Purpose, Scope, and HIPAA Status
This HIPAA Privacy and Security Policy ("Policy") describes how MyCareHuddle, LLC ("MyCareHuddle") protects the privacy and security of health-related information created, received, maintained, or transmitted through the MyCareHuddle eldercare coordination platform.
IMPORTANT — MyCareHuddle's HIPAA Status: MyCareHuddle is not a Covered Entity under the Health Insurance Portability and Accountability Act (HIPAA) as defined by the U.S. Department of Health and Human Services. As a direct-to-consumer care coordination platform, we are not a healthcare provider, health plan, or healthcare clearinghouse.
However, we voluntarily adopt HIPAA-aligned privacy and security standards because we believe health information deserves strong protection. We commit to the practices described in this Policy as a matter of our own values and our users' trust.
This Policy applies to: all MyCareHuddle workforce members including employees, contractors, interns, and volunteers; all systems, devices, and services used to develop, operate, or support the Platform; and all third-party vendors with access to health-related information in the MyCareHuddle system.
Definitions
- Health-Related Information (HRI): Any personally identifiable information relating to a person's health status, medications, care history, or provision of care that is stored in MyCareHuddle — functionally equivalent to what HIPAA calls Protected Health Information (PHI).
- Electronic Health-Related Information (eHRI): HRI stored or transmitted electronically through our Platform — functionally equivalent to electronic PHI (ePHI).
- Workforce Member: Any employee, contractor, intern, or volunteer whose work is under the direct control of MyCareHuddle.
- Minimum Necessary: The principle that workforce members access, use, and disclose only the HRI needed to perform their assigned duties.
- Admin User: A MyCareHuddle user who creates and manages a care recipient profile and care team.
- Caregiver User: A MyCareHuddle user invited by an Admin to participate in a care team.
Privacy and Security Officer
Cathy Ackerman, Founder, is designated as both Privacy Officer and Security Officer. As Privacy Officer, she is responsible for overseeing privacy compliance, handling user rights requests, and managing privacy complaints. As Security Officer, she is responsible for security compliance, risk analysis, and technical and administrative safeguards for eHRI.
Key responsibilities of the Privacy/Security Officer:
- Maintain and update this Policy and supporting procedures at least annually or when material changes occur
- Ensure workforce training on privacy and security practices upon hire and periodically thereafter
- Coordinate risk assessments, security audits, and incident response
- Serve as the primary contact for privacy complaints and security incidents
Permitted Uses and Disclosures of Health-Related Information
MyCareHuddle uses and discloses HRI only for the following purposes:
- Provision of services: Operating the Platform to help care teams coordinate eldercare, track medications, share information with authorized caregivers, log daily care activities, and communicate as a team
- Operations and quality improvement: Monitoring system performance, preventing fraud or abuse, improving algorithms and workflows — using de-identified data wherever feasible and the minimum necessary HRI otherwise
- Legal and regulatory requirements: Responding to court orders, subpoenas, or other legal demands as required by law
- Safety: Disclosing information as necessary to prevent or lessen a serious and imminent threat to a person's health or safety
Any non-routine disclosure outside these purposes requires documented authorization from the Admin user or a specific legal basis.
User Rights
MyCareHuddle provides the following rights to users with respect to their health-related information:
- Access: Users may view, download, or export their HRI stored in the Platform through account settings or by contacting us at support@MyCareHuddle.com. We will respond within 30 days.
- Correction: Users may update or correct their HRI through their account. Where a correction request cannot be accommodated, we will explain why.
- Deletion: Users may delete their account directly in the app or request deletion of their account and associated HRI by contacting us. We will delete or anonymize data within 90 days of account deletion or a verified request, except where retention is required by law. Residual copies may persist in encrypted backup systems for up to 180 days before permanent deletion, as described in our Privacy Policy.
- Accounting of Disclosures: Users may request a log of non-routine disclosures of their HRI. We maintain such logs and will provide them upon request within 30 days.
- Restriction: Users may request that we restrict certain uses of their HRI. We will honor reasonable restriction requests where technically feasible.
Minimum Necessary and Access Control
MyCareHuddle maintains role-based access controls so that workforce members access only the minimum HRI necessary to perform their assigned roles.
Core access control requirements:
- Unique user IDs for all accounts; shared accounts for systems that handle HRI are prohibited
- Role-based permissions restrict access to production HRI to authorized engineering, operations, and support personnel on a need-to-know basis
- Multi-factor authentication (MFA) for all administrative and production access that can reach eHRI
- Automatic session timeouts and device lock policies for systems accessing HRI
- Documented access provisioning and termination procedures, including prompt revocation of access when roles change or individuals leave
Access rights are reviewed at least quarterly and after significant organizational changes.
Technical Safeguards
MyCareHuddle implements the following technical safeguards:
- Encryption in transit: all network communications that include eHRI are protected using TLS 1.2 or higher between clients, APIs, and backend services
- Encryption at rest: eHRI stored in databases, file storage, and backups is encrypted at rest using AES-256 or equivalent cryptography
- Audit logging: access to eHRI, authentication events, and security-relevant actions are logged and retained for a minimum of six years for security monitoring and incident investigation
- Secure development: code changes follow secure development practices including version control, code review, dependency scanning, and vulnerability remediation
- Backups and recovery: regular encrypted backups are performed and tested to enable recovery of eHRI in the event of data loss or system failure
- Vulnerability management: we conduct regular vulnerability scans and penetration testing and remediate identified issues on a risk-prioritized basis
Administrative and Physical Safeguards
Administrative Safeguards
- Conduct periodic risk analyses (at least annually) to identify and remediate reasonably foreseeable risks to eHRI
- Maintain an incident response plan and breach notification procedures
- Require privacy and security awareness training for all workforce members upon hire and at least annually thereafter
- Maintain a sanctions policy for workforce members who violate this Policy
Physical Safeguards
- Use reputable cloud providers with data centers that implement controlled physical access, environmental protections, and hardware security measures
- Require secure workspace practices for any workforce member accessing eHRI remotely, including encrypted devices and private network connections
- Prohibit local storage of eHRI outside approved encrypted systems
Security Incidents and Breach Notification
MyCareHuddle maintains a documented incident response process for suspected or actual security incidents involving HRI.
Incident Response Steps:
- Identification and containment: isolate affected systems and restrict access as necessary to prevent further exposure
- Investigation: determine scope, root cause, and HRI involved
- Risk assessment: evaluate the nature and extent of the incident and the likelihood of harm to affected individuals
- Notification: notify affected users without unreasonable delay and within 60 days of discovering a breach — this timeline aligns with HIPAA breach notification standards that we voluntarily follow
- Documentation: maintain records of the incident, response actions, and corrective measures
What We Will Tell You: In the event of a breach, our notification to affected users will include: a description of what happened, the types of information involved, steps we have taken to address the breach, steps you can take to protect yourself, and contact information for questions.
Business Associates and Vendors
MyCareHuddle classifies and manages third-party vendors who may access HRI on our behalf.
Our vendor management requirements:
- Identify all vendors that create, receive, maintain, or transmit HRI on MyCareHuddle's behalf (including cloud hosting, messaging, analytics, and logging services)
- Execute data processing agreements with such vendors that require them to maintain appropriate security safeguards, limit use of HRI to the services they provide, and support breach notification and audit requirements
- Evaluate vendor security posture during onboarding through security questionnaires or third-party audit reports
- Review vendor agreements at least annually
Current primary infrastructure providers include cloud hosting and database services. Specific vendor names are maintained in our internal vendor registry, available to users upon request.
Remote Work and Device Security
Because MyCareHuddle workforce members may work remotely, we apply the following minimum standards for remote access to systems containing eHRI:
- Company-approved or pre-authorized devices with full-disk encryption, current operating systems, and endpoint protection software
- Prohibition on storing eHRI locally outside approved encrypted applications and systems
- Use of secure, encrypted network connections (VPN or equivalent) when accessing administrative systems from remote locations
- Screen lock and automatic timeout on all devices used to access eHRI
State Privacy Law Compliance
In addition to our voluntary HIPAA-aligned practices, MyCareHuddle complies with applicable state privacy laws. Relevant state laws may include:
- California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) for California residents — see our Privacy Policy for California-specific rights
- New York SHIELD Act for New York residents
- Other applicable state health privacy laws
Where state law provides stronger protections than our baseline practices, we apply the more protective standard.
Training, Awareness, and Sanctions
- All workforce members receive privacy and security training, including MyCareHuddle-specific procedures, as part of onboarding and at least annually thereafter
- Additional training is provided when policies, systems, or applicable laws change
- Violations of this Policy may result in disciplinary action up to and including termination or contract revocation, as well as referral to appropriate legal authorities for criminal violations
- Training completion is documented and records are maintained for a minimum of six years
Policy Management and Documentation
MyCareHuddle maintains documentation required by this Policy and applicable law, including:
- Risk assessments, security audits, and remediation plans
- Access control records and access review logs
- Workforce training records
- Incident response and breach documentation
- Vendor agreements and security assessments
This Policy is reviewed at least annually and updated as needed to reflect changes in law, regulations, MyCareHuddle's services or infrastructure, or identified risks. The effective date at the top of this document reflects the most recent update.
Questions and Complaints
Questions about this Policy or concerns about privacy or security can be directed to:
- Privacy & Security Officer: Cathy Ackerman
- Email: support@MyCareHuddle.com
- Mail: MyCareHuddle, LLC, 56 Walsingham Rd, Mendham, NJ 07945
MyCareHuddle will log, investigate, and respond to all privacy and security inquiries and complaints in a timely manner. We will not retaliate against any person for submitting a good-faith complaint or concern.
If you believe your privacy rights have been violated and are not satisfied with our response, you may contact your state attorney general's office or the Federal Trade Commission at ftc.gov/privacy.
