Decisive Connect Privacy Policy

Last updated: June 17, 2025

1. Introduction

Decisive Connect ("Decisive Connect," "we," "our," or "us") provides workflow-automation and data-integration tools to healthcare organizations. Protecting the privacy and security of Protected Health Information ("PHI") and other personal data is core to our mission. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you:

By accessing or using the Site or Platform, you acknowledge that you have read and understood this Privacy Policy.

2. Scope & Relationship to HIPAA / Business-Associate Agreements

When we handle PHI on behalf of a covered entity or business associate (e.g., your hospital or clinic), we do so solely as that party's "Business Associate" under the U.S. Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and its implementing regulations, as amended by the HITECH Act. Our Business-Associate Agreement ("BAA") governs any PHI processing and will prevail over conflicting terms in this Policy. For non-PHI personal data (e.g., account credentials for hospital staff), this Privacy Policy applies.

3. Definitions

PHI: Individually identifiable health information that is created, received, or transmitted by a Covered Entity or Business Associate, as defined by HIPAA.

Personal Information / Personal Data: Information that identifies, relates to, describes, or can reasonably be linked to an individual, whether or not it is PHI.

De-identified / Aggregated Data: Data that cannot reasonably be used to identify an individual, consistent with 45 C.F.R. § 164.514(b).

4. Information We Collect

The categories of information we collect depend on how you interact with Decisive Connect and include:

5. How We Use Information

We use the information we collect for the following purposes:

6. Disclosures & Recipients

We never sell PHI or personal data. We only share information:

  1. With your healthcare organization under the BAA.

  2. With subprocessors / service providers bound by contractual privacy and security obligations.

  3. For legal compliance (e.g., subpoenas, court orders) after assessing and, where possible, narrowing the request.

  4. For corporate transactions such as mergers or acquisitions, subject to confidentiality and continuity of protections.

  5. With your consent or at your direction.

A current list of subprocessors is available at Decisive Connect/subprocessors.

7. HIPAA, HITECH & U.S. State-Specific Rights

7.1 HIPAA Safeguards

We implement administrative, physical, and technical safeguards meeting or exceeding 45 C.F.R. Part 164 Subpart C, including:

7.2 Patient Rights (HIPAA)

Where we maintain PHI on behalf of a covered entity, that entity is responsible for addressing patient rights of access, amendment, restriction, accounting of disclosures, and confidential communications. We support these requests as required under our BAA.

7.3 State Privacy Laws

California Consumer Privacy Act (CCPA) / CPRA: If you are a California resident and we process your non-PHI personal information, you may request access, deletion, correction, or opt-out of "sharing" for cross-context behavioural advertising. We do not "sell" personal info as defined by CCPA.

Other states (VA CDPA, CO CPA, CT DPA): Similar rights apply; contact us as described below.

Missouri currently has no comprehensive privacy statute, but we respect your rights under any applicable law.

8. International Transfers & GDPR

When we process personal data of individuals in the European Economic Area, UK, or Switzerland, Decisive Connect acts as a Data Processor, and the healthcare organization acts as the Data Controller. Transfers to the United States are made under:

Data subjects may exercise GDPR rights through their healthcare provider or directly via privacy@decisiveconnect.com.

9. Cookies & Similar Technologies

We use strictly necessary cookies for authentication and security. Where permitted, we also use functional and analytics cookies (e.g., Plausible or Matomo) to understand product performance. You may control cookies through browser settings; disabling them may affect Platform functionality.

10. Data Retention

PHI: Retained in accordance with the BAA or customer instructions, then securely deleted or de-identified using NIST SP 800-88 guidelines.

Other data: Retained as long as needed to fulfill the purposes outlined above, comply with legal obligations, resolve disputes, and enforce agreements.

11. Information Security Incident Response

We maintain an incident-response plan aligned with NIST SP 800-61. In the event of a breach involving unsecured PHI, we will notify affected customers without unreasonable delay and no later than 60 days, consistent with 45 C.F.R. § 164.404.

12. Your Choices & Rights Summary

We will verify your identity (and, where applicable, authority) before honoring requests.

13. Third-Party Links & APIs

The Platform may link to third-party sites or incorporate third-party APIs (e.g., FHIR endpoints, cloud storage). We are not responsible for the privacy practices of those entities. Review their policies before interacting.

15. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be posted on this page and, if significant, we will notify account owners via email or in-app alerts at least 30 days before the change takes effect.

16. Contact Us

Decisive Connect Privacy Office

Decisive Connect LLC

5424 Taylor Ln
Fort Collins, CO 80528, USA

Email: privacy@decisiveconnect.com

If you believe we have not adequately addressed your privacy concern, you may file a complaint with the U.S. Department of Health & Human Services Office for Civil Rights or your local data-protection authority.

Need a BAA?

Healthcare organizations can request our standard Business-Associate Agreement by emailing compliance@decisiveconnect.com or through the admin settings of their Decisive Connect workspace.

Decisive Connect is committed to safeguarding patient trust while enabling innovative, compliant automation for healthcare. Let us know if you have any questions or require modifications to this policy for your specific deployment.