De-Identified Data Commitment
Effective 11 August 2026 · Version 1.0. This is a binding public commitment by NexGenHealth LLC governing de-identified data. We will not narrow it retroactively; dated prior versions remain available at this address.
1. What we de-identify
Before health information is used for our internal AI features, analytics, or product improvement, we process it through an automated de-identification pipeline that targets the eighteen categories of direct identifiers enumerated at 45 CFR § 164.514(b)(2) — names; geographic subdivisions smaller than a state; dates directly related to an individual; ages over 89; telephone and fax numbers; email addresses; Social Security numbers; medical record numbers; health plan beneficiary numbers; account numbers; certificate and licence numbers; vehicle and device identifiers; URLs; IP addresses; biometric identifiers; full-face photographs; and any other unique identifying number, characteristic, or code.
We cite that identifier list as a technical specification. NexGenHealth is not a HIPAA covered entity or business associate, we do not claim HIPAA compliance or certification, and no government agency has certified our de-identification.
1a. How we handle dates
Dates of service in your uploaded records are not deleted — they are shifted by a secret offset unique to your account, applied consistently to every record you upload. The interval between any two of your dates is preserved, so your trends remain readable, while the actual calendar dates are not. Your date of birth is removed outright rather than shifted, and ages over 89 are reported as “90 or older”.
2. We will not re-identify
We will not attempt to re-identify de-identified data, and we will not attempt to link it to any identified or identifiable person, household, or device.
3. We will keep it de-identified
We will maintain and use de-identified data solely in de-identified form.
4. We bind anyone who receives it
We will not provide de-identified data to any third party except under a written agreement that imposes these same obligations, prohibits re-identification, and prohibits onward disclosure except on identical terms. We do not currently provide de-identified data to any third party.
5. If re-identification happens anyway
If we learn that de-identified data has been re-identified — by us, a recipient, or anyone else — we will treat the affected data as identifiable consumer health data again, apply our full privacy commitments to it, and act on the incident.
6. What this does not cover
This commitment governs de-identified data only. Information that still identifies you is governed by our Privacy Policy and by your consent choices.
7. Changes
We will not narrow this commitment retroactively. If we change it, the change applies prospectively, and the prior version remains binding on data de-identified while it was in force. Dated prior versions are kept available at this address.