HIPAA & Data Security
Your Privacy, Security, and Trust Matter
At SjöHaven, we understand that managing Sjögren's Syndrome often involves sharing sensitive personal and health-related information. Protecting that information is one of our highest priorities.
This page explains how we approach privacy, security, and regulatory compliance.
1. Our Commitment To Protecting Your Information
SjöHaven was built with privacy and security in mind from the beginning.
We believe that your health information belongs to you, and you should always remain in control of how it is stored, shared, and used.
Our goal is to provide a secure environment where you can confidently track symptoms, manage medications, journal experiences, collaborate with caregivers, and access AI-powered support tools.
2. Is SjöHaven HIPAA Compliant?
The Health Insurance Portability and Accountability Act (HIPAA) establishes standards for protecting certain health information in the United States.
Whether HIPAA applies depends on the specific relationship between healthcare providers, business associates, and technology platforms.
While SjöHaven is designed using many HIPAA-aligned privacy and security principles, SjöHaven is not a healthcare provider and may not be considered a HIPAA Covered Entity.
As our platform evolves, we continuously evaluate regulatory requirements and security best practices to help safeguard user information.
If a future healthcare partnership requires Business Associate Agreements (BAAs), those requirements will be addressed separately.
3. How We Protect Your Data
We implement multiple layers of security designed to help protect your information.
Encryption in Transit
All data transmitted between your device and our systems is encrypted using industry-standard HTTPS/TLS encryption.
This helps prevent unauthorized access while information is being transmitted.
Secure Authentication
User accounts are protected through secure authentication systems designed to reduce unauthorized access.
Security measures may include:
- Strong password requirements
- Email verification
- Secure session management
- Access controls
- Authentication monitoring
Role-Based Access Controls
Access to sensitive information is restricted based on user roles and permissions.
Only authorized individuals may access specific administrative tools or account functions.
Administrative actions are logged and monitored when appropriate.
Data Segregation
Each user's information is isolated and protected through application-level security controls.
Users may only access information associated with their own account unless explicit sharing permissions have been granted.
Secure Infrastructure
SjöHaven utilizes reputable cloud infrastructure providers that maintain industry-standard security programs, monitoring systems, and physical security protections.
4. Your Information Remains Under Your Control
You decide:
- What information to track
- What information to share
- Who can view your information
- When to revoke access
Care Team and caregiver access features are controlled by you and can be modified at any time.
We do not sell your personal information.
5. AI Features and Data Protection
Some SjöHaven features use artificial intelligence to provide insights, summaries, recommendations, and support.
When AI features are used:
- Data is processed only to provide requested functionality
- We work to minimize unnecessary data exposure
- AI responses are generated to support your wellness journey
- AI-generated content is not medical advice
Users should always consult healthcare professionals for diagnosis, treatment decisions, and medical guidance.
6. Community Privacy
SjöHaven may offer community features that allow members to connect and support one another.
Please remember:
- Information shared publicly within community areas may be visible to other members
- You should avoid posting highly sensitive personal information publicly
- You control what you choose to share
We encourage thoughtful participation while protecting your privacy.
7. Data Access and Accountability
Access to user information is limited and controlled.
Administrative access is restricted to authorized personnel who require access to perform operational responsibilities.
Sensitive administrative actions may be logged, including:
- Account modifications
- Permission changes
- Security actions
- Administrative reviews
8. Data Retention
We retain information only as long as necessary to:
- Provide our Services
- Maintain your account
- Comply with legal obligations
- Resolve disputes
- Improve platform functionality
Users may request account deletion in accordance with our Privacy Policy.
9. Security Monitoring
We continuously work to improve security through:
- Software updates
- Infrastructure monitoring
- Access control reviews
- Security best practice implementation
- Risk assessment processes
No online platform can guarantee absolute security, but we are committed to maintaining reasonable safeguards designed to protect your information.
10. Your Privacy Rights
Depending on your location, you may have rights regarding your personal information, including:
- Accessing your information
- Correcting inaccurate information
- Requesting deletion
- Exporting your data
- Managing permissions and sharing settings
For more information, please review our Privacy Policy.
11. Responsible Disclosure
If you believe you have discovered a security vulnerability affecting SjöHaven, please contact us immediately.
We appreciate responsible disclosure and will investigate reports promptly.
Security Contact:
support@sjohaven.com
12. Questions About Security?
If you have questions about privacy, security, or data protection practices, please contact us.
Contact Information
SjöHaven
Website: https://sjohaven.com
Email: support@sjohaven.com
13. Our Promise
We built SjöHaven around a simple belief:
Your health journey is personal, and your information deserves to be treated with care, respect, and security.
We remain committed to protecting your trust every step of the way.