Privacy Policy

How Holdmark Health handles your information.

We collect what we need to operate the service, hold chart-note data inside a BAA-covered enclave, and use it only for the work you subscribed us to do. Nothing leaves your tenant, and nothing you upload trains anyone else’s model.

1 · Information we collect

What we receive from you, and what we generate.

Holdmark Health is provided to medical, dental, and mental-health practices as a managed compliance workspace. To deliver the service we collect three categories of information:

Account information
The practice owner and authorized staff — name, work email, role, and the credentials you set to access the workspace.
Practice configuration
Specialty, licensed states, provider count, billing and EHR identifiers, and the Business Associates you have registered (name, role, BAA renewal date).
Audit substrate
Chart notes, billing files, and policy documents you connect or upload for analysis. These are processed in your tenant under a signed Business Associate Agreement (BAA).

We also generate operational artifacts on your behalf — audit packets, finding records, training-roster entries, regulatory feed timeline events, and breach-response worksheets. These live in the same tenant and are exported in the packets you compose.

2 · How we use information

Only the work you subscribed us to do.

Information in your workspace is used for three purposes, and no others:

  1. 1. Run the analyses you ask for. Continuous scans, on-demand audit packets, training delivery, BAA renewals, and breach-response workflows — all run against your tenant, with results surfaced to authorized users.
  2. 2. Operate the service. Billing, support, security monitoring, and product reliability — limited to what is necessary to keep the workspace available and to respond to your requests.
  3. 3. Improve the shared rule library. Aggregated, de-identified patterns (a finding shape, not a patient) may inform the rule library shipped to all tenants. We never use your chart notes or PHI for this purpose.

3 · Business Associate Agreements

Chart-note data stays under a signed BAA, in your tenant.

Holdmark Health is a Business Associate to the covered entities that use the service. A signed Business Associate Agreement (BAA) ships with every paid plan and covers Protected Health Information (PHI) processed inside the workspace.

  • PHI never leaves your tenant. Chart notes, billing files, and the analyses produced from them are stored and processed behind the BAA, with access limited to authorized users on your account and to Holdmark staff operating under the agreement.
  • No training on your data. PHI and the findings generated from it are not used to train models that are shared with other tenants, customers, or third parties.
  • Subcontractors are disclosed. The list of subcontractors that may process BAA-covered information is available on request and is updated as the service evolves.
  • Breach reporting.In the event of a breach of unsecured PHI within Holdmark’s custody, the BAA obligates us to notify the covered entity without unreasonable delay and within the window required by 45 CFR § 164.410.

4 · Data retention

How long things stay in your tenant.

Account and configuration
Retained for the life of the subscription, plus 30 days after cancellation to allow export.
Chart-note analyses
Retained for the retention period required by the policies you have adopted (commonly 6 years for HIPAA documentation), then purged from your tenant.
Audit packets
Retained on your tenant for as long as you keep them; exports you download are your responsibility once they leave the workspace.
Billing records
Retained for 7 years to satisfy tax and financial-reporting obligations.
Support correspondence
Retained for 3 years, or as required to resolve open matters, whichever is longer.
Aggregated rule-library telemetry
Retained indefinitely; does not contain PHI and is not traceable to a single tenant.

5 · How we share information

We do not sell data, and we share narrowly.

We do not sell, rent, or trade personal information. We share information only with the parties listed below, and only as needed to operate the service or as required by law:

  • Subprocessors. Hosting, email delivery, payment processing, and security monitoring — each covered by a data-processing agreement that limits use to the service you have subscribed to.
  • Your authorized users. Information flows to the people you have invited to your workspace and to the actions they take (audit packets, training record acknowledgements, breach-response drafts).
  • Legal process. If compelled by valid legal process, we will challenge over-broad requests and notify affected customers where permissible.
  • Business transitions. If Holdmark Health is acquired or merges, customers are notified before any transfer of tenant data, and the receiving party is bound by this policy until a successor agreement applies.

6 · Your choices

The controls available to you and your team.

Authenticated users on your account can:

  • Export the full workspace (audit packets, training rosters, BAA inventory) at any time.
  • Revoke access for departing staff from the dashboard.
  • Request deletion of account information at the end of the subscription, subject to the BAA and applicable retention rules.
  • Request a copy of the categories of subcontractors that handle BAA-covered data.

Patient-level access requests (a patient asking to see, correct, or export their own record) are routed to the covered entity — Holdmark supports the workflow but the covered entity remains the authority on patient-facing disclosures.

7 · Security

How we hold the workspace.

The workspace is operated in a tenant-isolated environment with role-aware access, audit logging of every privileged action, and PHI scope limited to the data you connect or upload. Externally, all traffic is encrypted in transit; data at rest is encrypted using provider-managed keys. Internal access to production systems requires authenticated, audited, time-bounded credentials.

No system is perfectly secure. If you discover a vulnerability or a suspected incident, please write to holdmark-health@polsia.app with the subject line Security report.

8 · Contact

Reach a person, not a form.

Questions about this policy, a data request, or a BAA inquiry — write to holdmark-health@polsia.app. A real person reads this inbox and will reply the same business day.

Last updated: . We will notify active subscribers by email before any material change takes effect.