← Back to chartguard.polsia.app
HIPAA Compliant
NY SHIELD Act
No PHI Stored

1. Who We Are

ChartGuard is an AI-powered EMS PCR narrative analysis service operated by Polsia. Our platform analyzes patient care report (PCR) narratives to help EMS agencies identify documentation gaps, billing deficiencies, and QA/QI issues before claims are denied.

Contact: privacy@polsia.app · chartguard.polsia.app

2. What We Collect

Account information

When you register, we collect your email address and (optionally) your name. Payment processing is handled entirely by Stripe; we do not store credit card numbers.

Narrative data and HIPAA architecture

Critical design principle: ChartGuard does not store the content of your PCR narratives. When you submit a narrative for analysis, we compute a SHA-256 cryptographic hash of the narrative text and store only that hash alongside your user ID, timestamp, and document hash. The original narrative text never leaves your device and is never persisted to our servers.

We store: SHA-256 hashes (not content), timestamps, user IDs, document metadata hashes, and analysis scores (billing readiness, QA/QI). No patient names, DOBs, addresses, SSNs, diagnosis codes, or treatment details are ever stored.

Analytics

We collect anonymized usage analytics via a first-party beacon (polsia.com/api/beacon). This tracks page views and session identifiers for product improvement only. It does not collect or associate any PHI.

3. How We Use Your Data

We do not use your submitted narratives to train or fine-tune AI models. AWS Bedrock HIPAA-eligible infrastructure is used; no customer data is used for model training under any circumstances.

4. Data Retention

Narrative content is never retained. Only SHA-256 hashes and audit metadata are kept for regulatory compliance purposes. Audit logs are retained as long as your account is active, plus 7 years for HIPAA compliance.

When you delete your account, all data associated with your account is permanently removed within 30 days. This is your right to erasure under NY SHIELD Act.

5. Third-Party Sharing

We do not sell, rent, or share your data with third parties for marketing purposes. Data shared with third parties is limited to:

6. Your Rights

You have the right to:

To exercise your right to erasure, contact privacy@polsia.app or use the account deletion feature in the app. Deletion completes within 30 days.

7. Cookies

We use session cookies (httpOnly, sameSite=strict, secure in production) to maintain your authenticated session. These are essential for authentication and cannot be disabled without logging you out.

Analytics cookies are first-party only and do not track PHI. They can be opted out by contacting privacy@polsia.app.

8. Data Security

We implement:

9. HIPAA Compliance

ChartGuard is built on HIPAA-eligible AWS infrastructure. A Business Associate Agreement (BAA) is included with every paid plan. We do not access, use, or disclose Protected Health Information (PHI) beyond what is necessary to provide the analysis service. No model training occurs on any customer data.

10. NY SHIELD Act Compliance

ChartGuard complies with the New York SHIELD Act and NYDPA. We maintain reasonable administrative, technical, and physical safeguards for personal information. A data breach notification will be provided to affected users within 72 hours of discovery, as required by law.

11. Changes to This Policy

We will notify users of material changes to this policy via email and a notice on the platform. Material changes take effect 30 days after notice.

12. Contact

For privacy concerns, data deletion requests, or BAA requests: privacy@polsia.app