SBARAlerts is a secure healthcare communication platform for skilled nursing facilities, physicians, and authorized healthcare professionals. This Privacy Policy applies to SBARAlerts.com and related services.
1Information We Collect
SBARAlerts may collect account details, facility affiliation, professional role, email address, telephone number, login credentials, support communications, IP addresses, browser information, authentication events, and audit activity.
Authorized users may submit SBAR reports, uploaded clinical documents, resident or patient identifiers, clinical observations, physician responses, and associated dates and timestamps. Some of this information may constitute Protected Health Information under HIPAA.
2How We Use Information
Information may be used to authenticate users, manage accounts, route SBAR communications, provide secure access to documents, record physician responses, send notification messages, maintain audit records, provide support, detect misuse, and satisfy contractual or legal obligations.
SBARAlerts does not sell Protected Health Information or use clinical information for unrelated advertising.
3HIPAA and Protected Health Information
When SBARAlerts processes PHI on behalf of a Covered Entity, the relationship may be governed by a signed Business Associate Agreement. Healthcare organizations remain responsible for user authorization, workforce training, minimum-necessary access, organizational policies, and timely account termination.
4Sharing and Disclosure
Information may be disclosed to authorized facility users, physicians, approved service providers, or governmental authorities when reasonably necessary to provide services, comply with law, investigate security incidents, or protect users and the platform.
SMS notifications are intended not to contain PHI. Users must sign in to the secure platform to review clinical information.
5Security Safeguards
Safeguards may include TLS encryption, secure password hashing, role-based access control, facility-level authorization, secure sessions, login throttling, protected document storage, audit logging, monitoring, backups, and incident-response procedures.
No internet-connected platform can guarantee absolute security. Users must protect credentials and promptly report suspected unauthorized access.
6Data Retention
Information is retained only as long as reasonably necessary to provide services, meet contractual requirements, maintain audit records, resolve disputes, comply with legal obligations, and support backup or disaster-recovery functions.
When no longer required, information may be deleted, de-identified, or securely destroyed according to documented procedures and customer instructions.
7Privacy Rights
Depending on applicable law, individuals may have rights to request access, correction, deletion, restriction, objection, or a copy of certain personal information. Requests involving clinical records or PHI may need to be directed to the healthcare organization responsible for those records.
8Cookies and Secure Sessions
SBARAlerts uses cookies and similar technologies necessary for authentication, secure sessions, CSRF protection, preferences, and fraud prevention. Disabling required cookies may prevent access to secure areas.