Privacy Policy
Last updated: [Effective Date]
Template for legal review
This document is a drafting template, not a lawyer-vetted agreement. Have it reviewed by qualified legal counsel — for Ethiopia, counsel familiar with the 2024 Personal Data Protection Proclamation and Ministry of Health rules — before relying on it.
Atlas is an electronic health record (EHR) platform used by [Hospital Name] (“the Provider”) to deliver and administer care. This policy explains how protected health information (PHI) and related account data are processed in the platform. It should be read together with the Data Processing Agreement, which is the controlling document for how Atlas handles data on the Provider's behalf.
1. Who we are
Atlas provides the software platform. The Provider — the healthcare organization operating the workspace — is the data controller of the patient information in that workspace: it decides why and how the data is used. Atlas is the data processor, handling that data only under the Provider's instructions as set out in the DPA.
2. Information we process
- Protected health information (PHI): patient demographics (name, MRN, date of birth, sex, contact details), insurance/coverage details, clinical records (encounters, problems, allergies, medications, orders, results, vitals, immunizations), admissions, theatre and maternity records, and billing/invoice data.
- Account data: staff name, email, phone, role, and authentication credentials — passwords are stored only as salted hashes, never in plain text.
- Usage and audit metadata: sign-in and session events, per-record access logs (who viewed or changed what, and when), device identifiers for the Offline Client, and sync history — kept to secure the platform and satisfy audit obligations.
3. How information is used
Information is processed solely to operate the EHR for the Provider, including to:
- deliver, coordinate, and document patient care (treatment);
- support billing, invoicing, and insurance/coverage processing (payment);
- run scheduling, pharmacy, inventory, staffing, and reporting (operations);
- authenticate users, enforce role-based access, and maintain the audit trail; and
- maintain, secure, and troubleshoot the platform, including offline sync.
Information is never sold, and never used for advertising or unrelated profiling.
4. How information is stored and protected
- Tenant isolation:each Provider's data lives in its own database schema on Atlas's hosted infrastructure and is never queryable from another workspace.
- Encryption: connections to the platform use TLS in transit; the Offline Client stores its local working copy in an encrypted on-device database, so a lost or stolen laptop does not expose readable patient records.
- Remote wipe:a lost or decommissioned device's Offline Client can be remotely revoked, denying it further sync and, where supported by the device, triggering local data removal.
- Access control and audit: every clinical action requires an explicit role permission, and access to patient records is logged in an audit trail the Provider can review.
- Passwords stored as salted hashes; session tokens are signed and expire.
5. Retention
Records are retained for as long as the Provider maintains its workspace, and in line with the medical-record retention periods the Provider is subject to under applicable Ethiopian health-record regulations and Ministry of Health guidance. On termination of the Provider's agreement, data is returned or securely deleted per the schedule in the DPA.
6. Sharing and sub-processors
PHI is disclosed only as directed by the Provider or as required by law — for example to other treating facilities on referral, or to payers for billing. Atlas uses a limited set of infrastructure and support sub-processors to run the Service, each bound by confidentiality and security obligations at least as strict as this policy. Current sub-processor categories:
- [Cloud infrastructure provider — e.g. AWS, region noted in Section 7]
- [Transactional email / SMS provider, if used for account notifications]
- [Mobile-money / payment gateway, for billing processing only]
A current, named sub-processor list is available on request and will be attached to the DPA once vendors are finalized.
7. Cross-border storage
The Provider's workspace is hosted on Atlas's own infrastructure, expected to be AWS's Cape Town (af-south-1) region or an equivalent regional facility. If data is at any point stored or processed outside Ethiopia, that transfer is subject to the cross-border conditions in the DPA and the Provider's own due-diligence obligations under Ethiopian data-protection law.
8. Patient rights
Patients have rights over their health information — including to access, request correction of, and request restrictions on their records. Because the Provider is the controller, these requests are handled by the Provider; contact the Provider's designated privacy or medical-records officer to exercise them. Atlas supports the Provider in fulfilling verified requests through the platform's record-access and export tools.
10. Changes to this policy
This policy may be updated to reflect changes in the platform or applicable law. Material changes will be communicated to Providers in advance, and the “last updated” date above will change accordingly.
11. Contact
For privacy questions about your own care record, contact the healthcare organization that provides your care. For platform or DPA questions, contact your Atlas account representative.
