Summary
AltraSync helps therapy and ABA organizations manage audits, billing support workflows, client intake operations, internal communication, support tickets, and administrative follow-up. The app is designed to keep company data separated by tenant/company and to limit access based on the logged-in user's role.
Information AltraSync may process
- Account details such as username, role, company, recovery email, login/security status, and permission settings.
- Operational documents uploaded by authorized users, including PDFs, spreadsheets, images, billing files, support attachments, and related extracted metadata.
- Workflow records such as audit findings, correction status, support tickets, replies, retention logs, AI summary logs, and admin activity history.
- Technical security records such as login events, failed attempts, session state, device/IP metadata where available, and system configuration activity.
How information is used
Information is used to operate AltraSync workflows, show dashboard metrics, route support tickets, send correction/support emails, track retention, maintain audit history, help authorized users review documents, and provide secure access to company-specific records.
PHI and sensitive data handling
AltraSync is designed for healthcare-adjacent operations where uploaded documents may contain protected health information. Users should avoid placing unnecessary PHI into support tickets, internal chat, or free-text fields and should use job IDs, proof IDs, request IDs, or screenshots with sensitive details hidden whenever possible.
Customer and user responsibilities
Each customer remains responsible for deciding what documents are appropriate to upload, granting access only to authorized workforce members, maintaining its own HIPAA policies, Business Associate Agreement review, patient notices, consents, payer requirements, and internal compliance program. AltraSync users should not use the platform as a public patient portal or as a substitute for the customer's official Notice of Privacy Practices.
AI features
AI features are optional and controlled through Admin AI Settings. Dashboard AI summaries use company-level counts and safe issue categories only. They are designed not to send PDFs, full note text, evidence text, client names, provider names, dates of birth, member IDs, or PHI. Other AI review features should use extracted or masked text only when enabled by an authorized admin.
Storage and retention
On Azure, AltraSync stores persistent runtime data under the configured data root, currently expected to be inside /home. Uploaded documents, database files, support attachments, logs, and backups should remain separated from deployed code. Retention controls are designed to remove PHI-heavy uploaded/evidence files after the configured retention period while preserving safer operational logs.
Sharing and support
Support requests are visible to authorized Super Admin support users inside AltraSync. Support emails may include company name, username, user email, role, page, request ID, priority, topic, and attachment names so issues can be resolved faster. Users should not attach client documents unless necessary and approved.
Security controls
AltraSync includes role-based permissions, tenant/company isolation, HTTPS hosting, session timeout controls, optional single-login enforcement, mandatory recovery email setup, email two-factor verification, audit logs, support ticket history, and retention logs. These controls help reduce unauthorized access and improve accountability.
Security incidents
If a suspected privacy or security incident involves customer data, AltraSync support should review available logs, preserve relevant evidence, and coordinate with the affected customer so the customer can evaluate any required notices under its own legal and compliance obligations.
Official resources
For general HIPAA background, users can review HHS resources for the HIPAA Privacy Rule, HIPAA Security Rule, and Breach Notification Rule.
Contact
For privacy, security, support, or access questions, contact support@altrasync.com or use the Support Center inside AltraSync.