Legal
Privacy Policy
How information is collected, processed, stored, and protected through the ComplyGovern website and application.
01Introduction
ComplyGovern is committed to protecting the privacy, confidentiality, and security of information entrusted to its healthcare governance and compliance platform.
ComplyGovern provides software supporting accreditation readiness, regulatory compliance, quality management, patient safety, policy governance, risk management, and workforce learning.
This Privacy Policy describes how information is collected, processed, stored, and protected through the ComplyGovern website and application.
02Information We Collect
ComplyGovern may collect business contact information, account details, technical information, customer communications, and information submitted through its applications.
Customer-provided information may include regulatory documentation, policies, quality records, patient safety findings, risk assessments, training records, peer review information, and other healthcare governance documents.
Certain records may contain protected health information (PHI) or other sensitive information.
03Customer Data Ownership
Healthcare organizations retain ownership and control of information submitted to their ComplyGovern environments, subject to applicable agreements and law.
ComplyGovern processes customer information to provide authorized services and does not sell confidential healthcare records.
04HIPAA and Protected Health Information
Where ComplyGovern creates, receives, maintains, or transmits PHI on behalf of a HIPAA-covered entity or business associate, applicable HIPAA requirements and a Business Associate Agreement (BAA) govern the relationship.
ComplyGovern processes PHI according to the applicable BAA, authorized customer instructions, and legal requirements.
Healthcare organizations remain responsible for their own privacy practices and regulatory obligations.
05How We Use Information
Information may be processed to:
- Provide healthcare governance and compliance services.
- Support accreditation and regulatory readiness.
- Manage policies, evidence, findings, and corrective actions.
- Support quality, patient safety, and risk management.
- Deliver workforce training and learning management.
- Provide technical support and implementation.
- Maintain application security and performance.
- Fulfill contractual and legal obligations.
06AI-Assisted Processing
ComplyGovern may provide AI-assisted regulatory intelligence, document management, policy analysis, information retrieval, and governance workflows.
AI-assisted capabilities may help authorized users review regulatory developments, identify potentially affected policies, classify documents, and identify possible compliance gaps.
AI-generated information is intended to support human decision-making and does not replace professional regulatory interpretation, clinical judgment, or organizational responsibility for compliance.
Customer information processed through AI services remains subject to applicable contractual, privacy, and security requirements.
07Microsoft Azure Hosting and Security
ComplyGovern is hosted on Microsoft Azure and designed to integrate with Microsoft 365, SharePoint Online, Teams, and Microsoft Entra ID.
Administrative, technical, and organizational safeguards are used to protect information against unauthorized access, disclosure, alteration, or loss.
Security responsibilities are governed by applicable customer agreements and service arrangements.
08Information Sharing
Information may be shared with authorized service providers supporting cloud hosting, technical operations, support, communications, and subscription administration.
Where service providers process PHI on ComplyGovern's behalf, applicable HIPAA subcontractor requirements must be satisfied.
ComplyGovern does not sell PHI or confidential healthcare governance records.
09Data Retention and Privacy Rights
Customer information is retained according to applicable agreements, legal requirements, and authorized customer configurations.
Upon termination, information will be returned, retained, or deleted according to applicable contractual and legal obligations.
Individuals seeking access to or correction of healthcare information should ordinarily contact the healthcare organization responsible for their records.
10Cookies and Policy Updates
The ComplyGovern website may use cookies and similar technologies for functionality, security, and analytics.
This policy may be updated as services and legal requirements evolve. Material changes will be reflected through an updated effective date and any legally required notice.
11Contact Information
ComplyGovern