Smart HMS
CapabilitiesModulesPlatformPricingFAQ
Log inBook a demo
CapabilitiesModulesPlatformPricingFAQ
Log in to Hospital PortalBook a live demo
Home/Legal & Trust/Privacy Policy & Data Protection

Privacy Policy & Data Protection

How Smart HMS protects Protected Health Information (ePHI), hospital telemetry, clinician credentials, and organizational records.

Effective: September 16, 2026Version 2.4
On This Page
1. Overview & Scope2. Controller vs Processor Roles3. Categories of Data Collected4. PHI & Clinical Data Safeguards5. Biometric & ZKTeco Data6. Hosting & Sub-processors7. Data Retention & Deletion8. Data Subject Rights9. Data Protection Officer
Legal CenterPrivacy Policy •Terms of Service HIPAA & Security SLA & Uptime Policy

Healthcare Data Governance Notice

Smart HMS is engineered strictly for hospital administration, clinical EHR/EMR recording, pharmacy lot tracking, and financial reconciliation. We adhere to the Health Insurance Portability and Accountability Act (HIPAA), General Data Protection Regulation (GDPR), and industry-standard data sovereignty standards.

1. Overview & Scope

This Privacy Policy governs the collection, processing, transmission, and archival of information by StatGenTech LLC (“Smart HMS”, “we”, “us”, or “our”) in connection with our multi-tenant Hospital Management System, web portals, offline-first mobile applications, and desktop command centres.

This policy applies to all healthcare facilities (“Customers”, “Tenants”), including hospitals, specialized clinics, diagnostic labs, and authorized users (doctors, nurses, administrative personnel, pharmacists, and accountants).

2. Customer Controller vs. Smart HMS Processor Role

Under applicable data protection frameworks (including GDPR Art. 28 and HIPAA 45 CFR § 164.502):

  • The Customer (Hospital/Clinic) is the Data Controller / Covered Entity: You determine the legal basis for processing patient health information, obtain necessary patient consents, and manage internal clinical data governance.
  • Smart HMS is the Data Processor / Business Associate: We process customer data exclusively on documented instructions from the Customer, for the sole purpose of delivering the HMS software services. We never sell, monetize, broker, or train public AI models on Customer patient data.

3. Categories of Data Collected

In operating the platform, Smart HMS processes the following datasets:

  • Administrative Account Data: Hospital corporate name, licensing numbers, tax ID, billing contact details, staff credentials, and role permissions.
  • Electronic Health Records & Clinical Data (ePHI): Patient identifiers (name, age, gender, blood group, contact), OPD consultation notes, IPD bed allocations, vital sign recordings, laboratory pathology/radiology reports, surgical notes, and electronic prescriptions.
  • Financial & Billing Records: Invoices, thermal receipt records, insurance ledger claims, deposit payments, corporate credit approvals, and tax tallies.
  • System Audit Trails & Telemetry: Immutable audit logs recording user ID, IP address, timestamp, device identifier, and specific records created, viewed, updated, or deleted.

4. Protected Health Information (PHI) & Security Safeguards

To safeguard ePHI against unauthorized access, destruction, or interception, Smart HMS implements multi-layered defence-in-depth security:

  • Encryption in Transit: All HTTP and WebSocket communications enforce TLS 1.3 with strict HTTP Strict Transport Security (HSTS).
  • Encryption at Rest: Database volumes, file stores, and automated snapshot archives are encrypted using FIPS 140-2 validated AES-256 encryption.
  • Multi-Tenant Logical Isolation: Data rows are partitioned using PostgreSQL Row-Level Security (RLS) keyed by tenant ID, preventing cross-tenant data leakage.
  • Granular Access Control: Strict Role-Based Access Control (RBAC) ensures staff members only view data required for their clinical or operational duty.

5. Biometric Data & ZKTeco Device Integration

Smart HMS provides seamless ADMS bridge synchronization with physical biometric devices (such as ZKTeco time & attendance terminals).

Biometric Privacy Affirmation: Raw biometric fingerprint templates or facial scan geometry remain on your local device hardware or local gateway. Smart HMS only receives and stores the alphanumeric employee ID, terminal timestamp, and punch verification status for shift and payroll compilation.

6. Infrastructure & Sub-processors

We partner with world-class cloud infrastructure providers that maintain SOC 1/2/3, ISO 27001, and HIPAA compliance certifications (e.g., AWS, Google Cloud Platform, Supabase Enterprise). All sub-processors are bound by strict Business Associate Agreements (BAAs) and Data Processing Agreements (DPAs). Customers may request our current sub-processor registry at any time.

7. Data Retention, Export & Deletion

  • Statutory Retention: Customers acknowledge that hospital records and medical histories may be subject to mandatory legal retention periods (e.g., 7–10 years depending on jurisdiction).
  • Data Portability: Customers can export patient registries, billing ledgers, and diagnostic reports in standard machine-readable formats (JSON, CSV, PDF) at any time.
  • Post-Termination Purge: Upon contract termination, Customer data is preserved for a 60-day grace period for full export, after which all primary databases and backups are cryptographically destroyed.

8. Data Subject Rights (GDPR & Local Privacy Laws)

Where applicable, patients have rights to inspect, amend, or request an accounting of disclosures of their health records. Because Smart HMS operates as a data processor, any patient request received directly by Smart HMS will be promptly redirected to the respective Hospital Administrator for verification and execution.

9. Data Protection Officer & Inquiries

For inquiries regarding our HIPAA privacy safeguards, security certifications, or to execute a Business Associate Agreement (BAA), contact our Data Protection Team:

Office of the Data Protection Officer (DPO)
Smart HMS / StatGenTech Compliance Group
Email: privacy@smarthms.com
Security Inquiries: security@smarthms.com
Direct Response Time: Within 2 business days
Smart HMS

A cloud, multi-tenant hospital management system - one command centre for every patient, appointment and clinical decision.

Product

CapabilitiesModulesPricingBook a demo

Modules

Outpatient & inpatientPharmacyBilling & financeHR & attendance

Access

Log inFAQRequest Demo

Legal & Trust

Privacy PolicyTerms of ServiceHIPAA & ComplianceSLA & Uptime
© 2026 StatGenTech · Smart HMS. All rights reserved.
Privacy Policy·Terms of Service·HIPAA & Security·SLA & Uptime
NestJS · Prisma · PostgreSQL · Next.js · Flutter · Electron · ZKTeco ADMS