Privacy & Security Program

Administrative Safeguards Policy

Effective September 18, 2026

Program status: in progress. These policies are written and operating, but Business Associate Agreements, the formal risk analysis, and final policy adoption are not yet complete. Nothing on this page is a claim of HIPAA compliance or certification.

1. Purpose and scope

This policy defines the administrative controls Tetherhealth.io, LLC applies to protect personal and health-related information handled by Tetherwell™ and TetherCore™. It is modelled on the administrative safeguards standards of the HIPAA Security Rule (45 CFR §164.308) so that the program is capable of supporting our obligations upon commencement of any business associate relationship.

It applies to every employee, founder, contractor, and vendor with access to production systems, customer data, or the accounts that control them — collectively, the "workforce."

2. Security management process

Risk analysis

We maintain an inventory of the systems that store or transmit sensitive information: the application database, authentication, file storage, the AI gateway, the SMS provider, email delivery, hosting, and analytics. For each one we record what data it holds, who can reach it, and what would happen if it were exposed. The inventory is reviewed at least annually and whenever a new sub-processor is added. A formal, documented risk analysis with scored likelihood and impact is in progress and is a prerequisite for any Business Associate Agreement we sign.

Risk management

Identified risks are assigned an owner, a remediation plan, and a target date. High-severity findings — anything that could expose another person's data — are remediated before other product work continues.

Information system activity review

Authentication events, database errors, and administrative actions are logged. Support-contact changes, consent decisions, message sends, delivery outcomes, and opt-outs are written to an append-only audit trail. These logs are reviewed monthly, and immediately after any suspected incident.

Sanctions

Workforce members who violate this policy are subject to consequences proportionate to the violation, up to and including removal of access, termination of employment or contract, and referral to law enforcement. Sanctions are documented and retained for six years.

3. Assigned security responsibility

A single named individual holds the role of Privacy & Security Officer and is accountable for this program: maintaining these policies, approving access, overseeing vendors, running training, and leading incident response. This role is held by Ash Choi, LMHC, PMH-C, who may be contacted at ash@tetherhealth.io. The named holder is recorded in our internal register and updated within five business days of any change.

4. Workforce security

5. Information access management

6. Security awareness and training

All workforce members complete privacy and security training at onboarding and at least annually, with periodic reminders covering phishing, credential hygiene, safe handling of sensitive content, and how to report a concern. Details, including records retention, are in the workforce training policy.

7. Security incident procedures

Suspected incidents must be reported to the Privacy & Security Officer immediately and no later than 24 hours after discovery. Response, assessment, containment, and notification are governed by the breach-notification procedure. Every incident — including those determined not to be breaches — is logged with the facts, the assessment, and the outcome.

8. Contingency plan

9. Evaluation

This program is evaluated at least annually, and whenever there is a material change to our systems, sub-processors, or legal obligations. Automated dependency and configuration scanning runs continuously against every change, and findings are triaged on a scheduled basis.

10. Business associate and vendor oversight

Before a sub-processor can handle sensitive information, we review its security posture and execute appropriate contractual protections. Where protected health information is involved, that means an executed Business Associate Agreement. Our current sub-processor categories — database and authentication, hosting, AI gateway, SMS delivery, and transactional email — are listed in the Privacy Policy. Executing those agreements is part of the in-progress work described at the top of this page, and no protected health information is accepted from a covered entity before the corresponding agreement is signed.

11. Documentation and retention

Policies, risk analyses, training records, access approvals, sanctions, and incident records are retained for at least six years from the later of their creation date or last effective date, and are made available to workforce members responsible for implementing them.