Privacy Policy
Effective date: July 28, 2026 · VigilReady LLC
1. Who We Are
VigilReady LLC (“we,” “our,” or “us”) operates VigilReady, a HIPAA-compliant document management platform for disability services providers. Our principal place of business is in the United States. Questions about this policy can be directed to [email protected].
2. Information We Collect
We collect the following categories of information in connection with operating the platform:
- Account information — name, email address, and role provided at registration.
- Protected Health Information (PHI) — compliance documents uploaded by staff on behalf of clients, which may include names, dates of birth, Medicaid numbers, and service records.
- Usage data — document access events, approval actions, and audit log entries required by HIPAA.
- Technical data — IP addresses, browser type, and session identifiers used for security and anomaly detection.
3. How We Use Information
- To provide and operate the compliance document management service.
- To maintain the HIPAA-required audit trail of all PHI access.
- To detect and respond to unauthorized or anomalous access.
- To send system notifications (document status changes, expiring requirements).
- To comply with legal obligations including applicable federal and state regulations.
4. How We Share Information
We do not sell personal information. We share information only as follows:
- AWS (Amazon Web Services) — our cloud infrastructure provider. We maintain a Business Associate Agreement (BAA) with AWS covering all PHI stored or processed on their services.
- Payment processing — subscription billing is handled by Stripe, our payment processor. Stripe receives only organization-level billing details (company name, billing contact, payment method). No client names, documents, or health information are transmitted to Stripe.
- Within your organization — authorized staff and administrators in your organization can access documents and compliance data scoped to your account.
- Legal requirements — we may disclose information if required by law, subpoena, or to protect the safety of individuals.
5. Data Security
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Documents are stored in a private Amazon S3 bucket accessible only via time-limited signed URLs. We enforce multi-factor authentication, session timeouts, and rate limiting. Access to PHI is logged in an append-only audit trail. We conduct regular security reviews and monitoring.
6. Data Retention
We retain PHI and compliance records for a minimum of seven (7) years in accordance with HIPAA requirements. Audit logs are retained for the same period. Upon termination of service, data will be securely deleted within 90 days unless a longer retention period is required by law.
7. Your Rights
Depending on applicable law, you may have the right to access, correct, or delete your personal information. Requests regarding PHI must follow the process described in our HIPAA Notice. For other requests, contact [email protected].
8. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to account administrators. Continued use of the platform after changes take effect constitutes acceptance.