Privacy Policy
Learn how Sigma Health collects, uses, protects, and handles your clinical and organizational data in accordance with global healthcare security standards.
Our Healthcare Data Protection Pledge
Sigma Health operates as a trusted software platform for healthcare clinics and institutions. We never sell, license, or monetize your clinic or patient data. Your clinical records remain 100% your property and are isolated within encrypted, tenant-restricted environments.
1. Information We Collect
To provide our cloud-based Hospital Management Information System (HMIS), Sigma Health collects information necessary to create user accounts, manage clinic subscriptions, and enable healthcare workflows.
1.1 Account & Contact Information
When clinic administrators register an organization or invite staff members, we collect names, professional email addresses, telephone numbers, clinical roles, and billing parameters.
1.2 Clinical & Operational Data (Customer Data)
Authorized clinic personnel input clinical data onto the platform, including patient demographics, encounter notes, diagnoses, prescriptions, billing records, inventory transactions, and insurance claims. This data is handled strictly on behalf of the customer organization.
1.3 Telemetry & System Diagnostics
We automatically log system interaction metrics, such as IP addresses, browser specifications, login activity timestamps, request error codes, and audit logs required for security monitoring.
2. How We Use Information
We use collected information exclusively for the operation, maintenance, security, and improvement of the Sigma HMIS platform.
- Core Service Delivery: Processing patient visits, pharmacy dispensations, appointment scheduling, billing invoices, and e-claims workflows requested by clinic personnel.
- Security & Compliance Auditing: Maintaining audit trails for medical data access, verifying user permissions, and detecting suspicious login activity.
- Customer Communications: Sending operational notices, system maintenance alerts, password resets, and critical compliance updates.
- System Optimization: Monitoring system latency and application bugs to maintain peak uptime across operating clinics.
4. Data Security
Healthcare information requires high security standards. We enforce stringent technical and organizational controls to protect customer data against unauthorized access, disclosure, or alteration.
AES-256 Encryption
All database backups and stored files encrypted at rest.
TLS 1.3 Transport
All web network requests protected via HTTPS TLS 1.3.
Strict RBAC Controls
Role-based access checks enforced on every backend request.
5. Data Retention
We retain customer clinical data for the duration of an active subscription agreement. Upon account termination:
- Grace Period: Clinic administrators are provided a 30-day window to export full patient, clinical, and financial records in standard data formats.
- Permanent Deletion: Following the 30-day grace period, active databases are purged of tenant data. Encrypted backup archives are overwritten according to our standard 90-day rolling rotation.
6. Third-Party Services
Sigma Health relies on audited third-party sub-processors to fulfill infrastructure requirements (such as cloud hosting, transactional email delivery, and regional insurance claim submission gateways).
All sub-processors are bound by Data Processing Agreements (DPAs) that mandate security and confidentiality protections equivalent to our own standard.
7. International Data Transfers
Sigma Health operates high-availability data centers across multiple regions. Where cross-border data transfers occur, we implement recognized legal transfer mechanisms, including Standard Contractual Clauses (SCCs) and regional health data protection compliance protocols.
8. User & Patient Rights
Depending on your jurisdiction, organizations and individual users hold specific privacy rights regarding their data:
Right to Access & Export: Clinic admins can export complete clinical dataset logs at any time via the administrative reporting interface.
Right to Rectification: Authorized clinical staff can correct or update patient demographic information directly in the master patient index.
Patient Inquiries: Patients requesting medical record modifications should contact their healthcare provider directly, as Sigma acts as a data processor for operating clinics.
9. Children's Privacy
Sigma Health HMIS software accounts are restricted to licensed healthcare organizations and adult medical personnel. Pediatric patient health data managed within the system by healthcare providers is subject to strict guardian consent requirements governed by the treating medical institution.
10. Changes to This Policy
We may update this Privacy Policy periodically to reflect technological or regulatory modifications. When material updates are made, registered clinic administrators will receive notification via email or an in-app banner 30 days prior to the effective date.
11. Contact Information
If you have questions, privacy inquiries, or data protection concerns regarding this policy, please reach out to our dedicated Data Protection Officer:
Email Privacy Team
privacy@sigmaconnect.orgOrganization
Sigma Health Technologies Inc.
Attn: Data Protection Office