Privacy Notice & BAA Reference

Version 2026-08-31

Scope

MDS Command acts as a Business Associate of the customer facility. Protected health information (PHI) is processed only to provide the documentation, MDS/PDPM support, and audit-defense services described in the Terms of Service, and as permitted by the executed Business Associate Agreement (BAA). No PHI is collected on our public marketing pages.

What we collect

Facility user emails, role assignments, audit logs, and — if you choose to use the clinical tools — the facility documentation data you input.

Encryption

PHI is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher. Backups and file storage inherit the same encryption controls. Uploaded evidence lives in private storage reachable only through short-lived, permission-checked links.

Access control

Access is role-based (CNA, LPN, RN, Infection Preventionist, DON, Administrator) and enforced in the database with row-level security, not merely by hiding navigation. Every record is scoped to a facility; a user assigned to one facility cannot read, export, search, or receive alerts for another facility's residents.

Multi-factor authentication is supported for all roles and required for Infection Preventionist and DON. Sessions automatically end after 15 minutes of inactivity. Passwords must be at least 12 characters and contain at least three character classes.

Audit logging

Sign-ins, record access, exports, approvals, priority changes, and AI dispositions are recorded in an append-only audit log. Updates and deletions are blocked at the database level, and entries are retained for six years.

Breach notification

MDS Command will notify the customer's designated Privacy Official of any confirmed or reasonably suspected breach of unsecured PHI within 24 hours of discovery, with the facts known at that time and updates as the investigation proceeds.

Text messaging (TCPA)

Recipients may reply STOP to any message to opt out; opt-outs are applied immediately, the contact is flagged, and no further messages are sent to that number. Delivery receipts from the carrier are stored with each message so delivery can be evidenced during survey.

Return or destruction of data

On termination or upon the customer's written request, customer data is returned in a usable export or securely destroyed within 30 days, except where law requires longer retention. In that case, the data remains protected and use is limited to the required purpose.

De-identified data

De-identified, aggregate information may be used for case studies only with the customer's prior written authorization. De-identification follows the HIPAA Safe Harbor method.

Subprocessors and hosting

Hosting and database services run on a HIPAA-eligible cloud platform under a signed BAA. A SOC 2 Type I report for the hosting platform is available for the surveyor binder on request from your account contact.

This notice describes product safeguards and is not legal advice; have counsel review before distribution.