Program status: in progress. These policies are written and operating, but Business Associate Agreements, the formal risk analysis, and final policy adoption are not yet complete. Nothing on this page is a claim of HIPAA compliance or certification.
1. Purpose and scope
This policy defines the administrative controls Tetherhealth.io, LLC applies to protect personal and health-related information handled by Tetherwell™ and TetherCore™. It is modelled on the administrative safeguards standards of the HIPAA Security Rule (45 CFR §164.308) so that the program is capable of supporting our obligations upon commencement of any business associate relationship.
It applies to every employee, founder, contractor, and vendor with access to production systems, customer data, or the accounts that control them — collectively, the "workforce."
2. Security management process
Risk analysis
We maintain an inventory of the systems that store or transmit sensitive information: the application database, authentication, file storage, the AI gateway, the SMS provider, email delivery, hosting, and analytics. For each one we record what data it holds, who can reach it, and what would happen if it were exposed. The inventory is reviewed at least annually and whenever a new sub-processor is added. A formal, documented risk analysis with scored likelihood and impact is in progress and is a prerequisite for any Business Associate Agreement we sign.
Risk management
Identified risks are assigned an owner, a remediation plan, and a target date. High-severity findings — anything that could expose another person's data — are remediated before other product work continues.
Information system activity review
Authentication events, database errors, and administrative actions are logged. Support-contact changes, consent decisions, message sends, delivery outcomes, and opt-outs are written to an append-only audit trail. These logs are reviewed monthly, and immediately after any suspected incident.
Sanctions
Workforce members who violate this policy are subject to consequences proportionate to the violation, up to and including removal of access, termination of employment or contract, and referral to law enforcement. Sanctions are documented and retained for six years.
3. Assigned security responsibility
A single named individual holds the role of Privacy & Security Officer and is accountable for this program: maintaining these policies, approving access, overseeing vendors, running training, and leading incident response. This role is held by Ash Choi, LMHC, PMH-C, who may be contacted at ash@tetherhealth.io. The named holder is recorded in our internal register and updated within five business days of any change.
4. Workforce security
- Authorization and supervision. Access to production data requires written approval from the Privacy & Security Officer. Contractors operate against non-production data unless production access is documented and justified.
- Clearance. Before access is granted, each workforce member signs a confidentiality agreement and completes the training described in our workforce training policy.
- Termination. On departure or role change, access is revoked the same day: accounts disabled, shared credentials rotated, devices removed from trusted lists, and the removal recorded.
5. Information access management
- Access is granted on a minimum-necessary basis: the least data and the fewest privileges required to do the job.
- Application access is enforced in the database itself through row-level rules, so an account can only read its own records even if application code is wrong.
- Elevated service credentials that bypass those rules are held only by server-side code, never shipped to a browser or mobile app, and never stored in the code repository.
- Access rights are reviewed at least every six months and after any role change.
6. Security awareness and training
All workforce members complete privacy and security training at onboarding and at least annually, with periodic reminders covering phishing, credential hygiene, safe handling of sensitive content, and how to report a concern. Details, including records retention, are in the workforce training policy.
7. Security incident procedures
Suspected incidents must be reported to the Privacy & Security Officer immediately and no later than 24 hours after discovery. Response, assessment, containment, and notification are governed by the breach-notification procedure. Every incident — including those determined not to be breaches — is logged with the facts, the assessment, and the outcome.
8. Contingency plan
- Data backup. The production database is backed up automatically by our hosting provider, with point-in-time recovery.
- Disaster recovery. Infrastructure is defined in code and the database schema is reproducible from version-controlled migrations, so the platform can be rebuilt from source and the most recent backup.
- Emergency mode. If the platform is degraded, crisis resources (911, 988, Postpartum Support International, and local lines) remain reachable and are never gated behind sign-in.
- Testing and revision. Restore procedures are tested at least annually and the results recorded.
9. Evaluation
This program is evaluated at least annually, and whenever there is a material change to our systems, sub-processors, or legal obligations. Automated dependency and configuration scanning runs continuously against every change, and findings are triaged on a scheduled basis.
10. Business associate and vendor oversight
Before a sub-processor can handle sensitive information, we review its security posture and execute appropriate contractual protections. Where protected health information is involved, that means an executed Business Associate Agreement. Our current sub-processor categories — database and authentication, hosting, AI gateway, SMS delivery, and transactional email — are listed in the Privacy Policy. Executing those agreements is part of the in-progress work described at the top of this page, and no protected health information is accepted from a covered entity before the corresponding agreement is signed.
11. Documentation and retention
Policies, risk analyses, training records, access approvals, sanctions, and incident records are retained for at least six years from the later of their creation date or last effective date, and are made available to workforce members responsible for implementing them.
