Last updated: January 2026. This policy applies to Providence Health and the operational services provided through its contracted engagements with partner healthcare facilities.
Overview
Providence Health ("the Company," "we," "us," or "our") is committed to protecting the privacy and security of all information we handle in the course of providing contracted operational services to our partner healthcare facilities. This policy describes the types of information we collect, how we use and protect it, and the rights of individuals whose information we may process.
Because our work is conducted inside healthcare organizations and often involves clinical, operational, and patient-related information, we apply the highest standards of data stewardship to everything we handle — not just the minimum required by applicable law.
Information We Collect
The information Providence Health collects depends on the nature of the services we are providing. Across our service areas, this may include:
- Protected Health Information (PHI): Clinical data recorded during patient encounters by our contracted EMS personnel, including patient demographics, clinical assessments, treatment provided, and disposition information. PHI is collected only as necessary for the direct provision of patient care and the documentation requirements associated with it.
- Emergency Management Program Data: Documentation generated in the course of managing your facility's emergency management program, including plans, policies, after-action reports, training records, and exercise documentation. This information is maintained on behalf of the partner facility and remains the property of the facility.
- Operational & Logistics Data: Supply chain records, inventory data, vendor information, and other operational documentation generated in the course of logistics and safety coordination services.
- Safety & Incident Data: Workplace safety documentation, incident investigation records, corrective action tracking, and OSHA-required recordkeeping maintained as part of contracted safety officer functions.
- Client Contact & Organizational Information: Contact information, organizational data, and correspondence exchanged with partner facilities during the contracting and service delivery process.
- Website Data: Standard technical information collected by web servers when you visit provhealth.net, including IP address, browser type, referring URL, and pages viewed. We do not use this data to identify individual visitors.
How We Use Information
Information collected by Providence Health is used exclusively for the purposes for which it was collected. We do not sell, trade, or broker any information we collect — clinical, operational, or otherwise. Specific uses include:
- Provision of Contracted Services: Using collected information to perform the services defined in our agreements with partner facilities — managing emergency programs, staffing EMS departments, coordinating logistics, and maintaining safety compliance functions.
- Continuity of Care: Sharing relevant clinical information with receiving hospitals, medical command facilities, or other clinical contacts during EMS transport and patient transfer, as required for the continuity and safety of patient care.
- Quality Assurance: Internal review of patient care reports, operational documentation, and program records by our clinical and management teams to identify opportunities for improvement and ensure service quality.
- Regulatory Compliance: Preparation and submission of documentation required under applicable federal and state regulations governing EMS operations, emergency management, occupational safety, and healthcare licensing.
- Contract Performance Tracking: Maintaining documentation necessary to demonstrate delivery of contracted services, track program milestones, and support service agreement compliance.
- Communications: Responding to inquiries submitted through our website or direct contact channels. We do not add contacts to marketing lists without explicit consent.
HIPAA Compliance
Providence Health is committed to full compliance with the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations, including the Privacy Rule (45 CFR Parts 160 and 164) and the Security Rule.
Where our services involve access to, creation of, or use of Protected Health Information on behalf of a covered entity, we operate as a Business Associate as defined under HIPAA. We execute Business Associate Agreements (BAAs) with all partner facilities whose PHI we may access or process in the course of providing contracted services. Our BAA template reflects current regulatory requirements and is available for review during the contracting process.
Our privacy and security practices with respect to PHI include:
- Access Controls: PHI access is restricted to personnel who require it to perform their assigned functions. Access is granted on a minimum necessary basis and reviewed regularly.
- Encryption: All digital PHI is encrypted at rest and in transit using current industry-standard encryption protocols.
- Audit Controls: Access to systems containing PHI is logged and subject to periodic audit to detect unauthorized access or inappropriate use.
- Workforce Training: All Providence Health personnel who may access PHI receive HIPAA training prior to deployment and on an annual basis thereafter.
- Breach Response: In the event of a suspected or confirmed breach of unsecured PHI, we follow documented incident response procedures and notify affected covered entities in accordance with HIPAA Breach Notification Rule requirements.
Data Security
Providence Health maintains a comprehensive information security program designed to protect all categories of information we handle — not just PHI. Security measures include:
- Encrypted Storage: All digital records — clinical, operational, and administrative — are stored on encrypted, access-controlled systems. We do not use unsecured cloud storage for any sensitive operational data.
- Device Security: Company-issued devices used to access client systems or sensitive operational data are subject to endpoint protection requirements, including device encryption and remote wipe capability.
- Network Security: Personnel accessing sensitive systems remotely are required to use secure, encrypted connections. Access to client networks and systems is limited to personnel with a legitimate operational need.
- Vendor Management: Third-party vendors and service providers who may access our systems or the data we hold are evaluated for security posture and required to maintain appropriate safeguards as a condition of engagement.
- Incident Response: We maintain a documented security incident response plan that is reviewed and tested annually. Security incidents are investigated promptly, and affected parties are notified in accordance with applicable legal requirements and contract terms.
Data Retention
Providence Health retains information for the period necessary to fulfill the purpose for which it was collected, to meet our contractual obligations, and to comply with applicable legal and regulatory retention requirements. Retention periods vary by data type:
- Patient Care Records: Retained in accordance with applicable state EMS record retention requirements, which vary by state. Records are transferred to the partner facility or destroyed in accordance with HIPAA and applicable law at the conclusion of the engagement.
- Emergency Management Program Documentation: Retained for the duration of the engagement plus a reasonable post-engagement period for reference and audit purposes. Original program documents are the property of the partner facility and are transferred at engagement conclusion.
- Operational & Contract Records: Retained for a minimum of seven years following the conclusion of the relevant engagement to meet accounting, tax, and legal requirements.
- Website Data: Standard web server logs are retained for up to 90 days and then deleted.
Third-Party Disclosure
Providence Health does not sell, rent, or otherwise disclose information to third parties for commercial purposes. Disclosures outside the organization occur only in the following circumstances:
- As Required for Care: Clinical information necessary for the continuity of patient care is shared with receiving providers, hospitals, and medical command as required by the clinical situation.
- As Required by Law: Information may be disclosed in response to valid legal process, regulatory requirements, mandatory reporting obligations (such as reportable disease or injury notifications), or in response to a lawful request from a government authority.
- To Service Providers: We engage a limited number of service providers who may have access to certain categories of information in the course of providing services to us (e.g., cloud infrastructure providers, communication platforms). These providers are subject to confidentiality obligations and are not permitted to use information they access for any purpose beyond their contracted service function.
- In a Business Transaction: In the event of a merger, acquisition, or sale of substantially all of our assets, information we hold may be transferred as part of that transaction. We will provide notice of any such transfer and ensure that successor entities are bound by appropriate privacy obligations.
Your Rights
Individuals whose information is processed by Providence Health may have rights under applicable law, including HIPAA and various state privacy statutes. These may include:
- Right to Access: The right to request a copy of your personal information we hold, subject to applicable legal limitations.
- Right to Correction: The right to request correction of inaccurate or incomplete information we hold about you.
- Right to Accounting of Disclosures: Under HIPAA, patients may request an accounting of disclosures of their PHI made by covered entities and their business associates.
- Right to Complain: You have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights if you believe your HIPAA rights have been violated.
Website & Cookies
The provhealth.net website does not use tracking cookies, advertising pixels, or third-party analytics platforms. We collect only standard server log data (IP address, browser type, pages visited) for security and performance monitoring purposes. This data is not used to identify individual visitors and is deleted after 90 days.
We do not embed third-party tracking scripts, social media widgets, or advertising tags on our website. The contact form on this site transmits messages via EmailJS, a third-party email delivery service. Information submitted through the contact form is subject to EmailJS's terms of service for the purpose of message delivery; we do not authorize EmailJS to use this information for any other purpose.
Contact Compliance
For privacy concerns, HIPAA-related requests, records inquiries, or compliance questions, please contact our Compliance Officer:
Providence Health — Compliance
48 Bi-State Plaza, Old Tappan, NJ 07675
[email protected]
Policy Updates
Providence Health reviews and updates this privacy policy periodically to reflect changes in our services, regulatory requirements, or operational practices. Material changes will be noted on this page with an updated effective date. We encourage partner facilities and other stakeholders to review this policy periodically. Continued engagement with Providence Health following a policy update constitutes acceptance of the revised terms.