1. Who We Are
STFE Systems Inc. ("STFE," "we," "our," or "us") is a healthcare technology company incorporated in Delaware, USA, with engineering operations in Chennai, India. We operate a deterministic clinical admission decision engine for Skilled Nursing Facilities (SNFs) and Critical Access Hospitals (CAHs) accessible at health.stfe.io and via API.
For purposes of HIPAA, STFE is a Business Associate to Covered Entities (healthcare facilities) that use our platform. We are not a Covered Entity ourselves.
Contact: privacy@stfe.io | STFE Systems Inc., 8 The Green Suite R, Dover, Delaware 19901, USA
2. Information We Collect
A. Account & Facility Information (Collected Directly)
- Name, email address, job title, and NPI number of facility staff who create accounts
- Facility name, address, facility type (SNF/CAH), CMS Certification Number (CCN)
- Billing and payment information (processed by a PCI-DSS compliant third party — we never store raw card numbers)
- Configuration preferences set by the Director of Nursing (clinical thresholds, capability flags)
B. Clinical Data (Processed on Behalf of Facilities — Governed by BAA)
- De-identified or PHI-containing patient clinical data submitted by facility staff for admission evaluation
- Admission decision records, clinical constraint evaluation results, and audit logs
- MDS assessment pre-population data generated from intake evaluations
Clinical data is processed under our Business Associate Agreement (BAA). Facilities are the Data Controllers for all PHI they submit. STFE is the Data Processor/Business Associate.
C. Usage Data (Collected Automatically)
- Log data: IP addresses, browser type, pages accessed, timestamps
- Session information (authentication tokens — stored in memory only, never persisted)
- Application performance metrics (error rates, response times — no patient data included)
We do not use advertising cookies, cross-site tracking, or behavioral analytics tools. We use only essential operational cookies.
3. How We Use Information
- Platform Operation: To provide the STFE clinical decision engine, generate audit records, and deliver reports
- Clinical Governance: To enforce facility-configured clinical thresholds and maintain the DON governance sign-off chain
- Security: To detect unauthorized access, maintain audit trails, and generate SHA-256 tamper-evident integrity records
- Support: To respond to technical support requests and resolve platform issues
- Compliance: To fulfill our legal obligations under HIPAA, applicable state laws, and our BAA obligations
- Platform Improvement: Aggregated, de-identified usage patterns to improve clinical constraint accuracy (never individual patient data)
We never use clinical data for advertising, sell data to third parties, or use patient information for any purpose outside of operating the platform for the facility that submitted it.
4. HIPAA & Protected Health Information
STFE operates as a HIPAA Business Associate. All PHI submitted through the platform is:
- Encrypted in transit (TLS 1.3) and at rest (AES-256) on AWS HIPAA-eligible infrastructure
- Accessible only to authorized facility staff through role-based access controls
- Subject to a Business Associate Agreement (BAA) signed with each customer facility
- Never retained beyond the terms specified in the BAA
- Auditable via SHA-256 hash-sealed, immutable audit records on every evaluation
To request a BAA or to report a potential HIPAA violation, contact: compliance@stfe.io
5. Data Sharing
We share information only in the following limited circumstances:
- With your facility's authorized users: Clinical records are accessible only to authenticated staff at your facility
- With subprocessors: AWS (infrastructure, HIPAA-eligible), Stripe (payment processing, no PHI), Datadog (performance monitoring, no PHI). Full subprocessor list available on request.
- As required by law: In response to valid legal process (subpoena, court order) after notifying the affected facility where legally permitted
- In a business transfer: If STFE is acquired, clinical data transfers only with customer consent and appropriate BAA assignment
We never sell, rent, or trade personal data or clinical data to any third party for any purpose.
6. Data Retention
- Audit records (case evaluations): 7 years from date of evaluation, consistent with CMS medical record requirements
- Account data: Duration of the customer relationship + 2 years, then deleted
- Shadow audit data: 90 days unless exported or incorporated into a case record
- Application logs: 90 days rolling retention
You may request earlier deletion of non-PHI account data by contacting privacy@stfe.io. PHI retention is governed by the BAA and applicable law.
7. Your Rights
For facility administrators and staff:
- Access: Request a copy of your account data
- Correction: Update your account information through the platform settings
- Deletion: Request deletion of your account data (subject to legal retention requirements)
- Data portability: Request an export of your facility's evaluation records in a structured format
For patients: Patient rights regarding PHI are exercised through your healthcare facility (the Covered Entity), not directly through STFE. Contact the facility that submitted your information.
For California residents (CCPA): You have the right to know what personal information we collect, request deletion, and opt out of sale (we do not sell data). Submit requests to privacy@stfe.io.
8. Security
STFE maintains a comprehensive information security program including:
- SOC 2 Type II — independent audit in progress
- Penetration testing by independent security firms (annual)
- All data encrypted at rest (AES-256) and in transit (TLS 1.3)
- Multi-factor authentication required for all administrative access
- SHA-256 tamper-evident hash-sealing of all clinical audit records (tamper-evident)
- Access controls: role-based, least-privilege, with full audit logging
- Incident response plan with 72-hour notification for breaches affecting PHI
To report a security vulnerability: security@stfe.io
9. International Data Transfers
STFE's engineering team operates from Chennai, India. All production data and PHI remains on AWS infrastructure in the us-east-1 (N. Virginia) region and does not leave the United States. Engineering access to production systems is restricted and logged.
10. Children's Privacy
STFE is a B2B healthcare platform designed for use by licensed healthcare professionals. We do not knowingly collect information from individuals under the age of 18. The platform is not directed at minors.
11. Changes to This Policy
We will notify registered users by email at least 30 days before any material changes to this Privacy Policy. The "Last Updated" date at the top of this page reflects the most recent revision. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
12. Contact
- Privacy questions: privacy@stfe.io
- HIPAA / BAA: compliance@stfe.io
- Security: security@stfe.io
- Mailing address: STFE Systems Inc., 8 The Green Suite R, Dover, Delaware 19901, USA