CMSMonitor is a hospital compliance application provided by Indidge Systems
(“HealthDox”, “we”, “us”). This policy
explains what information the app handles and how.
Information we process
Account identity. When you sign in with your
organization’s Microsoft (Entra ID) account, we receive your name,
email/username, and a Microsoft user identifier. We use this to
authenticate you and to attribute actions (for example, who recorded a
compliance decision).
Compliance content you enter. Notes, impact
assessments, attestations, deadlines, and similar records you create are
stored on our backend to provide the service to your organization.
Public regulatory data. The app displays public
information from CMS sources (the Federal Register and the CMS Provider
Data Catalog). This is not personal data.
What we do NOT do
We do not use your data for advertising and do
not track you across other apps or websites.
We do not sell your personal information.
CMSMonitor is not intended to store protected health
information (PHI). Please do not enter patient identifiers or records.
How information is used
To provide and secure the service (authentication, authorization, audit trail).
To operate features you request (rule tracking, assessments, controls, calendar).
Storage and security
Data is hosted on Microsoft Azure and transmitted over encrypted HTTPS
connections. Access is limited to authorized users of your organization.
Data retention and your rights
We retain your organization’s data for the duration of the service agreement.
Requests to access, correct, or delete data should be directed to your
organization’s administrator or to us at
privacy@healthdox.net.
Children
CMSMonitor is a business tool and is not directed to children.
Changes
We may update this policy; material changes will be posted here with a new date.