Privacy Policy
HT WORKS INC. (we, us or our) is committed to protecting the privacy and security of all personal data and Protected Health Information (PHI) entrusted to us by our clients and their end-users. We handle all data responsibly and in compliance with applicable regulations including HIPAA, the DPDP Act 2023, and CCPA/CPRA. This Privacy Policy (Effective June 25, 2026 | Version 1.0) sets out our commitment to protecting the privacy of personal information provided to us, or otherwise collected by us, offline or online, including when you access our services via our website or portal, or when we otherwise interact with you.
HIPAA Notice
HT Works Inc. is a HIPAA Business Associate. Medical records and health-related data handled through our services are Protected Health Information (PHI) processed under a signed Business Associate Agreement (BAA) with each client.
What we collect
We collect only what is necessary to provide our services:
- Website visitors: IP address, browser data, and contact form submissions (name, organization, email);
- Portal users: account details, login credentials, engagement metadata, and usage logs;
- PHI via portal or client engagement: health-related records and data submitted by clients, processed solely to deliver contracted services.
How we use your data
- To provide contracted technology and services to our clients;
- To manage your account and authenticate access;
- To communicate about your engagements and account;
- To comply with HIPAA and all applicable law;
- To send communications — only if you have opted in (you may unsubscribe at any time).
We never use PHI for marketing or any purpose beyond the contracted service.
PHI and HIPAA compliance
All PHI handled by HT Works Inc. is processed under a signed BAA. HT Works Inc. applies HIPAA’s Minimum Necessary Standard — we access only the PHI required to complete contracted work. PHI is never shared with third parties except as permitted under your BAA or required by law.
Clients must have an executed BAA before sharing PHI. To request a BAA or Data Protection Addendum (DPA), contact: Riyas Razik, HIPAA Security & Privacy Officer, HT Works Inc.
Data security
We protect your data using:
- Encryption in transit (TLS 1.2+) and at rest (AES-256);
- Multi-factor authentication and role-based access controls;
- Audit logging and monitoring via Azure and Grafana;
- Regular vulnerability assessments and security evaluations;
- Workforce HIPAA security awareness training;
- ISO 27001-aligned Information Security Management practices.
Data retention
| Data Type | Retention Period |
|---|---|
| PHI (via portal / client engagements) | 6 years — required by HIPAA |
| Client account and engagement data | Duration of contract + 6 years |
| Contact form data (non-PHI) | 90 days, then securely deleted |
| Security / audit logs | 6 years minimum |
Data sharing
We do not sell, lease, or share your personal information or PHI with third parties for commercial purposes. We may share data only:
- With clients — to deliver contracted work product;
- With trusted service providers (cloud hosting, security tools) under strict confidentiality and BAA agreements where applicable;
- When required by law or court order.
Breach notification
If a security incident involves PHI, HT Works Inc. will notify the affected client without unreasonable delay and within 60 days of discovery, in accordance with HIPAA (45 CFR §164.410) and the applicable BAA. Breach assessments are conducted using the HIPAA 4-factor test pursuant to 45 CFR §164.402.
Your rights
You have the right to:
- Know what personal data we hold about you;
- Request correction or deletion of your data;
- Opt out of marketing communications at any time;
- Receive your data in a portable format (where applicable).
Note: HIPAA rights requests relating to patient medical records (access, amendment) should be directed to the Covered Entity (healthcare provider or law firm) that submitted the records.
To exercise your rights, contact: Riyas Razik, HIPAA Security & Privacy Officer, HT Works Inc.
Cookies
We use essential cookies (required for the platform to function) and optional analytics cookies to understand how the platform is used. You can manage cookie preferences via your browser settings or the cookie banner on first visit.
Policy updates
We may update this policy from time to time. Material changes will be notified via the platform or by email to registered users. The effective date above indicates when this version was last updated.
Contact & HIPAA Privacy Officer
HIPAA Privacy & Security Officer
Riyas Razik | HT Works Inc.
Email: Riyas.Razik@medoment.com
Updated on 1st June 2026
