Dime procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “All patient rights regarding access, correction, or restriction of their PHI are governed by their healthcare provider (the Covered Entity). Patients seeking to exercise such rights should contact their provider directly.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “We retain PHI only for as long as necessary to fulfill our service obligations or as required by law or contract. Upon termination of a client agreement or upon request, PHI is securely deleted or returned in accordance with the BAA.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “We may share information only as follows: With Covered Entities: To perform contracted services under the BAA. With Subcontractors (if any): Only under written agreements requiring HIPAA compliance. As Required by Law: When responding to lawful requests from authorities or regulatory agencies. We never sell, rent, or trade PHI or personal data to third parties.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “As a Business Associate under HIPAA, we enter into Business Associate Agreements with our healthcare clients ("Covered Entities") to ensure all handling of PHI is fully compliant.Under the BAA, we:Use PHI only as permitted or required to perform our contracted services.Implement safeguards to protect PHI against unauthorized use or disclosure.Report any breaches of unsecured PHI as required by law.Ensure our subcontractors agree to similar restrictions and protections.” | Captured 2026-07-20Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.