Privacy Policy

Effective Date: 2026-07-22 | TDM Technologies LLC

1. Overview

HIPAAPath ("the Application") is a self-assessment tool that helps independent healthcare providers document their HIPAA Security Rule compliance posture. TDM Technologies LLC ("we," "us") is committed to a data-minimization architecture: we do not store, process, or transmit the substantive content of your security self-assessment, your HIPAA Security Manual, or any Protected Health Information (PHI) of your patients on our servers. A narrow set of business-metadata fields — your account record, your acceptance of the Terms of Service, your email preferences, and any purchase or subscription records — is stored on our servers so that we can authenticate you, honor your purchases and subscriptions, and respect your unsubscribe preferences. Those fields are enumerated in §2 below.

2. Data We Collect

  • Account Information: When you sign in, we receive your name and email address from your chosen identity provider (email magic link, Google, or Microsoft). This identifies your account — nothing else from the provider is stored.
  • Audit Data: The security self-assessment data you enter (practice name, device inventory, policy acknowledgments) is stored locally on your devices in your browser's IndexedDB. We do not transmit, store, or process this content on our servers. When you generate the HIPAA Security Manual, it is rendered locally and downloaded directly to your device for you to keep, share, or store wherever you choose. See §3 below for the full Bring-Your-Own-Storage architecture description.
  • Usage Analytics: We use PostHog (US Cloud) to capture non-PHI usage events — page views, sign-in completions, chapter completions, and Manual export generation — to understand which parts of the product help. Autocapture is disabled, IP addresses are anonymized, session replay is disabled, and event payloads never include the contents of your audit. PostHog uses localStorage rather than cookies for its anonymous identifier.
  • Error Monitoring: We use Sentry to capture client-side errors and server-side exceptions for debugging. Breadcrumbs and request payloads are filtered before transmission, and audit data, email addresses, and session tokens are never included in error reports.
  • Server Logs & Hosting: The Application is hosted on Vercel. Standard edge and server logs (IP address, request path, timestamps, response status) may be retained for up to 30 days for security monitoring and operational purposes.
  • Account Database: Your account record — name, email, identity provider, Terms of Service acceptance triplet (timestamp, version, IP address), and email-preference fields described below — is stored in a managed Postgres database operated by Neon. Audit data is never stored here.
  • Email Delivery: Transactional email (magic-link sign-in, compliance-update welcome, one-click unsubscribe confirmations, and the quarterly compliance update itself) is sent via Resend. Resend processes your email address and message content for delivery.
  • Email Preferences: If you opt in to compliance updates, we store your preference, the timestamp of your opt-in, and an opaque token used to process one-click unsubscribe requests. We do not share this with third parties; the token is rotated if you re-subscribe after unsubscribing.
  • Feedback Submissions: The in-app feedback widget is open to every visitor, with or without an account. When you send feedback we receive your 1–5 rating, any text you write, and technical context captured so we can reproduce what you saw — the page you were on, your browser viewport size, your browser's user-agent string, and the deployed version of the Application. If you are signed in, your account email is attached so we can reply; if you are not, the reply-address field is optional and may be left blank. Submissions are emailed to our support inbox via Resend and are not written to our database — they persist only as email in that inbox. Please do not include PHI or patient details in feedback.
  • Purchases and Subscriptions: Payment processing is handled by Stripe; we never see or store your card details. When you make a purchase, we link your account to a Stripe customer ID and store the following non-payment metadata for the purposes of verifying your access to the artifact or subscription you bought:
    • Founding Member annual subscription ($299/year): Stripe subscription ID, Stripe price ID, subscription status (active, past_due, canceled, etc.), current period end date, and whether the subscription is set to cancel at the end of the current period.
    • Insurance-Ready Summary ($99 one-time SKU): Stripe checkout session ID, payment intent ID, customer ID, amount, currency, status, purchase date, and refund date (if applicable).
  • Any other information that you provide to us.

3. Bring-Your-Own-Storage (BYOS) Architecture

Your audit data lives on your devices, not on our servers. Chapter answers and progress are stored in your browser locally; the HIPAA Security Manual you generate is downloaded directly to your device for you to keep, share, or store wherever you choose. We never see or store the contents of your audit.

4. No PHI on Our Servers

HIPAAPath is not a covered entity or business associate under HIPAA. The Application is designed to ensure that no Protected Health Information (PHI) or Personally Identifiable Information (PII) of your patients is ever entered into or transmitted through our platform. Do not enter patient names, dates of birth, or other PHI into any field in this tool.

5. Data Deletion

  • Audit data on your devices: Audit data lives in your browser's IndexedDB and in any Manual you have downloaded. Clear your browser's site data for this domain and delete any downloaded Manual files to remove it from your devices.
  • Email-preference records: To stop compliance-update emails, use the one-click unsubscribe link in any compliance-update email footer. This removes your opt-in flag and invalidates the unsubscribe token.
  • Subscription cancellation: To cancel a Founding Member annual subscription, visit your Account page and use the "Manage subscription" link, which opens the Stripe customer portal. Cancellation takes effect at the end of the current paid term; access remains active until then. Cancellation does not delete your account record or purchase history — see the next item for that.
  • Account record and purchase records: To delete your account record (name, email, identity-provider link, Terms of Service acceptance triplet, email preferences) and any associated Stripe-linked purchase or subscription metadata, contact privacy@hipaapath.com. Stripe payment-record retention is governed by Stripe's own retention policy and applicable tax / financial-record-keeping law.

6. Sharing of Your Data

For business purposes, we may share certain personal information we receive from and about you, and about your transactions with us or through the Application, with certain third parties, including third party service providers who provide you with services related to the Application, our advertising/digital agencies and other vendors, such as our contractors, service providers and other third parties we use to support our business. Doing so allows us to provide the Application and related services you request. Please note that we do not sell your data.

7. Other Privacy Rights Afforded by Law

EU and Other Non-US Privacy Rights

We operate exclusively within the United States. The Application is not intended for access or use from outside the United States, and we do not knowingly collect or process personal data subject to the laws of any jurisdiction other than the United States.

Nevada

Nevada residents who wish to exercise their sale opt-out rights under Nevada Revised Statutes Chapter 603A may submit a request to this designated address: privacy@hipaapath.com. However, please know we do not sell data triggering that statute's opt-out requirements.

Other States

States, such as Colorado, California, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oklahoma, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, provide (now or in the future) their state residents with rights to:

  • Confirm whether we process their personal information.
  • Access and delete certain personal information.
  • Correct inaccuracies in their personal information, taking into account the information's nature and processing purpose (excluding Iowa and Utah).
  • Data portability.
  • Opt-out of personal data processing for:
    • targeted advertising (excluding Iowa);
    • sales; or
    • profiling in furtherance of decisions that produce legal or similarly significant effects (excluding Iowa and Utah).
  • Either limit (opt-out of) or require consent to process sensitive personal data.

The exact scope of these rights may vary by state. To exercise any of these rights please email us at privacy@hipaapath.com.

8. Changes to this Policy

We may revise this Policy from time to time in our sole discretion, and the updated Policy applies to you after the effective date of the revision. Your continued access or use of the Application or related services following any amendments to the Policy constitutes your acceptance of the Policy as amended. It is your sole responsibility to monitor our website for changes to the Policy.

9. Contact

For privacy inquiries, contact TDM Technologies LLC at privacy@hipaapath.com.

10. Cookie Policy

Our site also uses "cookie" technology to collect additional website usage data and to improve the site and the Application. A cookie is a small data file that is transferred to your computer's hard disk. A session cookie enables certain features of the site and is deleted from your computer when you disconnect from or leave the site. A persistent cookie remains after you close your browser and may be used by your browser on subsequent visits to our site. We may use both session and persistent cookies to better understand how you interact with our site, to monitor aggregate usage by our users and web traffic routing on our site, and to improve our site and Application. You may also be able to configure your computer or mobile device to limit the collection of these "cookies," but that limitation may also limit our ability to provide all of the services or functionalities of the site.

HIPAAPath uses a small number of strictly necessary cookies to operate the Application — primarily to keep you signed in and to protect against cross-site request forgery (CSRF). For product analytics we use PostHog, which stores an anonymous identifier in your browser's local storage (not in a cookie); autocapture is disabled, IP addresses are anonymized, and session replay is disabled. We do not use cookies or similar technologies for advertising, marketing, cross-site tracking, or session replay.

The law allows us to store cookies on your device where they are strictly necessary for the operation of the site. The only cookies we set are strictly necessary ones; we do not deploy advertising, marketing, or cross-site tracking cookies, and we do not operate a cookie-consent management platform.

You can block or delete cookies through your browser settings at any time; because the cookies we use are strictly necessary, doing so may limit sign-in and certain features of the site.

Necessary

Necessary cookies help make a website usable by enabling functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

NameProviderPurposeMaximum Storage DurationType
__Secure-authjs.session-tokenHIPAAPath (hipaapath.com)Maintains your authenticated sign-in session. The Application cannot function without it.30 daysHTTP cookie
__Host-authjs.csrf-tokenHIPAAPath (hipaapath.com)Protects against cross-site request forgery (CSRF).SessionHTTP cookie
__Secure-authjs.callback-urlHIPAAPath (hipaapath.com)Remembers the page to return you to during sign-in.SessionHTTP cookie

Preferences

Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in. We do not use any.

Analytics

Analytic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

NameProviderPurposeMaximum Storage DurationType
ph_[project API key]_posthogPostHog (US Cloud)Stores an anonymous analytics identifier and a temporary event queue to measure aggregate product usage. Set only if analytics are not blocked client-side. Autocapture disabled; IP anonymized; session replay disabled; no audit content collected.Persistent (until you clear site data)HTML local storage (not an HTTP cookie)

Marketing

Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers. We do not use any.

Other Technologies

We do not use any other cookie-like tracking technologies beyond those listed above.

Can you help us make this better?

How easy is HIPAAPath to use so far?
HardEasy

Please don’t include patient information — this goes to us by email.