Privacy notice
Privacy notice
This notice explains what data PowerChart90 and related PDPM Audit Group services process, where that data goes, how long it is kept, and how to request deletion.
Effective date: August 17, 2026 · Last updated: August 17, 2026
1. Who we are
PDPM Audit Optimization Group, LLC (“PDPM Audit Group,” “we,” “us”) operates pdpmauditgroup.com and PowerChart90. Contact: audit-defense@pdpmauditgroup.com · (385) 888-7447.
2. What we collect
- Account / access data: username/email used to authenticate to PowerChart90, session tokens, and optional facility identifiers you enter.
- Scan payload: extracted or pasted documentation text, facility name, facility type, patient identifier fields you enter, assessment type, and scan focus.
- Technical logs: approximate timestamps, IP address, user-agent, and function invocation metadata from hosting (Netlify) needed to operate and secure the service.
- Communications: emails or messages you send to us.
3. Data flow (PowerChart90)
- Files may be opened in your browser so text can be extracted locally.
- The extracted/pasted text and related form fields are then transmitted over HTTPS to a Netlify Function (
powerchart90-engine) for analysis. - If LLM keys are configured for the site, the analysis request may be sent to OpenAI and/or Anthropic as subprocessors for model inference. If no LLM keys are present, analysis runs in an offline heuristic mode on the function host.
- “Extracted in your browser” does not mean the data remains only on your device after you run a scan.
4. How we use data
- Provide chart-audit readiness analysis and related product features
- Authenticate access, prevent abuse, and troubleshoot failures
- Improve product quality using aggregated, de-identified operational metrics where feasible
- Comply with law and defend legal claims when required
We do not sell personal information. We do not use customer chart text to train public foundation models. If a model provider’s default settings could retain prompts, we configure or contract for no-training / limited retention where available; see Security.
5. Retention and deletion
- Scan content: processed for the request; not intended as a long-term clinical archive. Transient function logs may retain short-lived operational metadata. Request deletion of retained copies by emailing audit-defense@pdpmauditgroup.com with subject “PowerChart90 deletion request.”
- Access credentials / session tokens: sessions expire (typically within 12 hours). Access credentials are rotated on request.
- Backups: hosting provider backups, if any, follow the provider’s retention cycle and are not used as a customer chart library.
- Legal holds: we may retain records longer when required by law, dispute, or audit defense.
6. PHI and de-identification
Do not upload Protected Health Information unless your organization has an applicable Business Associate Agreement in place and your privacy/compliance counsel has approved the disclosure. Prefer fully de-identified or synthetic test data for pilots. See HIPAA & PHI.
7. Sharing / subprocessors
We use infrastructure and (when enabled) model providers as subprocessors. Current public list:
- Netlify (hosting, CDN, serverless functions, logs)
- OpenAI (optional model inference when API keys are configured)
- Anthropic (optional model inference when API keys are configured)
We may update this list; material changes will be reflected on this page and/or Security.
8. Security
See our Security overview for controls, incident response, and limitations. No method of transmission or storage is perfectly secure.
9. Your choices
- Do not submit identifiers you are not authorized to share
- Request access, correction, or deletion of retained personal data via the contact above
- Sign out to clear local session tokens in the browser
10. Changes
We may update this notice. The effective date above will change when we do. Continued use after an update constitutes notice of the revised terms for the public site tools, subject to any signed customer agreement that controls.