Privacy & PHI Handling

Effective on first launch · Updated as the app changes.

PocketRounder is an inpatient charge-capture tool intended for use by licensed clinicians and their authorized staff. It is designed to handle Protected Health Information (PHI) consistent with the HIPAA Privacy and Security Rules. This page describes how PHI flows through the app and what your rights are.

What we collect

PocketRounder stores the PHI you enter directly:

The app collects no telemetry, no analytics, no crash reports, and no advertising identifiers.

Where it lives

Data is stored only on this device, in a SQLite database protected by iOS Data Protection (NSFileProtectionComplete). The database is excluded from iCloud backup. The Anthropic API key, if entered, is stored in the iOS Keychain.

No data is transmitted to Anthropic, Apple iCloud, or any third party unless cloud OCR is explicitly enabled — which is currently disabled until a Business Associate Agreement (BAA) is in place with a covered backend.

Who has access

Only the device owner, authenticated by Face ID, Touch ID, or device passcode, can open the app and view PHI. The app re-locks after a configurable idle interval (Settings → Security → Auto-lock).

Patient rights (HIPAA)

Data retention

Your clinic's HIPAA retention policy applies — typically six or more years for clinical and billing records. Configure auto-purge under Settings → Data Retention. The audit log is retained until manually wiped or the app is fully reset.

Breach response

If this device is lost, stolen, or compromised:

  1. Use Find My iPhone to remote-wipe immediately.
  2. Notify the clinic's Privacy Officer within 24 hours.
  3. Report to HHS OCR within 60 days if PHI was exposed.
  4. Notify affected individuals per the HIPAA Breach Notification Rule.

Third parties & BAAs

What this app does not do

Contact

For privacy questions or to report a suspected breach:

This policy is provided as a template for clinics deploying PocketRounder and should be customized for your covered entity and reviewed by your compliance counsel before production use. PocketRounder is a tool — HIPAA compliance is a property of the people, policies, and infrastructure around it.