1. Introduction
LaPortaCare, Inc. (“LaPortaCare,” “we,” “our,” or “us”) is committed to protecting privacy and safeguarding health information. We operate a secure, Azure-powered, FHIR-native care coordination and interoperability platform that supports hospitals, skilled nursing facilities (SNFs), home health agencies, primary and behavioral care providers, community-based organizations, and health plans.
This Privacy Policy describes how we collect, use, share, and protect information through our website, applications, and related services (“Services”).
2. Information We Collect
A. Information You Provide
- Name
- Email address
- Phone number
- Organization
- Account details
- Demo requests or support inquiries
B. Information Provided by Healthcare Organizations (PHI)
- Care transition documentation
- Admission, discharge, and transfer (ADT) notifications
- Assessments, referrals, and care coordination notes
- SDOH data and PROMs
- Risk indicators and clinical routing information
All PHI is handled in compliance with HIPAA, HITECH, and applicable state privacy laws.
C. Automatically Collected Information
- IP address
- Browser type
- Device identifiers
- Platform activity
- Cookies used for functionality, performance, and security (not advertising)
3. How We Use Information
- Deliver, operate, and improve the LaPortaCare platform
- Facilitate secure care transitions and interoperability
- Support compliance with CMS, ONC, DxF, and state-level data sharing requirements
- Provide customer support and respond to requests
- Monitor system performance and maintain security
- Conduct de-identified or aggregated analytics
- Comply with applicable legal and contractual obligations
LaPortaCare does not sell personal information or PHI.
4. How We Share Information
- Authorized healthcare organizations involved in care delivery
- Business associates under HIPAA-compliant agreements
- Technology providers such as Microsoft Azure
- Regulatory entities when legally required
We do not share information for marketing or unrelated commercial purposes.
5. Data Residency & Access Controls
- All PHI and PII are stored and processed exclusively within Microsoft Azure U.S. regions.
- Role-based access controls and least-privilege principles restrict who may access PHI.
- All access is logged, monitored, and governed by HIPAA-aligned safeguards.
- We do not transfer PHI outside the United States.
6. Security Measures
- Zero-trust architecture
- MFA and SSO (SAML/OIDC)
- Encryption in transit (TLS 1.2/1.3)
- Encryption at rest (AES-256)
- Azure Key Vault–based encryption key management
- Continuous monitoring and audit logging
- Secure software development lifecycle (SSDLC)
- SOC 2–aligned administrative and technical controls
LaPortaCare is not yet SOC 2 certified; however, our platform implements SOC 2–aligned practices.
7. Compliance Alignment
- HIPAA & HITECH
- CMS Interoperability & Patient Access Final Rule
- ONC 21st Century Cures Act
- USCDI standards
- Federal Information Blocking requirements
- California Data Exchange Framework (DxF)
- State-level HIE and ADT event notification requirements
Each organization remains responsible for its own regulatory compliance obligations.
8. Intellectual Property Protection
All platform content—including text, workflows, diagrams, architecture, descriptions, UI/UX components, terminology, visuals, data models, and care coordination logic—is proprietary to LaPortaCare, Inc.
You may not:
- Copy, imitate, replicate, or recreate LaPortaCare content
- Produce look-alike or functionally similar materials
- Paraphrase or derive versions using manual or AI methods
- Reverse engineer, scrape, extract, or analyze platform architecture
- Use LaPortaCare content for competitive positioning or imitation
Unauthorized use may violate:
- U.S. Copyright Law
- DMCA
- Trademark & Trade Dress laws
- Unfair competition statutes
LaPortaCare enforces its intellectual property rights to the fullest extent permitted by law.
9. Your Privacy Rights
- Access to certain personal information
- Correction or updates
- Deletion (when permissible)
- Information about how your data is used
Requests related to PHI must be submitted directly to the healthcare provider or payer responsible for that data.
10. Children’s Privacy
Our Services are intended for use by healthcare professionals and organizations, not children under the age of 13.
11. Policy Updates
We may update this Privacy Policy periodically. The “Effective Date” at the top of this page reflects the current version.
12. Contact Us
For privacy-related questions, compliance inquiries, or data rights requests:
LaPortaCare, Inc.
privacy@laportacare.com