Detecting that a specific patient is losing momentum requires Synarmic to associate program events with the correct patient. That is protected health information under HIPAA, and we treat it accordingly. Synarmic executes a Business Associate Agreement with every clinic before any data is transferred, and handles only the minimum data necessary to produce adherence intelligence for that clinic.
In practice that means program enrollment and status, appointment and follow-up history, lab completion status rather than lab values, refill or fulfillment events, and existing outreach records. We do not request diagnosis narratives, clinical notes, imaging, or billing detail, because none of them are necessary to detect drop-off.
Any separate analysis used to improve our models operates on de-identified data. De-identified data is not PHI under HIPAA, and we keep that environment distinct from the operational workflow described above rather than blurring the two.
Synarmic surfaces a signal, the likely barrier behind it, and a recommended next action drawn from actions your clinic has approved in advance. Clinically consequential signals are routed to your care team for review. Synarmic does not adjust protocols, does not send clinical guidance to patients on its own authority, and does not act on a clinically consequential signal without a human in the loop.
During a pilot engagement we work with the operational and behavioral signals listed above, provided by your clinic under the BAA. This data is used exclusively to generate adherence intelligence for your clinic. It is segregated by tenant, is not pooled with another clinic's data, is never sold, and is not used for any purpose outside your engagement scope. At the end of an engagement, data is returned or destroyed at your direction.
The Synarmic marketing site is hosted on Netlify, which provides TLS encryption in transit and DDoS protection. Netlify maintains its own SOC 2 attestation; that is our vendor's certification and not a Synarmic certification. Synarmic itself is pre-certification, and we will say so plainly rather than imply otherwise. All communications between clients and Synarmic are conducted over encrypted channels. We do not operate unsecured data collection endpoints.
Access to any engagement data is limited to Synarmic personnel directly involved in that engagement. We do not use shared credentials. Engagement data is segmented by client and is not accessible across accounts.
Pilot engagement data is retained for the duration of the engagement and for a period not exceeding 90 days following engagement close, after which it is deleted. Clients may request earlier deletion at any time by contacting us in writing. We will confirm deletion within 30 days of request.
In the unlikely event of a security incident involving clinic-provided data, we will notify affected clients within 72 hours of becoming aware of the incident, provide a written summary of what occurred and what data may have been affected, and cooperate fully with any reasonable investigation.
If you discover a potential security vulnerability in synarmic.com or any Synarmic system, please contact us at compliance@synarmic.com before public disclosure. We are committed to investigating and addressing valid reports promptly.
Security inquiries: compliance@synarmic.com
Synarmic · Orlando, FL