TenMed Network is committed to responsible handling of personal information, security-conscious operations, and applicable privacy obligations.
This Compliance Center provides access to TenMed Network’s public privacy and governance documents.
Compliance framework
Depending on the services provided, the information processed, and the jurisdictions involved, applicable requirements may include:
- HIPAA Privacy Rule
- HIPAA Security Rule
- HIPAA Breach Notification Rule
- HITECH-related requirements where applicable
- Applicable Indian data-protection requirements
- Digital Personal Data Protection Act, 2023, where applicable
- Applicable contractual, professional, cybersecurity, accessibility, and consumer-protection obligations
Applicability depends on TenMed Network’s legal role, services, contracts, information systems, customers, and jurisdictions. This page is not a legal opinion or certification.
Privacy governance
TenMed Network’s privacy governance may include:
- Privacy policies and internal procedures
- Data minimization
- Purpose limitation
- Access controls
- Data retention and deletion procedures
- Privacy-request handling
- Vendor and service-provider reviews
- Incident and breach response
- Workforce confidentiality obligations
- Periodic policy review and updates
HIPAA safeguards
Where TenMed Network is subject to HIPAA, its compliance program should address:
Administrative safeguards
- Designation of privacy and security responsibility
- Risk analysis and risk management
- Workforce authorization and supervision
- Security and privacy awareness training
- Incident response procedures
- Contingency planning and disaster recovery
- Periodic evaluation of safeguards
- Appropriate business associate agreements
Physical safeguards
- Facility and equipment controls
- Workstation security
- Device and media controls
- Secure disposal and reuse procedures
- Protection against unauthorized physical access
Technical safeguards
- Unique user identification
- Authentication controls
- Role-based access
- Automatic logoff where appropriate
- Encryption in transit and at rest where appropriate
- Audit logging and monitoring
- Integrity protections
- Secure backup and recovery
- Vulnerability and patch management
- Secure development and change management
Privacy safeguards
- Minimum necessary access and disclosure
- Appropriate use and disclosure controls
- Individual rights procedures
- Authorization procedures where required
- Notice and transparency practices
- Confidentiality and workforce obligations
Breach response
TenMed Network will maintain an incident-response process appropriate to its role and applicable law.
Where a breach of unsecured protected health information is subject to HIPAA, required notifications will be assessed and made in accordance with applicable requirements.
Website security commitments
For this public website:
- Do not request or store protected health information through the public contact form.
- Use HTTPS for website traffic.
- Keep credentials and secrets out of frontend code.
- Apply access controls to administrative functions.
- Use secure server-side form processing.
- Limit third-party tracking.
- Prevent sensitive form content from being sent to analytics tools.
- Apply spam protection and rate limiting.
- Monitor for suspicious activity.
- Maintain backups and recovery procedures.
- Review vendors that process personal information.
- Maintain appropriate records of security and privacy incidents.
Third-party providers
Third-party services used for hosting, forms, email, analytics, security, or customer support must be reviewed before use.
If a provider handles protected health information on behalf of TenMed Network, determine whether HIPAA applies and execute a business associate agreement where required.
Do not describe a provider as HIPAA compliant merely because it provides encryption or healthcare-related services.
Incident and breach reporting
Privacy or security concerns should be reported promptly to Support@tenmednetwork.com.
The internal process should document:
- Date and time of detection
- Systems and information involved
- Scope and affected individuals
- Containment actions
- Risk assessment
- Remediation
- Required notifications
- Lessons learned and corrective actions
Accessibility and responsible design
The website should follow recognized accessibility practices, including:
- Keyboard navigation
- Visible focus states
- Sufficient color contrast
- Descriptive link text
- Proper heading hierarchy
- Form labels and error messages
- Meaningful image alt text
- Responsive layouts
- Screen-reader compatibility
Public compliance documents
- Privacy Policy
- Terms of Use
- Cookie Policy
- Accessibility Statement
- Data Retention Policy (see “Data retention” in the Privacy Policy)
- Information Security Practices (see “Website security commitments” above)
- Notice of Privacy Practices — published where TenMed Network acts as a HIPAA covered entity; contact Support@tenmednetwork.com for a copy.
- Contact page
Important disclaimer
The publication of this Compliance Center, Privacy Policy, or any security statement does not by itself make TenMed Network HIPAA compliant, HIPAA certified, or compliant with every privacy law.
Actual compliance requires an organization-specific assessment, documented policies and procedures, workforce training, risk analysis, technical and physical safeguards, vendor review, contractual controls, incident response, and ongoing monitoring.
