Learn how Sigma Health collects, uses, protects, and handles your clinical and organizational data in accordance with global healthcare security standards.
Sigma Health operates as a trusted software platform for healthcare clinics and institutions. We never sell, license, or monetize your clinic or patient data. Your clinical records remain 100% your property and are isolated within encrypted, tenant-restricted environments.
To provide our cloud-based Hospital Management Information System (HMIS), Sigma Health collects information necessary to create user accounts, manage clinic subscriptions, and enable healthcare workflows.
When clinic administrators register an organization or invite staff members, we collect names, professional email addresses, telephone numbers, clinical roles, and billing parameters.
Authorized clinic personnel input clinical data onto the platform, including patient demographics, encounter notes, diagnoses, prescriptions, billing records, inventory transactions, and insurance claims. This data is handled strictly on behalf of the customer organization.
We automatically log system interaction metrics, such as IP addresses, browser specifications, login activity timestamps, request error codes, and audit logs required for security monitoring.
We use collected information exclusively for the operation, maintenance, security, and improvement of the Sigma HMIS platform.
Healthcare information requires high security standards. We enforce stringent technical and organizational controls to protect customer data against unauthorized access, disclosure, or alteration.
All database backups and stored files encrypted at rest.
All web network requests protected via HTTPS TLS 1.3.
Role-based access checks enforced on every backend request.
We retain customer clinical data for the duration of an active subscription agreement. Upon account termination:
Sigma Health relies on audited third-party sub-processors to fulfill infrastructure requirements (such as cloud hosting, transactional email delivery, and regional insurance claim submission gateways).
All sub-processors are bound by Data Processing Agreements (DPAs) that mandate security and confidentiality protections equivalent to our own standard.
Sigma Health operates high-availability data centers across multiple regions. Where cross-border data transfers occur, we implement recognized legal transfer mechanisms, including Standard Contractual Clauses (SCCs) and regional health data protection compliance protocols.
Depending on your jurisdiction, organizations and individual users hold specific privacy rights regarding their data:
Right to Access & Export: Clinic admins can export complete clinical dataset logs at any time via the administrative reporting interface.
Right to Rectification: Authorized clinical staff can correct or update patient demographic information directly in the master patient index.
Patient Inquiries: Patients requesting medical record modifications should contact their healthcare provider directly, as Sigma acts as a data processor for operating clinics.
Sigma Health HMIS software accounts are restricted to licensed healthcare organizations and adult medical personnel. Pediatric patient health data managed within the system by healthcare providers is subject to strict guardian consent requirements governed by the treating medical institution.
We may update this Privacy Policy periodically to reflect technological or regulatory modifications. When material updates are made, registered clinic administrators will receive notification via email or an in-app banner 30 days prior to the effective date.
If you have questions, privacy inquiries, or data protection concerns regarding this policy, please reach out to our dedicated Data Protection Officer:
Email Privacy Team
privacy@sigmaconnect.orgOrganization
Sigma Health Technologies Inc.
Attn: Data Protection Office