Privacy & Compliance

Our commitment to patient confidentiality, data security, and operational compliance.

Last updated: January 2026. This policy applies to Providence Health and the operational services provided through its contracted engagements with partner healthcare facilities.

Overview

Providence Health ("the Company," "we," "us," or "our") is committed to protecting the privacy and security of all information we handle in the course of providing contracted operational services to our partner healthcare facilities. This policy describes the types of information we collect, how we use and protect it, and the rights of individuals whose information we may process.

Because our work is conducted inside healthcare organizations and often involves clinical, operational, and patient-related information, we apply the highest standards of data stewardship to everything we handle — not just the minimum required by applicable law.

Information We Collect

The information Providence Health collects depends on the nature of the services we are providing. Across our service areas, this may include:

How We Use Information

Information collected by Providence Health is used exclusively for the purposes for which it was collected. We do not sell, trade, or broker any information we collect — clinical, operational, or otherwise. Specific uses include:

HIPAA Compliance

Providence Health is committed to full compliance with the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations, including the Privacy Rule (45 CFR Parts 160 and 164) and the Security Rule.

Where our services involve access to, creation of, or use of Protected Health Information on behalf of a covered entity, we operate as a Business Associate as defined under HIPAA. We execute Business Associate Agreements (BAAs) with all partner facilities whose PHI we may access or process in the course of providing contracted services. Our BAA template reflects current regulatory requirements and is available for review during the contracting process.

Our privacy and security practices with respect to PHI include:

Data Security

Providence Health maintains a comprehensive information security program designed to protect all categories of information we handle — not just PHI. Security measures include:

Data Retention

Providence Health retains information for the period necessary to fulfill the purpose for which it was collected, to meet our contractual obligations, and to comply with applicable legal and regulatory retention requirements. Retention periods vary by data type:

Third-Party Disclosure

Providence Health does not sell, rent, or otherwise disclose information to third parties for commercial purposes. Disclosures outside the organization occur only in the following circumstances:

Your Rights

Individuals whose information is processed by Providence Health may have rights under applicable law, including HIPAA and various state privacy statutes. These may include:

Website & Cookies

The provhealth.net website does not use tracking cookies, advertising pixels, or third-party analytics platforms. We collect only standard server log data (IP address, browser type, pages visited) for security and performance monitoring purposes. This data is not used to identify individual visitors and is deleted after 90 days.

We do not embed third-party tracking scripts, social media widgets, or advertising tags on our website. The contact form on this site transmits messages via EmailJS, a third-party email delivery service. Information submitted through the contact form is subject to EmailJS's terms of service for the purpose of message delivery; we do not authorize EmailJS to use this information for any other purpose.

Contact Compliance

For privacy concerns, HIPAA-related requests, records inquiries, or compliance questions, please contact our Compliance Officer:

Providence Health — Compliance

48 Bi-State Plaza, Old Tappan, NJ 07675

compliance@provhealth.net

Policy Updates

Providence Health reviews and updates this privacy policy periodically to reflect changes in our services, regulatory requirements, or operational practices. Material changes will be noted on this page with an updated effective date. We encourage partner facilities and other stakeholders to review this policy periodically. Continued engagement with Providence Health following a policy update constitutes acceptance of the revised terms.