Vendor Compliance & Governance

Third-Party Vetting & Data Safeguards

We enforce stringent procurement standards for every processing partner integrated into our digital ecosystem. Every vendor undergoes thorough compliance reviews prior to engagement.

Mandatory Safeguard Criteria

  • Executed Business Associate Agreements (BAAs) where PHI is involved
  • CCPA service-provider addenda for data privacy compliance
  • Explicit contractual no-sale and no-independent-use clauses

Cloud Infrastructure & Hosting

SOC 2 Type II
Purpose & Role

Provides secure, encrypted server environments and scalable database instances for core application hosting and clinical data storage.

Contractual Safeguards

Executed Business Associate Agreements (BAAs) where PHI is processed, CCPA service-provider addenda, and explicit no-sale/no-independent-use clauses.

Website Analytics

HIPAA Compliant Setup
Purpose & Role

Delivers privacy-first usage telemetry and aggregate performance data to optimize patient user experiences without tracking personally identifiable information.

Contractual Safeguards

Privacy-focused IP anonymization, strict CCPA service-provider addenda, zero data monetisation, and explicit no-sale/no-independent-use terms.

Security & Identity Management

Zero-Trust Framework
Purpose & Role

Enforces multi-factor authentication, single sign-on (SSO), end-to-end encryption key management, and continuous threat monitoring.

Contractual Safeguards

Executed BAAs covering identity token workflows, strict zero-trust access controls, CCPA addenda, and explicit no-sale clauses.

Email & Client Communications

Encrypted Transport
Purpose & Role

Facilitates transactional notifications, secure automated messaging, and appointment updates to healthcare clients and patients.

Contractual Safeguards

Executed BAAs covering transmitted communication data, HIPAA-compliant transport encryption (TLS 1.3), and CCPA service-provider agreements.

Payment/Billing Administration

PCI-DSS Level 1
Purpose & Role

Processes subscriber invoices, patient billing accounts, and secure payment tokenization in full compliance with financial privacy laws.

Contractual Safeguards

PCI-DSS Level 1 certified processors, executed BAAs for medical billing workflows, CCPA service-provider addenda, and strict no-sale restrictions.

Data Protection & Compliance

Privacy Policy & Protection of personal information

At StratiHealth, operating under VETRI, safeguarding your privacy and protecting sensitive medical and individual data is fundamental to our core mission. We adhere strictly to federal and state health data standards, ensuring that all data shared across California healthcare ecosystems remains confidential, secure, and transparently managed.

This Policy outlines how we collect, handle, store, and disclose data—including Protected Health Information (PHI) and Personally Identifiable Information (PII)—in full compliance with HIPAA, the California Consumer Privacy Act (CCPA), as amended by the CPRA, and applicable California Department of Health Care Services (DHCS) regulations.

Scope of This Privacy Policy

This policy applies universally across all interaction touchpoints within our integrated healthcare ecosystem, specifically covering:

Scope 01

Website Visitors

Individuals accessing our public platforms, portals, and digital health information resources.

Scope 02

Healthcare Partner Organizations

Clinical providers, health plans, and community care teams collaborating via StratiHealth.

Scope 03

CalAIM Program Participants

Beneficiaries receiving Enhanced Care Management (ECM) and Community Supports services.

California Healthcare Ecosystem Commitment

Our platform integrates robust access controls, end-to-end encryption, and rigorous audit protocols engineered specifically for California health systems, managed care plans, and CalAIM initiative partners.

Effective Date: January 1, 2025
Last Updated: January 15, 2025

Privacy Inquiries

Have questions regarding your personal health information or data rights?

Contact Privacy Officer
Compliance & Privacy Notice

Children's Privacy

StratiHealth is committed to protecting the privacy of minors and strictly complying with the Children's Online Privacy Protection Act (COPPA). Our digital services and platforms are strictly structured as business-to-business (B2B) solutions designed for healthcare organizations, health plans, and institutional partners.

This website is not directed at, marketed to, or intended for use by individuals under the age of 13. We do not knowingly solicit, collect, or maintain personal information from children through our public website or digital interaction channels.

If we discover or become aware that personal data belonging to a minor under 13 has been inadvertently collected through our site, we will take immediate corrective action to delete that information from our systems upon discovery.

Protected Health Information (PHI) Notice

Protected Health Information (PHI) relating to minor health plan members is handled solely under the Health Insurance Portability and Accountability Act (HIPAA) and applicable Business Associate Agreements (BAAs) with our covered entity partners, and is never gathered or processed through this public website.

Data Governance & Privacy

How We Use Data

StratiHealth collects and processes data solely for essential operational, clinical, and regulatory purposes. We maintain stringent data protection practices to support high-quality care coordination while safeguarding individual privacy.

Non-Commercial Commitment

StratiHealth does not sell personal information or Protected Health Information (PHI) under any circumstances. All data sharing is strictly restricted to authorized healthcare activities.

Healthcare Operations

Data is utilized to coordinate care delivery, streamline workflows across clinical and administrative teams, support population health management, and ensure continuous quality improvement across healthcare services.

Permitted Recipients
  • Health plans
  • County agencies
  • Contracted healthcare providers
  • Regulators
  • Vetted service providers

CalAIM Program Execution

Information directly powers Enhanced Care Management (ECM) and Community Supports delivery, including eligibility verification, authorization tracking, social determinants of health (SDOH) assessments, and outcome reporting.

Permitted Recipients
  • Managed care plans
  • County social services
  • Contracted community-based organizations
  • Authorized care managers

Legal & Regulatory Compliance

Personal information and Protected Health Information (PHI) are maintained and disclosed in strict alignment with HIPAA, CMIA, state mandates, and federal healthcare oversight standards.

Permitted Recipients
  • State and federal regulators
  • Healthcare auditing bodies
  • Authorized legal representatives
  • Compliance officers

Communications & Support

Participant contact information facilitates essential program notifications, care coordination updates, appointment reminders, platform maintenance announcements, and prompt support responses.

Permitted Recipients
  • Contracted communications platforms
  • Secure messaging gateways
  • Dedicated patient care representatives

Site Performance & Security

Technical telemetry and access logs are monitored to safeguard infrastructure integrity, prevent unauthorized access attempt, conduct security audits, and guarantee system availability.

Permitted Recipients
  • Internal IT security teams
  • Vetted cybersecurity infrastructure providers
  • Third-party compliance auditors
HIPAA & CMIA Compliant Infrastructure
Updated Annually for State Policy Alignment
Privacy & Transparency

Cookies & Tracking Policy

StratiHealth uses cookies and similar measurement technologies to ensure system integrity, preserve user preferences, and analyze aggregate performance. Below is a breakdown of how technologies are deployed across our services.

Strictly necessary for security, session maintenance, user authentication, and passcode gate states. These cookies enable core site functionality and cannot be disabled.

Cookie Purpose
Session, Security & Authentication
Duration
Session to 12 Months
Type
First-Party (Strictly Necessary)

Managing Preferences & Browser Settings

Most web browsers allow you to manage cookie settings through their preferences menu. You can set your browser to block or alert you about cookies, but blocking essential cookies may impair core functionality, login states, and secure form submissions across our portal.

Global Privacy Control (GPC)

Our systems detect and automatically honor Global Privacy Control (GPC) browser signals as valid opt-out requests for non-essential tracking technologies.

No Behavioral Ad Tracking

StratiHealth does not utilize cross-context behavioral advertising trackers, sell personal data, or build user profiling databases for third-party advertisers.

Have questions about our data practices?
Contact Privacy Office
Data Privacy & Compliance

Information We Collect

VETRI collects data through two distinct, securely isolated streams to support administrative coordination and compliant healthcare delivery.

Strict Protocol

All transmission uses modern encryption in transit and at rest.

Privacy Inquiries
Personal & Professional Identifiers

Collected during user onboarding, inquiries, site interaction, and routine business interactions:

Full name & job title
Organization & department
National Provider Identifier (NPI)
Business email & phone number
IP address & geolocation data
Device & browser metadata
Portal login credentials
Form submissions & inquiries
Protected Health Information (PHI)

Data elements handled in connection with CalAIM referrals and healthcare coordination:

Member & patient identifiers
Dates of birth & intake dates
Health plan & member ID numbers
CalAIM claim & referral metadata
Diagnosis codes & clinical status
Client Access Portal clinical notes

Note: PHI is only received, processed, and stored under a fully executed Business Associate Agreement (BAA) with authorized health plans and provider partners.

HIPAA & HITECH Compliant Infrastructure

HIPAA Business Associate & HITECH Act Alignment

Our platform is built from the ground up to protect Protected Health Information (PHI) and simplify compliance for covered entities and health organizations across every touchpoint.

Business Associate Agreements

We execute formal BAAs with every covered entity and partner before processing any Protected Health Information (PHI), ensuring clear regulatory boundaries.

Minimum-Necessary Standard

System workflows enforce automated data filters so staff and authorization scopes strictly access the minimum necessary information required for tasks.

AES-256 & TLS 1.3 Encryption

All sensitive health records are shielded at rest using AES-256 bit encryption and protected in transit across public networks via TLS 1.3 protocols.

Role-Based Access & Audit Logs

Fine-grained permissions restrict data visibility based on explicit roles, paired with tamper-evident real-time audit logging for every access request.

Breach Notification Obligations

Comprehensive monitoring and incident management protocols ensure immediate assessment and adherence to mandatory HIPAA breach disclosure timelines.

Zero-Sale Health Data Pledge

We maintain a strict zero-sale policy. Your health data and PHI are never sold, rented, monetized, or shared with third-party advertisers.

Compliance & Safeguards

Data Retention & Security Governance

VETRI maintains healthcare data integrity through defined retention schedules and multi-layered technical security safeguards.

Data Retention
Defined archival timelines and contract termination purge policies for healthcare records.
  • Statutory Healthcare Timelines

    Statutory Mandates

    Strict compliance with federal and state medical record storage regulations, maintaining full audit readiness.

  • CalAIM-Related Records

    7-Year Minimum

    Enhanced Care Management (ECM) and Community Supports documentation stored for mandatory retention windows.

  • Contact & Inquiry Data

    Active + 2 Years

    Inquiry forms and correspondence retained to facilitate ongoing partner assistance and compliance tracking.

  • Purge & Deletion Protocols

    Verified Deletion

    Automated data elimination workflows triggered upon contract termination or verified deletion requests.

Security Safeguards
Technical, administrative, and physical controls enforcing continuous data protection.
  • SOC 2-Aligned Controls

    Operational and technical framework built to align with rigorous SOC 2 Trust Services Criteria.

  • Multi-Factor Authentication

    Enforced MFA requirements across all administrative systems, workforce endpoints, and portal access.

  • Encryption in Transit & At Rest

    All sensitive data secured with TLS 1.3 protocol during transit and AES-256 standards at rest.

  • Least-Privilege Access

    Role-based access controls restricting data visibility exclusively to authorized, trained personnel.

  • Continuous System Monitoring

    Automated threat detection, continuous log analysis, and system health oversight around the clock.

  • Workforce HIPAA Training

    Mandatory annual security awareness, privacy practices, and data handling instruction for all team members.

  • Incident Response Protocols

    Documented rapid containment workflows, vulnerability remediations, and timely partner notifications.

Questions regarding security policies or partner compliance?

Contact our compliance team for detailed documentation or technical disclosures.

CCPA / CPRA

Your California Privacy Rights

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you specific rights regarding your personal information. Below is a detailed breakdown of these rights and how to exercise them with StratiHealth.

Applicable to California Residents
Free of charge for verifiable requests
45-Day standard response timeline

Consumer Rights Overview

You have the right to request that StratiHealth disclose what personal information we collect, use, disclose, and sell or share. This includes the categories of personal information, specific pieces of personal information, sources of collection, business purposes for collecting or sharing, and categories of third parties with whom we share the information. You may submit up to two verifiable requests per 12-month period free of charge.

Do Not Sell or Share My Personal Information

StratiHealth does not sell or share personal information for monetary consideration or cross-context behavioral advertising, and has not done so in the preceding 12 months. We treat your personal data with the strict confidentiality required by California law and healthcare industry standards.

Fulfillment & Verification Procedures

Authorized Agent Requests

You may designate an authorized agent to make a request under the CCPA/CPRA on your behalf. To protect your information, an authorized agent must provide written, signed permission demonstrating authorization, and you must directly verify your identity with StratiHealth, unless the agent holds a valid power of attorney under California Probate Code.

Verifiable Consumer Requests

To process your request to know, delete, or correct, we must first verify your identity. Verification requires matching points of information provided in your request with existing records. We will acknowledge receipt of your request within 10 business days and provide a substantive response within 45 calendar days. If necessary, a single 45-day extension may apply with notice.

Shine the Light (Cal. Civ. Code §1798.83)

California's 'Shine the Light' law allows California residents to request once per calendar year a list of third parties to whom we disclosed personal information for their direct marketing purposes during the preceding year. StratiHealth does not disclose personal information to third parties for direct marketing purposes.

Data Rights & Compliance

Submit a Privacy Request

We respect your right to control your personal information. Whether you are a California resident exercising statutory privacy rights, a healthcare partner, or a visitor to our platform, you can submit a verifiable privacy request directly to our team.

Need Immediate Assistance?

Our compliance office handles requests within standard business hours.

Click below to open our direct communication form for expedited processing.

Last Updated: October 24, 2024
Who Can Submit a Request

California Residents (CCPA/CPRA)

Request to know, delete, or correct personal information collected about you, or opt out of data sharing.

Healthcare Partners & Providers

Submit HIPAA inquiries, Business Associate Agreement (BAA) verification, or secure patient record access requests.

Site Visitors & Clients

Inquire about marketing preferences, site cookie settings, or request updates to your profile records.

Privacy Officer Contact Information

Privacy Officer Email

privacy@stratihealth.net

Send an email

Toll-Free Phone

(800) 987-6543

Call our privacy team

Mailing Address

StratiHealth Privacy Office, 100 Health Plaza, Suite 400, Los Angeles, CA 90024

Attn: Data Protection Officer