PSOps Security Statement and Data Protection Addendum
Effective date: September 23, 2026.
E1. Processing instructions and data inventory
Provider processes Customer Data to provide, maintain, secure and support the subscribed services, under Customer’s documented lawful instructions. Customer determines authorized users, recordkeeping purposes and lawful disclosures. Provider will notify Customer if it reasonably believes an instruction violates applicable data-protection law and will seek resolution without unnecessarily exposing or destroying data. The order must identify data subjects, data categories, service modules, processing duration, approved regions, vendors and integrations. Separate inventories are required for clinical records, operational records, personnel/payroll information, donors, and public website inquiries. Specific statutory addenda apply where required; this document is not represented as a complete GDPR, CJIS, PCI DSS or substance-use-record compliance agreement.
E2. Agreed safeguards
Access. Maintain unique accounts, least-privilege roles, department separation, prompt offboarding, controlled privileged access and periodic access reviews. PSOps supports native time-based multi-factor authentication (TOTP) with single-use recovery codes. Privileged and clinical MFA enforcement is a staged production control and must be verified as enabled for the applicable scope before any contractual statement represents MFA as mandatory. Department-wide MFA enforcement may also be enabled through authorized configuration. Data and keys. PSOps uses application-layer encryption for selected sensitive fields, credentials, tokens and protected snapshots, and applies restricted access to encryption keys. Encrypted-field coverage is not represented as proof that every database field or data path is encrypted. Key access, recovery and rotation remain controlled operational functions. Application security. Apply safe input/output handling, server-side authorization, CSRF protection where applicable, secret management, dependency review, patching and release gates. Test cross-department access, file downloads, report exports and state-submission paths. Prohibit production PHI in development/test environments unless a specific approved arrangement provides equivalent controls and a lawful purpose. Audit and monitoring. PSOps records relevant authentication, MFA, administrative and operational events in audit records. Audited application workflows include security and account events as well as selected incident, training, scheduling, apparatus, hydrant and administrative activity. Audit records are designed to identify the event without unnecessarily duplicating protected clinical content or credentials. Continuity. PSOps maintains production application and database backups as part of its continuity process. Specific backup frequency, retention, off-host isolation, recovery-point objectives, recovery-time objectives and restoration commitments apply only when documented in an approved operating policy or customer agreement. PSOps does not promise zero data loss or uninterrupted availability. People and vendors. Train personnel, bind them to confidentiality, manage access and maintain an approved vendor inventory. Monitor vendor commitments and execute applicable data-processing agreements and BAAs before data access. Provider remains responsible for its subcontracted performance.
E3. Incidents, requests and subprocessors
Provider will notify Customer without unreasonable delay of a confirmed or reasonably suspected compromise affecting Customer Data and will cooperate with containment, investigation, restoration and legally required notices. The BAA controls PHI-related notice obligations. Any shorter contractual response target applies only when expressly stated in the applicable customer agreement. Provider will assist Customer with lawful access, correction, retention, export and deletion requests. For public-records requests or legal process, Provider will refer the request to Customer where permitted and cooperate; Customer decides disclosure obligations. Confidentiality language does not override mandatory public law or waive exemptions protecting medical/personal records. Before authorizing a service provider to receive material Customer Data, Provider will document the provider's role and apply contractual and security safeguards appropriate to the data involved. A provider that creates, receives, maintains or transmits PHI for PSOps will be subject to the required HIPAA business-associate or subcontractor arrangement before such access is authorized.
E4. Retention and exit schedule
Record retention is set by category and applicable law, not one universal deletion period. HIPAA’s retention requirements for specified compliance documentation must not be represented as a universal six-year patient-chart retention period. Customer supplies its approved chart, personnel, financial, public-records and litigation-hold schedules; Provider implements and documents supported retention controls. Retention periods, backup rotation, termination export windows, active-copy deletion timing, isolated-backup expiry and legal-hold procedures are documented in the applicable customer order or approved retention policy. Where an order does not establish a specific period, PSOps will not represent a universal retention or deletion period for regulated records. Document deletions and exceptions; preserve medical-record access under law and the BAA.
E5. Security assurance and remedy
Provider will provide reasonable evidence of agreed safeguards, incidents and remediation while protecting confidential information. Record audit rights, assessment scope, insurance and service levels in the order; make no unsupported certification, coverage or uptime claim. These commitments require safeguards and response actions, not immunity from threats. Failure to perform triggers the agreement’s correction, termination and applicable remedies; general risk statements do not cancel those duties.