none are stored.
Every connection, upload and download on the exchange itself is logged and attributable to an individual account. That logging is a Security Rule requirement and is not optional.
If you think something has gone wrong
Tell us immediately using the help form below, and phone if it is urgent. The cases that matter most: you believe your private key has been seen by someone else; you were told a key download had already happened when you had not downloaded it; or your SFTP client showed a host key fingerprint that did not match the two published on your account page.
Need help, or does something here not fit your situation?
Tell us what you need and a person will call you. Use this for anything this form refuses, including the case where your organisation cannot provide fixed network addresses. That is a conversation, not a dead end.