Last Updated: August 27, 2026
Universal Data Health System ("UDHS," "we," "us," or "our"), operated by Big Rock Technology Group, LLC, is committed to protecting the privacy, confidentiality, integrity, and security of information entrusted to us.
This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you:
Because UDHS provides technology designed for healthcare organizations, certain information processed through UDHS may constitute Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and related regulations.
When UDHS processes PHI on behalf of a healthcare provider, healthcare organization, or other HIPAA-covered entity, our handling of that information may also be governed by a Business Associate Agreement ("BAA") and the instructions of that organization.
If you do not agree with this Privacy Policy, please discontinue use of our websites and services.
The information we collect depends on how you interact with UDHS and the services being used.
We may collect information you voluntarily provide, including:
You are responsible for ensuring that information you provide directly to us is accurate and current.
When you use a UDHS application or portal, we may process information necessary to establish, authenticate, secure, and administer your account.
This may include usernames, authentication credentials, access permissions, organization associations, security events, session information, and audit records.
When you access our websites or services, certain technical information may be collected automatically, including:
We may use this information to operate, secure, troubleshoot, monitor, and improve our services.
UDHS provides software and infrastructure that may be used by healthcare organizations to create, receive, maintain, transmit, or otherwise process healthcare information.
Depending on the implementation, this information may include:
Where such information constitutes PHI under HIPAA and UDHS acts as a Business Associate, UDHS processes that information according to applicable law, the applicable BAA, contractual requirements, and the instructions of the relevant healthcare organization.
If your healthcare information is maintained in UDHS by a healthcare provider or other healthcare organization, that organization generally controls your medical record.
Requests to access, correct, amend, restrict, or obtain copies of your medical information should normally be directed to your healthcare provider or the organization responsible for your record.
UDHS will cooperate with its customers as required by applicable law and contractual obligations.
We may use information collected through UDHS for purposes including:
When information constitutes PHI, our use of that information is additionally limited by HIPAA, applicable BAAs, contractual requirements, and customer instructions.
We do not sell personal information or PHI.
We may disclose information in limited circumstances necessary to operate our business and provide our services.
We may use third-party service providers that perform services on our behalf, such as infrastructure, hosting, communications, security, monitoring, payment processing, or other technical and business services.
These providers may receive only the information reasonably necessary to perform their services and are subject to contractual confidentiality, security, and data-protection requirements where appropriate.
Where a service provider will process PHI and HIPAA requires it, appropriate Business Associate arrangements will be established.
When you use UDHS through a healthcare provider, employer, hospital, clinic, laboratory, or other organization, information associated with your use may be available to authorized representatives of that organization.
We may disclose information when we reasonably believe disclosure is necessary to:
Where PHI is involved, disclosures will be handled according to applicable HIPAA requirements and other applicable laws.
If Big Rock Technology Group, LLC or UDHS is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar transaction, information may be transferred as part of that transaction subject to applicable confidentiality, contractual, and legal requirements.
UDHS does not sell personal information, patient information, or Protected Health Information.
We do not sell PHI for advertising or marketing purposes.
We do not use PHI obtained through our healthcare customers for unrelated advertising purposes.
If you provide a mobile telephone number and opt in to receive SMS or text messages from UDHS or through an applicable UDHS service, we may use that number to provide the communications for which you have enrolled.
Mobile information, SMS opt-in data, and SMS consent will not be sold, rented, shared, or disclosed to third parties or affiliates for their own marketing or promotional purposes.
SMS opt-in data and consent will not be shared with third parties for marketing purposes, even with consumer consent.
Information may be provided to telecommunications providers, messaging platforms, and other vendors strictly as necessary to deliver requested communications and operate the messaging service.
Message and data rates may apply depending on your wireless carrier and service plan.
Where applicable, you may opt out of SMS communications by replying STOP. You may reply HELP for assistance.
Opting out of SMS communications does not necessarily prevent communications that are required for healthcare, security, account administration, or other purposes where permitted by law and applicable consent requirements.
Our websites and applications may use cookies, session identifiers, local storage, and similar technologies.
These technologies may be used to:
Some cookies or similar technologies may be necessary for UDHS applications to function correctly.
We retain personal information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, satisfy contractual requirements, provide our services, resolve disputes, enforce agreements, maintain security, and comply with applicable laws.
Healthcare information may be subject to separate retention periods established by healthcare organizations, contracts, federal law, state or territorial law, professional requirements, or other regulatory requirements.
Backup copies may remain for a limited period after information is removed from active systems.
When information is no longer required, we may securely delete, destroy, de-identify, or anonymize it in accordance with applicable requirements.
UDHS takes the security of healthcare and personal information seriously.
We implement administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, destruction, or misuse.
Depending on the system and implementation, safeguards may include:
No electronic system, network, storage technology, or method of Internet transmission can be guaranteed to be completely secure. Accordingly, while we maintain safeguards designed to protect information, we cannot guarantee absolute security.
Users are responsible for protecting their account credentials and for accessing UDHS through appropriately secured devices and networks.
We maintain procedures designed to identify, investigate, mitigate, and respond to suspected security incidents.
Where an incident involves personal information or PHI and notification is required by applicable law or contractual obligations, UDHS will provide appropriate notifications to affected customers, organizations, individuals, regulators, or other parties as required.
When UDHS acts as a Business Associate, breach notification responsibilities will also be governed by the applicable Business Associate Agreement and HIPAA.
Where permitted by applicable law and contractual obligations, we may create or process information that has been de-identified, anonymized, or aggregated so that it cannot reasonably be used to identify an individual.
We may use such information for purposes including:
Where HIPAA applies, de-identification of PHI will be performed in accordance with applicable HIPAA requirements.
Certain UDHS products or features may incorporate artificial intelligence, machine learning, automated analysis, or decision-support technologies.
Where these technologies process healthcare or personal information, their use is subject to applicable contractual, privacy, security, and regulatory requirements.
Unless expressly authorized by the applicable customer agreement and permitted by law, UDHS does not use customer PHI to train public, general-purpose artificial intelligence models.
AI-generated or automated information provided through UDHS may be intended to assist authorized professionals and should not be interpreted as replacing professional medical judgment where such judgment is required.
Depending on your location and applicable law, you may have rights concerning your personal information, including the right to:
These rights may be subject to legal exceptions.
If the requested information is maintained by one of our healthcare customers, we may direct your request to that healthcare organization.
We may need to verify your identity before processing certain requests.
California residents may have additional rights under the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), subject to applicable exemptions.
These rights may include the right to request:
California residents may also have rights concerning the sale or sharing of personal information.
UDHS does not sell personal information.
Certain information regulated by HIPAA or other healthcare privacy laws may be exempt from portions of California consumer privacy laws.
We will not unlawfully discriminate against individuals for exercising applicable privacy rights.
UDHS websites are not directed toward children for general consumer use.
However, healthcare organizations using UDHS may lawfully maintain information concerning minor patients as part of providing healthcare services.
Such information is processed on behalf of the applicable healthcare organization and is subject to applicable healthcare privacy laws, contractual requirements, parental or guardian rights, and other legal requirements.
UDHS services may contain links to or integrations with third-party websites, applications, systems, healthcare networks, laboratories, pharmacies, clearinghouses, insurers, or other services.
This Privacy Policy does not govern independent third parties.
Their collection and use of information are governed by their own privacy policies, contracts, and applicable laws.
Some browsers provide a "Do Not Track" ("DNT") setting.
Because there is not currently a universally accepted technical or legal standard governing DNT signals, our websites may not respond to all DNT signals.
Where applicable law requires recognition of a specific browser-based privacy preference signal, we will process such signals as required by law.
UDHS is based in the United States.
If you access our services from outside the United States, information may be processed or stored in the United States or other jurisdictions where authorized service providers operate.
Where required, we implement appropriate safeguards for international transfers of personal information.
Healthcare customers may also impose geographic or data-residency requirements through their agreements with UDHS.
We may update this Privacy Policy periodically to reflect changes in our services, technologies, business practices, or applicable laws.
When this Privacy Policy is updated, we will revise the "Last Updated" date at the top of this document.
Material changes may also be communicated through our website, applications, customer communications, or other appropriate methods.
We encourage you to periodically review this Privacy Policy.
If you have questions or concerns regarding this Privacy Policy, privacy practices, or the handling of personal information, please contact:
Universal Data Health System (UDHS)To request access, correction, deletion, or other action concerning personal information controlled directly by UDHS, contact:
Please provide sufficient information for us to identify the relevant account or information and verify your identity.
If your request concerns medical records or PHI controlled by a healthcare provider, hospital, clinic, laboratory, pharmacy, or other healthcare organization using UDHS, you should contact that organization directly.
UDHS will assist its customers with appropriate privacy requests where required by law, contract, or an applicable Business Associate Agreement.
© 2026 Big Rock Technology Group, LLC. All rights reserved.