Privacy Policy
Effective date: [DATE]
Spectra Health — Privacy Policy
1. Who we are
Spectra Health LLC, a Wyoming limited liability company (“Spectra Health,” “Spectra,” “we,” “us”), provides behavioral-health screening and billing-decision-support software to licensed healthcare providers and their practices (“Providers”). Contact: privacy@spectrahealth.co.
2. Scope
This Policy describes how we handle information collected through our website and the Provider-facing application. Protected Health Information (PHI) that patients submit through screening links is handled on behalf of the Provider (a HIPAA Covered Entity) under HIPAA and our Business Associate Agreement (BAA) with that Provider — not under this consumer Policy. Where this Policy and a BAA conflict as to PHI, the BAA controls.
3. Information we collect
- Provider account data: name, work email, practice/organization, role, and authentication data (via Supabase Auth).
- Billing data: subscription status and payment method, processed by Stripe. We do not store full card numbers.
- Patient health information (PHI): screening responses, scores, and the identifiers a Provider enters (e.g., a medical record number and age). This is provided by the patient and processed solely to deliver the service to the Provider.
- Technical/usage data: IP address, device/browser info, and security logs. Our logs are configured to exclude answer content and patient identifiers.
4. How we use information
To provide, secure, and improve the service; to process subscriptions; to communicate with Providers; and to comply with law. We do not sell personal information or PHI, and we do not use PHI for advertising.
5. PHI and HIPAA
For PHI, Spectra acts as a Business Associate. We use and disclose PHI only as permitted by the BAA and HIPAA — to provide the service to the Provider, as required by law, or as the Provider directs. We maintain administrative, physical, and technical safeguards, including encryption of PHI at rest and in transit. Substance-use screening data may be subject to 42 CFR Part 2; Providers are responsible for obtaining any required patient consents.
6. Sharing and subprocessors
We share data with vendors who help us operate the service under contract (and BAAs where PHI is involved), including our cloud hosting/database provider and Stripe (billing). We may disclose information to comply with law or protect rights and safety. We do not otherwise share personal information or PHI.
7. Security
AES-256 field-level encryption of PHI, encryption in transit (TLS), role-based access, audit logging, and rate limiting. No method is 100% secure; we cannot guarantee absolute security.
8. Retention
We retain Provider and PHI data for as long as needed to provide the service and as required by the BAA, the Provider’s instructions, and applicable law, then delete or de-identify it.
9. Your choices and rights
Providers may access or update account information or contact us at privacy@spectrahealth.co. Patients seeking access, amendment, or deletion of their health information should contact their Provider, who controls that record under HIPAA. Depending on residence, you may have rights under laws such as the CCPA/CPRA or other state privacy laws; contact us to exercise them.
10. Cookies
We use necessary cookies for authentication and basic analytics. You can control cookies through your browser.
11. Children
The service is provided to licensed Providers, not to consumers directly. Providers are responsible for any use involving minor patients and for obtaining required consents.
12. Changes
We may update this Policy and will post the new effective date.
13. Contact
privacy@spectrahealth.co, [mailing address].
