HTN Prevention Program — Privacy Policy
Effective Date: May 5, 2026
The HTN Prevention Program app ("the App") is operated by Mount Sinai Heart in support of a hypertension prevention program for first responders. This Privacy Policy explains what information the App collects, how it is used, and the choices available to you. This policy applies to the mobile application identified by the package name com.mswheart.fdhypertensionapp (Android) and the iOS bundle identifier MSWHeart.BPFirstResponder.
The App handles Protected Health Information (PHI) and is operated in compliance with the U.S. Health Insurance Portability and Accountability Act (HIPAA).
Information We Collect
Personal Information
- Name — used to identify your account and personalize the experience.
- Email address — used for sign-in via one-time passcode and program communications.
- Phone number (optional) — used for sign-in via SMS one-time passcode if you choose this method.
- Address (optional) — used for shipping blood pressure cuffs and program logistics.
- Date of birth (optional) — used to support clinical risk stratification when provided.
- Race and ethnicity (optional) — used to support clinically validated treatment guidelines when provided.
- Union affiliation — used to associate your account with the appropriate first responder program cohort.
Health Information
- Blood pressure readings (systolic, diastolic, heart rate, timestamp, device ID, optional notes) — captured via Bluetooth from your blood pressure cuff or entered manually.
- Blood pressure category (Normal, Elevated, Stage 1, Stage 2, Crisis) — derived from your readings using American Heart Association guidelines.
- Lifestyle information (optional) — exercise frequency, food frequency, sleep quality, stress level, smoking status, medication adherence — collected via in-app surveys to support program coaching.
- Call notes and follow-up history — entered by nurse coaches in connection with re-engagement and follow-up care.
Device and Technical Information
- Device or other identifiers — used for Bluetooth pairing with your blood pressure cuff, device authentication, and crash diagnostics.
- Crash logs and diagnostics — captured automatically when the App encounters errors. Used to improve App reliability.
- App activity — basic usage signals (sign-ins, screens viewed) used to improve the App and surface re-engagement reminders.
How We Use Your Information
- To provide the App's core functionality, including blood pressure tracking, history, and personalized health insights.
- To enable secure sign-in via email or phone-based one-time passcode.
- To allow nurse coaches and authorized program staff to follow up with you regarding elevated readings, missed readings, or program milestones.
- To pair the App with your blood pressure cuff over Bluetooth.
- To monitor App reliability through crash reporting and diagnostics.
- To comply with HIPAA, audit logging requirements, and other applicable laws.
How We Share Your Information
We do not sell your information. We do not share your information for advertising or marketing purposes. The App does not display third-party advertisements.
We share information only with the following categories of recipients, in support of the App's operation:
- Authorized clinical staff at Mount Sinai Heart and the HTN Prevention Program, including nurse coaches and program administrators, who use your data to provide care and follow-up.
- Convex — our backend database provider, which stores your account and reading data under a HIPAA Business Associate Agreement.
- Clerk — our authentication provider, which handles sign-in and identity management.
- Sentry — our crash reporting provider, which receives device identifiers, crash logs, and diagnostic information to help us identify and fix App issues. Sentry does not receive your blood pressure readings, lifestyle data, or other health information.
- Apple and Google — to the extent required for App Store and Google Play distribution and basic platform telemetry.
We may also disclose information when legally required (e.g., subpoena, court order) or to protect the safety of users.
Data Security
- All data is encrypted in transit via HTTPS/TLS.
- Sensitive data stored locally on your device is encrypted using SQLCipher (AES).
- Authentication uses one-time passcodes; passwords are not stored on our servers.
- Multi-factor authentication is required for all program staff accessing patient data.
- Access to Protected Health Information is logged and audited per HIPAA §164.312(b).
Data Retention
We retain your account and health information for the duration of your participation in the HTN Prevention Program plus six (6) years thereafter, in accordance with HIPAA record retention requirements. Audit logs are retained for the same period. Crash logs and diagnostics are retained for 90 days.
Your Rights and Choices
- Access — you may request a copy of your data by contacting us at the address below.
- Correction — you may correct or update your profile information directly in the App or by contacting us.
- Deletion — you may request deletion of your account and associated data by contacting us. Some data may be retained as required by HIPAA or other law (e.g., audit logs).
- Opt out — Date of Birth and Race/Ethnicity are optional fields; you may decline to provide them.
To exercise any of these rights, email us at support@htnprevention.org or contact your assigned nurse coach.
Children's Privacy
The App is intended for adults 18 years of age and older. We do not knowingly collect information from children under 13. If you believe a child has provided us with information, please contact us and we will delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. The "Effective Date" at the top of this page reflects the most recent version. Material changes will be communicated through the App or via email.