Privacy & Security Program

Workforce Training Policy

Effective September 18, 2026

Program status: in progress. These policies are written and operating, but Business Associate Agreements, the formal risk analysis, and final policy adoption are not yet complete. Nothing on this page is a claim of HIPAA compliance or certification.

1. Purpose

A substantial proportion of information-security incidents originate in human error rather than system failure. This policy establishes the training required of all personnel with access to Tetherwell™ systems or customer information, in order to ensure that such personnel understand the nature of the information they handle, the safeguards applicable to it, and the procedures to be followed in the event of a suspected incident.

2. Who must be trained

Every workforce member — employees, founders, contractors, interns, and volunteers — who has or may gain access to production systems, customer data, support inboxes, or the accounts that control them. Vendors are covered by contract rather than by this policy, but anyone acting as an extension of our team is trained the same way we are.

3. When training happens

4. What the training covers

Privacy fundamentals

Security practices

Safety and crisis handling

Incident reporting

5. Confidentiality agreement

Before access is granted, each workforce member signs a confidentiality agreement covering personal and health-related information, and acknowledges this policy and the administrative safeguards policy in writing.

6. Records

We record who completed which training, on what date, and the version of the material used. Signed acknowledgements are stored with them. Records are retained for at least six years and are produced on request during a partner or customer security review.

7. Non-completion and violations

Access is suspended where required training remains outstanding more than 30 days after its due date. Violations of this policy are handled under the sanctions section of the administrative safeguards policy, with consequences proportionate to the violation, up to and including termination and referral to law enforcement.

8. Ownership and review

The Privacy & Security Officer owns this policy, keeps the material current, and reviews it at least annually.