Corterve

HIPAA Compliance

Your health information deserves the highest level of protection. Here's how we ensure HIPAA compliance.

Last updated: July 13, 2026

Our Commitment

MannaSync Solutions Inc. ("MannaSync," "we," "us," or "our") operates the Corterve platform ("Corterve," the "Service") and is committed to safeguarding health information consistent with the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA"). We understand that protecting Protected Health Information (PHI) is not just a legal requirement—it's a fundamental responsibility that enables the trust necessary for our mission.

This page describes how MannaSync approaches PHI through Corterve, the safeguards we maintain, and the rights and protections available to patients. It should be read together with our Privacy Policy.

Scope: How PHI Flows Through Corterve

HIPAA applies differently depending on how information moves through the Service:

  • Patient-authorization model. For most recruitment activity, patients provide information directly to Corterve and separately authorize each referral. Identifying PHI is shared with a research site only after the patient gives explicit, per-study, revocable authorization for that specific study.
  • Business associate model. Where MannaSync creates, receives, maintains, or transmits PHI on behalf of a HIPAA covered entity (for example, a research site or sponsor that is a covered entity), MannaSync acts as a business associate and handles that PHI under a Business Associate Agreement (BAA).

Technical Safeguards

  • Encryption in transit (TLS) and at rest
  • Authentication controls, including MFA
  • Role-based, least-privilege, deny-by-default access
  • Comprehensive audit logging of PHI access

Physical Safeguards

  • Google Cloud infrastructure hosted in the U.S.
  • Data centers with physical access controls and monitoring
  • Secure sub-processors under BAAs where applicable
  • Redundancy and disaster-recovery capabilities

Administrative Safeguards

  • Designated Privacy and Security Officers
  • Annual HIPAA training for all employees
  • BAAs with infrastructure sub-processors handling PHI
  • Regular risk assessments and policy reviews

Breach Response

  • Documented incident response procedures
  • Timely breach notification as required by law
  • 24/7 security monitoring and alerting
  • Regular penetration testing

Patient Authorization Model

Corterve is built around explicit patient authorization. Your PHI is shared with a research site or sponsor only after you provide clear, informed authorization for a specific study. That authorization is:

  • Explicit — nothing identifying is shared for recruitment without your affirmative consent.
  • Per-study — each authorization applies only to the specific study you consented to, and referrals may be used only for that study.
  • Revocable — you may withdraw your authorization at any time, which stops future sharing (it does not undo disclosures already made in reliance on your prior authorization).

Business Associate Agreements

Where MannaSync Solutions Inc. handles PHI on behalf of a covered entity, we will enter into a Business Associate Agreement (BAA) that governs our permitted uses and disclosures and our safeguard obligations. BAAs are available to qualifying covered entities and partners on request. In turn, MannaSync maintains BAAs with the infrastructure sub-processors that handle PHI on our behalf, so that protections flow through the chain of service providers.

Breach Notification & Workforce Training

Breach notification. In the event of a breach of unsecured PHI, MannaSync is committed to investigating promptly and providing notification to affected individuals and, where applicable, to covered entities and regulators, within the timeframes and in the manner required by HIPAA and applicable law.

Workforce training. Members of our workforce who may access PHI receive privacy and security training and operate under least-privilege, deny-by-default access. Access to PHI is limited to what is necessary to perform authorized functions and is logged for accountability.

Your Rights Under HIPAA

As a patient, you have the right to:

  • 1.Access your PHI — Request a copy of your health information we maintain.
  • 2.Request amendments — Ask us to correct inaccurate information.
  • 3.Accounting of disclosures — Receive a record of who your PHI has been shared with.
  • 4.Request restrictions — Ask for limits on how we use or share your information.
  • 5.Confidential communications — Request we contact you in a specific way.

Questions or Concerns?

If you have questions about the HIPAA practices of MannaSync Solutions Inc., wish to exercise your rights, or need to request a Business Associate Agreement, please contact us at privacy@corterve.com. MannaSync Solutions Inc. is located in Dayton, OH.

Contact Privacy Officer