Data Residency and Hosting
Last updated: January 15, 2022
This page explains where Clistahr stores and processes customer data. It is provided for informational purposes to help agencies complete their own security and compliance reviews. It does not modify any agreement between Clistahr Technologies, Inc. ("Clistahr") and a customer. Our Terms of Use and, where applicable, Your subscription agreement and Business Associate Agreement govern the scope of Our obligations, including limitations of liability. Compliance requires professional judgment and regulations change, so agencies should apply their own legal and compliance review.
Summary
All Clistahr customer data is stored and processed in the United States, on Amazon Web Services, in the US East (N. Virginia) region, us-east-1.
Clistahr does not operate data centers outside the United States and does not offer data residency in other countries. There is no residency option to select: every agency's data resides in the same US region.
Hosting Location
Item | Detail |
|---|---|
Cloud provider | Amazon Web Services, Inc. (AWS) |
Region | US East (N. Virginia) — |
Country of storage and processing | United States |
Availability zones | Multiple availability zones within the region, for resilience |
Backup location | US East (Ohio) — |
Alternative regions offered | None. Clistahr is a US-only service. |
AWS Business Associate Addendum | Executed. AWS processes protected health information only in accordance with that addendum. |
AWS is responsible for the physical security of its facilities and the security of the underlying cloud infrastructure. Clistahr is responsible for security of everything it deploys and configures within that infrastructure. Information about AWS data center controls and its compliance certifications is available at https://aws.amazon.com/compliance/data-center/controls/.
What Is Stored in us-east-1
The following data resides in the US East (N. Virginia) region:
- Patient and client records, clinical documentation, care plans, assessments, orders, and progress notes
- Visit records, schedules, and electronic visit verification data, including the device location captured at clock-in and clock-out
- Agency workforce records, including applicant data, credentials and licenses, in-service training records and certificates, leave requests, and timecards
- Documents, photographs, and files uploaded through the web or mobile interfaces
- Payroll and billing data generated within the platform
- User accounts, roles, permissions, and authentication records
- Application audit records showing who accessed or changed a record and when
- Application and infrastructure logs, collected using Amazon CloudWatch
- Encrypted backups and snapshots
Data Flows That Leave the Platform
Some data necessarily travels outside the platform in order to deliver the Service. In every case below, the processing takes place in the United States unless stated otherwise.
Email. Notifications, password expiration reminders, and similar messages are delivered through Amazon Simple Email Service (SES) in the United States. Once a message reaches the recipient's mail provider, delivery and storage are outside Our control.
Push notifications. Mobile push notifications for shifts, visits, and account events are delivered through a push notification provider. Push payloads are limited to non-clinical operational text and do not contain patient information. Device tokens are processed by Firebase Cloud Messaging.
SMS. One-time passcodes and operational messages are delivered through an SMS provider and then through mobile carriers. AWS End User Messaging handles SMS delivery.
Health information exchange integrations. Where an agency enables an integration such as CRISP, the platform transmits the agreed data set to that organization at the agency's instruction. Data handled by the receiving organization is subject to that organization's own policies and agreements.
Other integrations. Where an agency enables an integration with a payer, clearinghouse, e-signature provider, or similar third party, residency for that data depends on the third party. External electronic signature requests are handled by BoldSign.
Access to Data
- Access to production systems is limited to a small number of named Clistahr personnel whose role requires it, protected by multi-factor authentication and reviewed quarterly.
- Standing access to production data is not granted for routine work. Elevated access is time-limited, requires documented approval, and is logged and reviewed after use.
- All access to protected health information is recorded in audit trails that are retained for at least six years.
- Location of personnel with access: Production access is restricted to a small number of named individuals with personal, non-shared accounts, permitted only from IP addresses on an approved allowlist and protected by multi-factor authentication. Access is granted on a least-privilege basis, reviewed periodically, and logged.
Encryption
- Data in transit is encrypted using TLS 1.2 or higher.
- Data at rest — databases, object storage, snapshots, and backups — is encrypted using AWS Key Management Service.
- Encryption keys are managed by Clistahr within AWS KMS, are rotated on a defined schedule, and are never exported to workstations.
Retention and Deletion
Agencies determine how long their records are kept, in line with the recordkeeping obligations that apply to them. Clistahr retains agency data for the term of the agreement and in accordance with the agency's instructions. Audit records relating to access to protected health information are retained for at least six years, as required by 45 CFR 164.316(b)(2).
On termination, the agency may export its data, after which remaining data is returned or destroyed in accordance with the Business Associate Agreement. Residual copies may persist in encrypted backups until they expire on Our standard backup schedule. Data subject to a legal hold is retained until the hold is released.
Full detail is in Our Privacy Policy.
Subprocessors
A current list of subprocessors that may process agency data, including their role and processing location, is available to agencies on request. Where a subprocessor may access protected health information, Clistahr executes a Business Associate Agreement before any access is granted.
Questions
For security questionnaires, a copy of Our Business Associate Agreement, or documentation requests, contact contact@clistahr.com or Your account contact.
See also: Privacy Policy · Terms of Use