One Senior Care Trading Partner Exchange

Privacy and security notice

What this website collects, what it deliberately cannot do, and the law that governs the exchange it serves.

Federal law that applies

The data exchanged through the One Senior Care Trading Partner Exchange is protected health information. It is governed by the Health Insurance Portability and Accountability Act of 1996, its Privacy Rule at 45 CFR Part 160 and 45 CFR Part 164 Subparts A and E, and its Security Rule at 45 CFR Part 164 Subparts A and C, as amended by the Health Information Technology for Economic and Clinical Health Act (the HITECH Act), Public Law 111-5, Title XIII, and by the Breach Notification Rule at 45 CFR Part 164 Subpart D.

Disclosures are limited to the minimum information necessary for the stated purpose, as required by 45 CFR 164.502(b). Unauthorised access to, use of, or disclosure of protected health information carries civil penalties under 42 U.S.C. 1320d-5 and criminal penalties, including fines and imprisonment, under 42 U.S.C. 1320d-6. Documentation of who was granted access, on what basis and by whose approval is retained for six years in accordance with 45 CFR 164.316(b)(2).

What this website collects

That is the complete list. There is no other field on any form here.

What this website cannot do

Storage and retention

Submissions relating to an approved account are retained for the life of the relationship plus six years, as the documentation of who was granted access and on what basis. Rejected or superseded submissions are retained for 90 days. A generated private key is held only until you download it, and is destroyed at that moment; if it is never collected it is purged. Passwords do not exist here, so none are stored.

Every connection, upload and download on the exchange itself is logged and attributable to an individual account. That logging is a Security Rule requirement and is not optional.

If you think something has gone wrong

Tell us immediately using the help form below, and phone if it is urgent. The cases that matter most: you believe your private key has been seen by someone else; you were told a key download had already happened when you had not downloaded it; or your SFTP client showed a host key fingerprint that did not match the two published on your account page.

Need help, or does something here not fit your situation?

Tell us what you need and a person will call you. Use this for anything this form refuses, including the case where your organisation cannot provide fixed network addresses. That is a conversation, not a dead end.

A direct line, not a switchboard. We call this number to verify your key fingerprint before anything is switched on.

Up to 200 characters. This box is deliberately small, so that it can never be somewhere participant data is pasted.