This Privacy Policy describes how Sproutivity (“we,” “us,” or “our”) collects, uses, and protects information when you visit our website, interact with our marketing materials, or utilize our clinical intelligence platform.

As a partner to Skilled Nursing Facilities (SNFs), Assisted Living Facilities (ALFs), and other medical/healthcare companies, Sproutivity operates under a dual-privacy framework: we are a modern digital service provider for our website visitors and a HIPAA-compliant Business Associate for our client facilities.


1. Scope: Website Visitors vs. Resident Data

This policy covers two distinct types of data:

  • Website & Business Information: Data collected from facility administrators, DONs, and stakeholders through our website for marketing and business operations.

  • Protected Health Information (PHI): Resident data processed on behalf of our clients (Covered Entities). All PHI handling is governed strictly by the Business Associate Agreement (BAA) executed between Sproutivity and your facility.


2. Information We Collect from Website Visitors

We collect information that helps us provide high-value clinical insights to the right people:

  • Direct Inquiries: When you request a “Clinical Risk Audit,” sign up for our newsletter, or contact us, we collect your name, and contact information that you share with us.

  • Automated Data (Cookies): We use cookies and similar tracking technologies to analyze website traffic and improve SEO. This data is aggregated and does not include PHI.

  • Voluntary Submissions: Any data extracts provided for a free audit are handled via secure, encrypted channels and are treated as PHI from the moment of receipt.


3. Our Role as a HIPAA Business Associate

When Sproutivity integrates with a facility’s EMR or processes clinical datasets, we act as a Business Associate under 45 CFR § 160.103.

  • BAA Governance: We do not access, receive, or maintain PHI without a signed BAA that outlines our permitted uses and disclosures.

  • Minimum Necessary Rule: We strictly adhere to the HIPAA “Minimum Necessary” standard. Our algorithms only ingest the specific data points required to calculate risk scores and identify F-tag exposure.

  • Permitted Uses: We use PHI solely to perform clinical reporting, hospital readmission analysis, and quality improvement services for your facility.


4. Security Architecture (Administrative & Technical Safeguards)

Sproutivity employs enterprise-grade safeguards to ensure the Confidentiality, Integrity, and Availability of all data:

  • Encryption: All data is encrypted at rest using AES-256 and in transit via TLS 1.2 or higher.

  • Access Control: We utilize Multi-Factor Authentication (MFA) and the “Principle of Least Privilege.Only authorized personnel involved in clinical data processing can access sensitive systems.

  • Audit Logging: Every interaction with clinical data is logged. We maintain detailed audit trails to detect and analyze any unauthorized access attempts.

  • De-identification: When creating benchmarks or industry reports, we use the HIPAA Safe Harbor or Expert Determination methods to ensure data is fully de-identified and can no longer be linked to an individual.


5. Individual Rights (Residents)

Under HIPAA, the Covered Entity (your SNF) is responsible for managing resident rights, including access to records, amendments, and the Notice of Privacy Practices.

  • If Sproutivity receives a request from a resident or their representative, we will redirect that request to the facility’s Privacy Officer within three (3) business days.


6. Breach Notification

In the event of a breach of unsecured PHI, Sproutivity will notify the affected facility without unreasonable delay and strictly within the timeframe specified in our BAA. We provide full support to the facility to ensure they meet their reporting obligations to HHS and affected individuals.


7. Data Retention and Disposal

We retain PHI only for the duration of our service agreement or as required by law. Upon termination of a contract, PHI is either returned to the facility or destroyed using NIST-standard media sanitization methods.


8. Contact Our Privacy Office

For questions regarding our HIPAA compliance or to review our standard BAA, please contact:

Sproutivity Compliance Team Attn: Privacy Officer

Email: info@sproutivity.com


Last Updated: April 2026. This policy is updated periodically to stay aligned with evolving CMS and OCR guidance.

Trusted by some of the biggest brands

Spaces Logo
Next Logo White
Hemisferio Logo White
Digitalbox White
CGLobal White
Abstract Logo White
Business Coach Glyph

We’re Waiting To Help You

Get in touch with us today and let’s start transforming your business from the ground up.