Amplifier Health - Information Privacy Policy

Policy Number: POL-SEC-001

Version: 1.0

Effective Date: October 7, 2025

Policy Owner: Chief Technology Officer / Security Officer

Approved By: Amit Mehta, CEO

1.0 Purpose and Scope

This Information Privacy Policy documents the principles, standards, and procedures that Amplifier Health, Inc. ("Amplifier," "we," "us," "our") follows to protect the confidentiality, integrity, and availability of all information it collects, creates, and maintains.

This policy applies to all Amplifier employees, contractors, and agents ("Workforce Members") and to all data, systems, and networks used in the course of business operations. The primary objective is to ensure compliance with our legal, regulatory, and contractual obligations, including the Health Insurance Portability and Accountability Act (HIPAA) and the trust services criteria of SOC 2.

This policy specifically governs the handling of Protected Health Information (PHI) and Personally Identifiable Information (PII).

2.0 Policy Statement

Amplifier Health is fundamentally committed to the highest standards of data privacy and security. We operate as a Business Associate to our healthcare partners ("Covered Entities") and are contractually and ethically bound to protect the sensitive information entrusted to us.

Our privacy program is guided by the following core principles:

3.0 Roles and Responsibilities

4.0 Information Handling Procedures

4.1 Data Collection and Use

4.2 Access Control

4.3 Data Storage and Encryption

4.4 Data Retention and Destruction

5.0 Individual Rights

As a Business Associate, Amplifier Health assists our Covered Entity partners in meeting their obligations to patients regarding their PHI. We will support our partners in fulfilling patient requests for:

All such requests received by Amplifier Health will be promptly forwarded to the appropriate Covered Entity for handling.

6.0 Incident Response

Amplifier Health maintains a formal Incident Response Plan to address any potential data breach or security incident. In the event of a suspected breach of Unsecured PHI, we will:

  1. Execute our internal response plan to contain, investigate, and mitigate the incident.
  2. Notify the affected Covered Entity without unreasonable delay, and in no case later than the timeframe specified in our BAA (typically 5 business days).
  3. Cooperate fully with the Covered Entity to support their investigation and any required notifications to individuals or regulatory bodies like the Department of Health and Human Services.

7.0 Training and Awareness

All Amplifier Health Workforce Members are required to complete comprehensive HIPAA security and privacy training upon hiring and on an annual basis thereafter. Training records are maintained to document compliance.

8.0 Policy Review and Updates

This policy will be reviewed at least annually, or more frequently in response to significant changes in our business, technology, or the regulatory landscape.


Document History
| Version | Date | Author | Description of Change |
| 1.0 | October 7, 2025| Chief Technology Officer | Initial Version |