Program status: in progress. These policies are written and operating, but Business Associate Agreements, the formal risk analysis, and final policy adoption are not yet complete. Nothing on this page is a claim of HIPAA compliance or certification.
Tetherhealth.io, LLC ("Tetherhealth.io") operates Tetherwell™, a platform through which individuals record sensitive information concerning their mental health during pregnancy, the postpartum period, and the subsequent years of parenting. The pages below set out the written policies and operating procedures governing the confidentiality, integrity, and availability of that information, and the safeguards maintained pending completion of the requirements applicable to a HIPAA business associate.
The Privacy & Security Officer responsible for this program is Ash Choi, LMHC, PMH-C, who may be contacted at ash@tetherhealth.io.
The three policies
- Administrative safeguards — Security management, assigned responsibility, access governance, vendor oversight, and contingency planning.
- Workforce training — Who must be trained, what the training covers, how often it runs, and what happens when the rules are broken.
- Breach notification — How we detect, assess, contain, and report a security incident — and what affected people can expect from us.
What is already in place
- Encryption in transit (TLS) for every connection to the platform, and encryption at rest for stored data.
- Row-level access rules in the database so each account can only reach its own records.
- Least-privilege service credentials, kept out of the application code and out of the browser.
- An append-only audit trail for support-contact changes, consent decisions, and every message we send on a person's behalf.
- Automated dependency and configuration security scanning on every change, reviewed on a scheduled basis.
- Named responsibility for privacy and security decisions, described in the administrative safeguards policy.
Matters in progress
Tetherhealth.io makes no representation of HIPAA compliance or certification. The following items remain outstanding: execution of Business Associate Agreements with each sub-processor that may receive protected health information; completion of a documented risk analysis and risk-management plan; and formal adoption of the policies published herein. Our current status is further described in the Privacy Policy.
Reporting a security concern
Suspected vulnerabilities or unauthorized disclosures should be reported to ash@tetherhealth.io, together with sufficient detail to permit reproduction and assessment. Reporters are asked to refrain from public disclosure until Tetherhealth.io has had a reasonable opportunity to respond. Reports are acknowledged within three (3) business days.
