Health Information Privacy
Your health information deserves strong protection. Here is how MannaSync approaches privacy and security on Corterve.
Last updated: September 7, 2026
Our Commitment
MannaSync Solutions Inc. ("MannaSync," "we," "us," or "our") operates the Corterve platform ("Corterve," the "Service") and is committed to safeguarding health information consistent with applicable U.S. privacy and security requirements, including the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA") where HIPAA applies. Protecting Protected Health Information (PHI) is a core responsibility that supports trust in our mission.
This page describes how MannaSync approaches PHI through Corterve, the safeguards we maintain, and the rights and protections that may be available depending on your relationship with us or with a covered entity. It should be read together with our Privacy Policy. Nothing on this page is a blanket certification of HIPAA status for every visitor or use case.
Scope: How PHI Flows Through Corterve
HIPAA applies differently depending on how information moves through the Service:
- •Patient-authorization model. For most recruitment activity, patients provide information directly to Corterve and separately authorize each referral. Identifying PHI is shared with a research site only after the patient gives explicit, per-study, revocable authorization for that specific study.
- •Business associate model. Where MannaSync creates, receives, maintains, or transmits PHI on behalf of a HIPAA covered entity (for example, a research site or sponsor that is a covered entity), MannaSync acts as a business associate and handles that PHI under a Business Associate Agreement (BAA).
Technical Safeguards
- ✓Encryption in transit (TLS) and at rest
- ✓Authentication controls, including MFA where enabled
- ✓Role-based, least-privilege, deny-by-default access
- ✓Audit logging of access to sensitive records
Physical Safeguards
- ✓Cloud infrastructure hosted in the U.S. by reputable providers
- ✓Provider data centers with physical access controls
- ✓Sub-processors engaged under BAAs where applicable
- ✓Redundancy and recovery capabilities appropriate to the Service
Administrative Safeguards
- ✓Assigned privacy and security accountability
- ✓Privacy and security training for workforce members who may access PHI
- ✓BAAs with infrastructure sub-processors handling PHI where required
- ✓Periodic risk reviews and policy updates
Incident Response
- ✓Documented incident response procedures
- ✓Breach notification as required by applicable law
- ✓Security monitoring and alerting for production systems
- ✓Security testing as part of our ongoing program
Patient Authorization Model
Corterve is built around explicit patient authorization. Your PHI is shared with a research site or sponsor only after you provide clear, informed authorization for a specific study. That authorization is:
- •Explicit — nothing identifying is shared for recruitment without your affirmative consent.
- •Per-study — each authorization applies only to the specific study you consented to, and referrals may be used only for that study.
- •Revocable — you may withdraw your authorization at any time, which stops future sharing (it does not undo disclosures already made in reliance on your prior authorization).
Business Associate Agreements
Where MannaSync Solutions Inc. handles PHI on behalf of a covered entity, we will enter into a Business Associate Agreement (BAA) that governs our permitted uses and disclosures and our safeguard obligations. BAAs are available to qualifying covered entities and partners on request. In turn, MannaSync maintains BAAs with the infrastructure sub-processors that handle PHI on our behalf, so that protections flow through the chain of service providers.
Breach Notification & Workforce Training
Breach notification. In the event of a breach of unsecured PHI, MannaSync investigates promptly and provides notification to affected individuals and, where applicable, to covered entities and regulators, within the timeframes and in the manner required by HIPAA and applicable law.
Workforce training. Members of our workforce who may access PHI receive privacy and security training and operate under least-privilege, deny-by-default access. Access to PHI is limited to what is necessary to perform authorized functions and is logged for accountability.
Privacy Rights Related to HIPAA
HIPAA individual rights generally arise in a relationship with a covered entity (and, in some cases, through a business associate acting for that covered entity). Visiting corterve.com or using patient-matching features does not by itself mean Corterve is your covered entity or that every HIPAA right listed below applies to every visitor. Depending on your relationship with MannaSync, a research site, or another covered entity, you may be able to:
- 1.Access PHI — Request a copy of health information we maintain about you, where applicable.
- 2.Request amendments — Ask that inaccurate information be corrected, where applicable.
- 3.Accounting of disclosures — Request a record of certain disclosures of your PHI, where applicable.
- 4.Request restrictions — Ask for limits on how information is used or shared, where applicable.
- 5.Confidential communications — Request contact in a specific way, where applicable.
If your PHI is held primarily by a research site or other covered entity, you may need to exercise rights directly with that organization. We can help route requests when we act as a business associate.
Questions or Concerns?
If you have questions about the privacy practices of MannaSync Solutions Inc., wish to make a privacy request, or need to request a Business Associate Agreement, please contact us at privacy@corterve.com. MannaSync Solutions Inc. is located in Dayton, OH.
Contact Privacy Team