Privacy & Data Protection

Privacy Policy

This Privacy Policy explains how Home Health Diary collects, uses, discloses, protects, and retains information across our website and software platform.

Overview and Scope

Integrated IT Solutions LLC, doing business as “Home Health Diary” (“Company,” “we,” “us,” or “our”), is committed to protecting the privacy of visitors and customers.

This Privacy Policy (“Policy”) describes how we collect, use, disclose, and safeguard information in connection with the homehealthdiary.com website and all related pages, content, and forms (“Website”), and the Home Health Diary software-as-a-service platform used by licensed Customer agencies and their authorized staff (“Platform”).

This Policy applies only to Home Health Diary's collection and use of information. It does not govern participant or patient privacy rights, which are the responsibility of Customer agencies as HIPAA Covered Entities.

Participants, patients, or family members seeking information about their personal health records should contact their service coordinator or healthcare provider directly.

Business Model

Home Health Diary is sold exclusively to licensed home care, service coordination, and Medicaid waiver agencies (“Customers”) on a B2B basis.

We do not market to, collect data from, or serve individual consumers directly, and we never sell personal data.

01

What We Collect

When you request a demo, quote, or contact us through the Website, we collect your name, business email, phone number, and agency name.

We also use cookies and Google Analytics or Google Tag Manager to understand website traffic, including IP address, browser information, and pages visited.

02

How We Use Information

  • To provide, secure, and support the Platform.
  • To respond to demo and contact requests.
  • To send service notifications and, with your consent, product updates.
  • To meet HIPAA audit-logging and Medicaid compliance requirements.
  • To improve the Platform using aggregated, de-identified data only.

AI Features: Our AI note-writing tools process participant context and session notes solely to assist your team's documentation inside the Platform.

PHI is never used to advertise, never sold, and never shared with third parties for their own AI training or marketing.

03

What We Never Do

  • We never sell, rent, or trade personal information or PHI.
  • We never use PHI for advertising or marketing.
  • We never share your contact details with third parties for their marketing.
04

Who We Share With

We share information only with trusted service providers that help us operate our services, including cloud hosting, email and CRM services, analytics, and support tools.

Our cloud hosting uses AWS with U.S.-based servers. Service providers operate under strict confidentiality agreements, and vendors that access PHI must sign a Business Associate Agreement.

We may also disclose information when required by applicable law, regulation, court order, or legal process.

05

How We Protect Your Data

  • Encryption in transit using TLS/SSL.
  • Encryption at rest using AES-256.
  • Role-based access controls and authentication.
  • HIPAA-compliant audit logging.
  • Regular security reviews, backups, and disaster recovery.
  • Breach notification to your agency without unreasonable delay, in accordance with HIPAA and the BAA.

Platform Data Collection, Use & Retention

User and Account Information

We collect user account information, including login credentials, user roles, permissions, activity logs, and audit trails.

Device and System Information

We collect device, browser, IP address, and system information used for security, authentication, and Platform performance.

Location Information

Location data is collected during check-in and check-out only when your agency enables visit tracking or location-based features.

Protected Health Information

Protected Health Information may include participant service plans, session notes, assessments, and clinical documentation. This information is processed solely to provide our services under a signed HIPAA Business Associate Agreement.

Data Retention

Data is retained only for as long as necessary to provide our services, comply with legal, regulatory, and contractual obligations, support security and audit requirements, or as directed by your agency.

Upon account termination, data is securely deleted or returned in accordance with applicable laws and your agreement.

Cookies and Analytics

We use essential cookies to operate the Platform and Google Analytics to understand website usage and improve our services. You can manage or disable cookies through your browser settings at any time.

06

Your Rights

You may request access, correction, or deletion of your contact information by emailing [email protected] with the subject “Privacy Request.”

We respond within 10 business days. Marketing emails always include an unsubscribe link.

State privacy laws, such as the CCPA, may provide additional rights, which we honor where applicable.

07

New York Agencies

We support compliance with New York data security and breach-notification requirements under the NY SHIELD Act, along with NHTD and TBI waiver documentation rules across all nine RRDC regions.

08

Children

Our Website and Platform are intended for adult professionals.

Participant records that include minors are governed by HIPAA and the BAA, under the agency's responsibility as the Covered Entity.

09

Changes to This Policy

We will post updates to this Privacy Policy on this page. Active customers will receive email notice at least 30 days before material changes take effect.

Scroll to Top