Third-Party Vetting & Data Safeguards
We enforce stringent procurement standards for every processing partner integrated into our digital ecosystem. Every vendor undergoes thorough compliance reviews prior to engagement.
Mandatory Safeguard Criteria
- Executed Business Associate Agreements (BAAs) where PHI is involved
- CCPA service-provider addenda for data privacy compliance
- Explicit contractual no-sale and no-independent-use clauses
Cloud Infrastructure & Hosting
Provides secure, encrypted server environments and scalable database instances for core application hosting and clinical data storage.
Executed Business Associate Agreements (BAAs) where PHI is processed, CCPA service-provider addenda, and explicit no-sale/no-independent-use clauses.
Website Analytics
Delivers privacy-first usage telemetry and aggregate performance data to optimize patient user experiences without tracking personally identifiable information.
Privacy-focused IP anonymization, strict CCPA service-provider addenda, zero data monetisation, and explicit no-sale/no-independent-use terms.
Security & Identity Management
Enforces multi-factor authentication, single sign-on (SSO), end-to-end encryption key management, and continuous threat monitoring.
Executed BAAs covering identity token workflows, strict zero-trust access controls, CCPA addenda, and explicit no-sale clauses.
Email & Client Communications
Facilitates transactional notifications, secure automated messaging, and appointment updates to healthcare clients and patients.
Executed BAAs covering transmitted communication data, HIPAA-compliant transport encryption (TLS 1.3), and CCPA service-provider agreements.
Payment/Billing Administration
Processes subscriber invoices, patient billing accounts, and secure payment tokenization in full compliance with financial privacy laws.
PCI-DSS Level 1 certified processors, executed BAAs for medical billing workflows, CCPA service-provider addenda, and strict no-sale restrictions.
Privacy Policy & Protection of personal information
At StratiHealth, operating under VETRI, safeguarding your privacy and protecting sensitive medical and individual data is fundamental to our core mission. We adhere strictly to federal and state health data standards, ensuring that all data shared across California healthcare ecosystems remains confidential, secure, and transparently managed.
This Policy outlines how we collect, handle, store, and disclose data—including Protected Health Information (PHI) and Personally Identifiable Information (PII)—in full compliance with HIPAA, the California Consumer Privacy Act (CCPA), as amended by the CPRA, and applicable California Department of Health Care Services (DHCS) regulations.
Scope of This Privacy Policy
This policy applies universally across all interaction touchpoints within our integrated healthcare ecosystem, specifically covering:
Website Visitors
Individuals accessing our public platforms, portals, and digital health information resources.
Healthcare Partner Organizations
Clinical providers, health plans, and community care teams collaborating via StratiHealth.
CalAIM Program Participants
Beneficiaries receiving Enhanced Care Management (ECM) and Community Supports services.
California Healthcare Ecosystem Commitment
Our platform integrates robust access controls, end-to-end encryption, and rigorous audit protocols engineered specifically for California health systems, managed care plans, and CalAIM initiative partners.
Page Navigation
Jump directly to key sections of our privacy disclosures:
Privacy Inquiries
Have questions regarding your personal health information or data rights?
Contact Privacy OfficerChildren's Privacy
StratiHealth is committed to protecting the privacy of minors and strictly complying with the Children's Online Privacy Protection Act (COPPA). Our digital services and platforms are strictly structured as business-to-business (B2B) solutions designed for healthcare organizations, health plans, and institutional partners.
This website is not directed at, marketed to, or intended for use by individuals under the age of 13. We do not knowingly solicit, collect, or maintain personal information from children through our public website or digital interaction channels.
If we discover or become aware that personal data belonging to a minor under 13 has been inadvertently collected through our site, we will take immediate corrective action to delete that information from our systems upon discovery.
Protected Health Information (PHI) Notice
Protected Health Information (PHI) relating to minor health plan members is handled solely under the Health Insurance Portability and Accountability Act (HIPAA) and applicable Business Associate Agreements (BAAs) with our covered entity partners, and is never gathered or processed through this public website.
How We Use Data
StratiHealth collects and processes data solely for essential operational, clinical, and regulatory purposes. We maintain stringent data protection practices to support high-quality care coordination while safeguarding individual privacy.
StratiHealth does not sell personal information or Protected Health Information (PHI) under any circumstances. All data sharing is strictly restricted to authorized healthcare activities.
Healthcare Operations
Data is utilized to coordinate care delivery, streamline workflows across clinical and administrative teams, support population health management, and ensure continuous quality improvement across healthcare services.
- Health plans
- County agencies
- Contracted healthcare providers
- Regulators
- Vetted service providers
CalAIM Program Execution
Information directly powers Enhanced Care Management (ECM) and Community Supports delivery, including eligibility verification, authorization tracking, social determinants of health (SDOH) assessments, and outcome reporting.
- Managed care plans
- County social services
- Contracted community-based organizations
- Authorized care managers
Legal & Regulatory Compliance
Personal information and Protected Health Information (PHI) are maintained and disclosed in strict alignment with HIPAA, CMIA, state mandates, and federal healthcare oversight standards.
- State and federal regulators
- Healthcare auditing bodies
- Authorized legal representatives
- Compliance officers
Communications & Support
Participant contact information facilitates essential program notifications, care coordination updates, appointment reminders, platform maintenance announcements, and prompt support responses.
- Contracted communications platforms
- Secure messaging gateways
- Dedicated patient care representatives
Site Performance & Security
Technical telemetry and access logs are monitored to safeguard infrastructure integrity, prevent unauthorized access attempt, conduct security audits, and guarantee system availability.
- Internal IT security teams
- Vetted cybersecurity infrastructure providers
- Third-party compliance auditors
Information We Collect
VETRI collects data through two distinct, securely isolated streams to support administrative coordination and compliant healthcare delivery.
Strict Protocol
All transmission uses modern encryption in transit and at rest.
Collected during user onboarding, inquiries, site interaction, and routine business interactions:
Data elements handled in connection with CalAIM referrals and healthcare coordination:
Note: PHI is only received, processed, and stored under a fully executed Business Associate Agreement (BAA) with authorized health plans and provider partners.
HIPAA Business Associate & HITECH Act Alignment
Our platform is built from the ground up to protect Protected Health Information (PHI) and simplify compliance for covered entities and health organizations across every touchpoint.
Business Associate Agreements
We execute formal BAAs with every covered entity and partner before processing any Protected Health Information (PHI), ensuring clear regulatory boundaries.
Minimum-Necessary Standard
System workflows enforce automated data filters so staff and authorization scopes strictly access the minimum necessary information required for tasks.
AES-256 & TLS 1.3 Encryption
All sensitive health records are shielded at rest using AES-256 bit encryption and protected in transit across public networks via TLS 1.3 protocols.
Role-Based Access & Audit Logs
Fine-grained permissions restrict data visibility based on explicit roles, paired with tamper-evident real-time audit logging for every access request.
Breach Notification Obligations
Comprehensive monitoring and incident management protocols ensure immediate assessment and adherence to mandatory HIPAA breach disclosure timelines.
Zero-Sale Health Data Pledge
We maintain a strict zero-sale policy. Your health data and PHI are never sold, rented, monetized, or shared with third-party advertisers.
Data Retention & Security Governance
VETRI maintains healthcare data integrity through defined retention schedules and multi-layered technical security safeguards.
Statutory Healthcare Timelines
Statutory MandatesStrict compliance with federal and state medical record storage regulations, maintaining full audit readiness.
CalAIM-Related Records
7-Year MinimumEnhanced Care Management (ECM) and Community Supports documentation stored for mandatory retention windows.
Contact & Inquiry Data
Active + 2 YearsInquiry forms and correspondence retained to facilitate ongoing partner assistance and compliance tracking.
Purge & Deletion Protocols
Verified DeletionAutomated data elimination workflows triggered upon contract termination or verified deletion requests.
SOC 2-Aligned Controls
Operational and technical framework built to align with rigorous SOC 2 Trust Services Criteria.
Multi-Factor Authentication
Enforced MFA requirements across all administrative systems, workforce endpoints, and portal access.
Encryption in Transit & At Rest
All sensitive data secured with TLS 1.3 protocol during transit and AES-256 standards at rest.
Least-Privilege Access
Role-based access controls restricting data visibility exclusively to authorized, trained personnel.
Continuous System Monitoring
Automated threat detection, continuous log analysis, and system health oversight around the clock.
Workforce HIPAA Training
Mandatory annual security awareness, privacy practices, and data handling instruction for all team members.
Incident Response Protocols
Documented rapid containment workflows, vulnerability remediations, and timely partner notifications.
Your California Privacy Rights
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you specific rights regarding your personal information. Below is a detailed breakdown of these rights and how to exercise them with StratiHealth.
Consumer Rights Overview
You have the right to request that StratiHealth disclose what personal information we collect, use, disclose, and sell or share. This includes the categories of personal information, specific pieces of personal information, sources of collection, business purposes for collecting or sharing, and categories of third parties with whom we share the information. You may submit up to two verifiable requests per 12-month period free of charge.
Do Not Sell or Share My Personal Information
StratiHealth does not sell or share personal information for monetary consideration or cross-context behavioral advertising, and has not done so in the preceding 12 months. We treat your personal data with the strict confidentiality required by California law and healthcare industry standards.
Fulfillment & Verification Procedures
Authorized Agent Requests
You may designate an authorized agent to make a request under the CCPA/CPRA on your behalf. To protect your information, an authorized agent must provide written, signed permission demonstrating authorization, and you must directly verify your identity with StratiHealth, unless the agent holds a valid power of attorney under California Probate Code.
Verifiable Consumer Requests
To process your request to know, delete, or correct, we must first verify your identity. Verification requires matching points of information provided in your request with existing records. We will acknowledge receipt of your request within 10 business days and provide a substantive response within 45 calendar days. If necessary, a single 45-day extension may apply with notice.
Shine the Light (Cal. Civ. Code §1798.83)
California's 'Shine the Light' law allows California residents to request once per calendar year a list of third parties to whom we disclosed personal information for their direct marketing purposes during the preceding year. StratiHealth does not disclose personal information to third parties for direct marketing purposes.
Submit a Privacy Request
We respect your right to control your personal information. Whether you are a California resident exercising statutory privacy rights, a healthcare partner, or a visitor to our platform, you can submit a verifiable privacy request directly to our team.
Need Immediate Assistance?
Our compliance office handles requests within standard business hours.
California Residents (CCPA/CPRA)
Request to know, delete, or correct personal information collected about you, or opt out of data sharing.
Healthcare Partners & Providers
Submit HIPAA inquiries, Business Associate Agreement (BAA) verification, or secure patient record access requests.
Site Visitors & Clients
Inquire about marketing preferences, site cookie settings, or request updates to your profile records.
Mailing Address
StratiHealth Privacy Office, 100 Health Plaza, Suite 400, Los Angeles, CA 90024
Attn: Data Protection Officer