IHN App Privacy Notice

IHN Provider App
Integrity Health Network (IHN)
1346 W. Arrowhead Rd, Suite 329, Duluth, MN 55811
info@ihnhealth.com
Effective Date: April 8, 2026
Last Revised: [today’s date when you publish]

This Privacy Notice describes how Integrity Health Network (IHN) collects, uses, stores, and protects information, including Protected Health Information (PHI) in connection with the IHN Provider App. By using this app, you acknowledge that you have read and understood this Privacy Notice. This app is intended for use by licensed healthcare providers and authorized IHN members within the United States.

1. Who We Are

Integrity Health Network (IHN) is an Independent Practice Association (IPA) based in Duluth, Minnesota. IHN operates as a Business Associate under HIPAA, providing administrative and network services to independent healthcare providers and clinics in Minnesota, Wisconsin, North Dakota, and Iowa.

Privacy Officer Contact:
Name: Teri Shelton, Co-CEO & Privacy Officer
Address: 1346 W. Arrowhead Rd, Suite 329, Duluth, MN 55811
Email: tshelton@ihnhealth.com

2. Information We Collect

2.1 Account Information

When you register for the IHN Provider App, we collect: full name and display name, professional email address, phone number, clinic name and affiliation, professional role, and profile photo (optional).

2.2 Message Content

When you use the direct messaging feature, the content of your messages including any PHI you choose to share, is stored in our secure database. You are responsible for determining whether it is appropriate to share PHI through this platform and for obtaining any necessary patient authorizations.

2.3 File Attachments

If you send file attachments in messages (such as images or documents), those files are stored in our secure cloud storage. Allowed file types are limited to images, PDFs, and Word documents. Files may not exceed 10MB in size.

2.4 Forum Posts and Replies

Content you post in the community forum, including post text and replies, is stored in our database and is visible to all authenticated IHN members.

2.5 Activity Logs

For HIPAA compliance purposes, we maintain audit logs of: user login events, message creation events, and automated message deletion events.

2.6 Push Notifications

The app may send push notifications to alert you of new direct messages and other account activity. Push notifications are delivered through Google Firebase Cloud Messaging and, where applicable, Apple Push Notification service (APNs). You can manage or disable push notifications at any time through your device settings.

3. How We Use Your Information

We use the information collected through the IHN Provider App to: provide and operate the app and its features, enable secure provider-to-provider communication, maintain a clinic directory for referral support, deliver educational resources through the learning center, send push notifications related to app activity, maintain audit logs as required by HIPAA, investigate and respond to security incidents, and improve and maintain the security of the platform.

4. How We Protect Your Information

4.1 Technical Safeguards

All data is transmitted over encrypted connections (TLS). All data is encrypted at rest using AES-256 encryption. Access to the app requires authenticated login. Direct messages are accessible only to the participants in each conversation. Firebase App Check is enabled to prevent unauthorized app access. The platform is built using the following Google Firebase services: Firebase Authentication, Firebase Firestore, Firebase Cloud Messaging (push notifications), and Firebase Cloud Storage, all covered under a signed HIPAA Business Associate Agreement between IHN and Google LLC.

4.2 Message Retention

Direct messages are automatically deleted after 30 days. This deletion is performed by an automated process and is logged in our audit system. You should not rely on this app for long-term storage of clinical records.

4.3 Access Control

The IHN Provider App is available to IHN member providers. Registration requires a current access code and is only accessible via a direct link provided by IHN during onboarding, the registration page is not publicly discoverable. All new accounts require email verification before access is granted. Upon launch, registration will be further restricted to approved clinic email domains. IHN reserves the right to revoke access at any time.

5. Sharing of Information

IHN does not sell, rent, or share your information or any PHI with third parties for marketing purposes. Information may be shared only in the following circumstances: with Google LLC, our technology platform provider, under a signed HIPAA BAA; as required by law, court order, or government authority; in connection with a HIPAA-required breach notification; or with your explicit consent.

6. Your Responsibilities

By using the direct messaging feature, you acknowledge and agree that: you are a licensed healthcare provider or authorized IHN member; you will only share PHI when clinically necessary and appropriate; you will not share PHI for patients who have not authorized such sharing where required; you understand that messages are deleted after 30 days and this app is not a substitute for your Electronic Health Record (EHR) system; and you will report any suspected unauthorized access or security incidents to IHN immediately at tshelton@ihnhealth.com.

7. Data Retention and Account Deletion

We retain account information for as long as your account remains active. Direct messages are automatically deleted after 30 days as described in Section 4.2. Audit logs are retained as required for HIPAA compliance, typically for a minimum of six years.

You may request deletion of your account and associated personal data at any time by contacting our Privacy Officer at tshelton@ihnhealth.com, or by using the “Delete My Account” option within the app’s Settings menu. Upon a verified deletion request, we will delete your account information and personal data within 30 days, except where retention is required for legitimate purposes such as security, fraud prevention, active legal obligations, or HIPAA-required audit log compliance. If any data must be retained for these purposes, we will inform you of what is retained and why.

8. Breach Notification

In the event of a breach of unsecured PHI involving your information, IHN will notify you in accordance with HIPAA Breach Notification Rule requirements, which may include written notification to your registered email address.

9. Children’s Policy

The IHN Provider App is intended solely for use by licensed healthcare professionals and authorized IHN members. It is not directed at or intended for use by individuals under the age of 18. We do not knowingly collect personal data from anyone under 18.

10. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal data, including the right to access, correct, or delete your data, and the right to object to certain processing. To exercise these rights, contact our Privacy Officer using the information in Section 1. This app is intended for use by healthcare providers within the United States; if you are located outside the United States and believe additional rights apply to you, please contact us and we will address your request accordingly.

11. Changes To This Policy

IHN reserves the right to update this Privacy Notice at any time. We will notify members of material changes through the app or by email. Continued use of the app following notice of changes constitutes your acceptance of the updated Privacy Notice.

12. Contact Us

If you have questions, concerns, or complaints about this Privacy Notice or IHN’s privacy practices, please contact our Privacy Officer:

Integrity Health Network
Attn: Privacy Officer
1346 W. Arrowhead Rd, Suite 329
Duluth, MN 55811
Email: tshelton@ihnhealth.com

Effective Date: April 8, 2026

Skip to content