Program status: in progress. These policies are written and operating, but Business Associate Agreements, the formal risk analysis, and final policy adoption are not yet complete. Nothing on this page is a claim of HIPAA compliance or certification.
1. Purpose
A substantial proportion of information-security incidents originate in human error rather than system failure. This policy establishes the training required of all personnel with access to Tetherwell™ systems or customer information, in order to ensure that such personnel understand the nature of the information they handle, the safeguards applicable to it, and the procedures to be followed in the event of a suspected incident.
2. Who must be trained
Every workforce member — employees, founders, contractors, interns, and volunteers — who has or may gain access to production systems, customer data, support inboxes, or the accounts that control them. Vendors are covered by contract rather than by this policy, but anyone acting as an extension of our team is trained the same way we are.
3. When training happens
- At onboarding, before production access is granted.
- Annually, as a refresher covering anything that changed.
- On material change, within 30 days of a new system, sub-processor, or legal obligation that affects how data is handled.
- After an incident, targeted retraining for the people and practices involved.
- Periodic reminders throughout the year on current threats, especially phishing and credential theft.
4. What the training covers
Privacy fundamentals
- What counts as sensitive information here: mood logs, screener answers, journal entries, conversations with Peri, phone numbers, and support-contact relationships.
- The minimum-necessary standard: access no more information than is required to perform the assigned task.
- Prohibition on accessing user content absent a legitimate operational purpose, and prohibition on discussing identifiable user content outside the platform, including in chat tools and support threads.
- Individual rights: access, correction, export, and deletion, and how to route those requests.
Security practices
- Unique credentials, a password manager, and multi-factor authentication on every account that touches production.
- Recognizing phishing and social-engineering attempts, including requests that appear to come from leadership.
- Device hygiene: disk encryption, automatic screen lock, current operating system updates.
- Keeping secrets out of source code, screenshots, support tickets, and AI prompts.
- Using test data for development and debugging wherever it is possible to do so.
Safety and crisis handling
- How the platform detects crisis language and what the product does in response.
- That we are not a clinical service, and that no workforce member gives medical advice.
- Escalation: when to surface 911, 988, and Postpartum Support International, and when to alert the Privacy & Security Officer.
- Handling messages sent to a person's support contacts with care — never including clinical detail in a text message.
Incident reporting
- What to report: lost devices, suspicious sign-ins, mistakenly shared data, a message sent to the wrong person, a suspected vulnerability.
- How fast: immediately, and within 24 hours of discovery at the latest.
- Who to tell: the Privacy & Security Officer at ash@tetherhealth.io.
- Assurance of non-retaliation for good-faith reports; failure to report, or delay in reporting, is itself a policy violation.
5. Confidentiality agreement
Before access is granted, each workforce member signs a confidentiality agreement covering personal and health-related information, and acknowledges this policy and the administrative safeguards policy in writing.
6. Records
We record who completed which training, on what date, and the version of the material used. Signed acknowledgements are stored with them. Records are retained for at least six years and are produced on request during a partner or customer security review.
7. Non-completion and violations
Access is suspended where required training remains outstanding more than 30 days after its due date. Violations of this policy are handled under the sanctions section of the administrative safeguards policy, with consequences proportionate to the violation, up to and including termination and referral to law enforcement.
8. Ownership and review
The Privacy & Security Officer owns this policy, keeps the material current, and reviews it at least annually.
