Healthcare Data Governance Notice
Smart HMS is engineered strictly for hospital administration, clinical EHR/EMR recording, pharmacy lot tracking, and financial reconciliation. We adhere to the Health Insurance Portability and Accountability Act (HIPAA), General Data Protection Regulation (GDPR), and industry-standard data sovereignty standards.
1. Overview & Scope
This Privacy Policy governs the collection, processing, transmission, and archival of information by StatGenTech LLC (“Smart HMS”, “we”, “us”, or “our”) in connection with our multi-tenant Hospital Management System, web portals, offline-first mobile applications, and desktop command centres.
This policy applies to all healthcare facilities (“Customers”, “Tenants”), including hospitals, specialized clinics, diagnostic labs, and authorized users (doctors, nurses, administrative personnel, pharmacists, and accountants).
2. Customer Controller vs. Smart HMS Processor Role
Under applicable data protection frameworks (including GDPR Art. 28 and HIPAA 45 CFR § 164.502):
- The Customer (Hospital/Clinic) is the Data Controller / Covered Entity: You determine the legal basis for processing patient health information, obtain necessary patient consents, and manage internal clinical data governance.
- Smart HMS is the Data Processor / Business Associate: We process customer data exclusively on documented instructions from the Customer, for the sole purpose of delivering the HMS software services. We never sell, monetize, broker, or train public AI models on Customer patient data.
3. Categories of Data Collected
In operating the platform, Smart HMS processes the following datasets:
- Administrative Account Data: Hospital corporate name, licensing numbers, tax ID, billing contact details, staff credentials, and role permissions.
- Electronic Health Records & Clinical Data (ePHI): Patient identifiers (name, age, gender, blood group, contact), OPD consultation notes, IPD bed allocations, vital sign recordings, laboratory pathology/radiology reports, surgical notes, and electronic prescriptions.
- Financial & Billing Records: Invoices, thermal receipt records, insurance ledger claims, deposit payments, corporate credit approvals, and tax tallies.
- System Audit Trails & Telemetry: Immutable audit logs recording user ID, IP address, timestamp, device identifier, and specific records created, viewed, updated, or deleted.
4. Protected Health Information (PHI) & Security Safeguards
To safeguard ePHI against unauthorized access, destruction, or interception, Smart HMS implements multi-layered defence-in-depth security:
- Encryption in Transit: All HTTP and WebSocket communications enforce TLS 1.3 with strict HTTP Strict Transport Security (HSTS).
- Encryption at Rest: Database volumes, file stores, and automated snapshot archives are encrypted using FIPS 140-2 validated AES-256 encryption.
- Multi-Tenant Logical Isolation: Data rows are partitioned using PostgreSQL Row-Level Security (RLS) keyed by tenant ID, preventing cross-tenant data leakage.
- Granular Access Control: Strict Role-Based Access Control (RBAC) ensures staff members only view data required for their clinical or operational duty.
5. Biometric Data & ZKTeco Device Integration
Smart HMS provides seamless ADMS bridge synchronization with physical biometric devices (such as ZKTeco time & attendance terminals).
6. Infrastructure & Sub-processors
We partner with world-class cloud infrastructure providers that maintain SOC 1/2/3, ISO 27001, and HIPAA compliance certifications (e.g., AWS, Google Cloud Platform, Supabase Enterprise). All sub-processors are bound by strict Business Associate Agreements (BAAs) and Data Processing Agreements (DPAs). Customers may request our current sub-processor registry at any time.
7. Data Retention, Export & Deletion
- Statutory Retention: Customers acknowledge that hospital records and medical histories may be subject to mandatory legal retention periods (e.g., 7–10 years depending on jurisdiction).
- Data Portability: Customers can export patient registries, billing ledgers, and diagnostic reports in standard machine-readable formats (JSON, CSV, PDF) at any time.
- Post-Termination Purge: Upon contract termination, Customer data is preserved for a 60-day grace period for full export, after which all primary databases and backups are cryptographically destroyed.
8. Data Subject Rights (GDPR & Local Privacy Laws)
Where applicable, patients have rights to inspect, amend, or request an accounting of disclosures of their health records. Because Smart HMS operates as a data processor, any patient request received directly by Smart HMS will be promptly redirected to the respective Hospital Administrator for verification and execution.
9. Data Protection Officer & Inquiries
For inquiries regarding our HIPAA privacy safeguards, security certifications, or to execute a Business Associate Agreement (BAA), contact our Data Protection Team:
Smart HMS / StatGenTech Compliance Group
Email: privacy@smarthms.com
Security Inquiries: security@smarthms.com
Direct Response Time: Within 2 business days