Privacy & Security Program

Breach Notification Procedure

Effective September 18, 2026

Program status: in progress. These policies are written and operating, but Business Associate Agreements, the formal risk analysis, and final policy adoption are not yet complete. Nothing on this page is a claim of HIPAA compliance or certification.

1. Purpose and scope

This procedure governs how Tetherhealth.io, LLC responds when personal or health-related information may have been accessed, disclosed, altered, or lost without authorization. It is written to satisfy the HIPAA Breach Notification Rule (45 CFR §§164.400–414) and applicable U.S. state breach-notification laws, and it applies whether the incident happens in our own systems or at a sub-processor.

2. Definitions

3. Detection and reporting

Incidents reach us through automated alerts, log review, sub-processor notices, customer or partner reports, and outside security researchers. Every workforce member must report a suspected incident to the Privacy & Security Officer immediately and no later than 24 hours after discovery. Anyone outside the company can report one to ash@tetherhealth.io; we acknowledge reports within three business days.

4. Response timeline

  1. Within 24 hours of discovery — report received, incident logged, Privacy & Security Officer notified, and a response lead assigned.
  2. Within 72 hours — immediate containment: revoke compromised credentials, close the exposure, and and preserve logs and evidence prior to any remediation activity.
  3. Within 10 business days — investigation and written risk assessment completed, scope and affected individuals identified.
  4. Without unreasonable delay, and no later than 60 calendar days after discovery — notification to affected individuals when the assessment concludes a breach occurred.
  5. Within 30 days of closing the incident — corrective actions implemented and the post-incident review documented.

When we act as a business associate for a covered entity, we notify that customer without unreasonable delay and no later than 10 calendar days after discovery, so they can meet their own obligations, and we support their notifications with the facts we hold.

5. Risk assessment

Unless we treat the incident as a breach outright, we assess at least these four factors and document the conclusion:

  1. The nature and extent of the information involved, including how identifying and how sensitive it is.
  2. Who used the information or to whom it was disclosed.
  3. Whether the information was actually acquired or viewed.
  4. The extent to which the risk has been mitigated.

Information that was properly encrypted and whose keys were not compromised is not treated as a breach.

6. Notification to affected individuals

Notice is sent by email to the address on the account, with an in-app notice as well. If we lack current contact details for ten or more people, we post a substitute notice on our website for 90 days. Each notice includes, in plain language:

7. Notification to regulators and media

8. Documentation

Every incident is documented with the timeline, the facts, the risk assessment and its conclusion, the notifications sent, and the corrective actions taken — including incidents determined not to be breaches, with the reasoning. Records are retained for at least six years.

9. Post-incident review and prevention

Within 30 days of closing an incident, we conduct a non-punitive post-incident review documenting the sequence of events, the control failures that permitted the incident, and the technical, procedural, or training changes required to prevent recurrence. Each corrective action is assigned an owner and a completion date and is tracked to closure under the administrative safeguards policy.

10. Ownership and review

The Privacy & Security Officer owns this procedure and reviews it at least annually, and after any incident that tested it.