AHS SANGAM Chart Connector — Privacy Notice

Extension version 0.2.1 · ID apnlaoiihchifpddcjdjabbcdnmffikj

Purpose and operator

Arizona Heart Specialists (AHS) provides this connector to authorized staff to open the patient chart requested by the AHS SANGAM workboard in the staff member’s existing Ethizo browser session and return the observed patient-ID match or navigation error. The connector supports this specific workflow; it does not provide clinical recommendations or file fax documents.

Information handled

When an authorized staff member requests chart opening, the connector receives the patient name and patient identifier, AHS practice identifier, staff subject identifier, request reference, and expiry time from SANGAM. It reads the relevant Ethizo page elements needed to confirm the practice, detect a login or capacity problem, select the patient, and check the visible patient identifier. This involves personally identifiable information, patient-identifying health context, relevant website content, and the requested chart-navigation activity.

The connector also handles the browser tab/window identifiers, navigation state, observed patient identifier, observation time, and whether it opened the chart. It does not collect Ethizo passwords or PINs, payment information, unrelated browsing history, fax contents, or a general copy of the patient chart. A login-state check reads interface labels, not entered passwords or PIN values.

How information is used and shared

The patient name is entered into the existing Ethizo patient-search interface when needed. The exact patient identifier is used to select and verify the intended chart. The connector returns the request reference, observed patient identifier, result state, observation time, and navigation evidence to the requesting AHS SANGAM workboard.

The recipients in this workflow are AHS and its existing SANGAM service, hosted on Google Cloud, and the existing Ethizo electronic health record service. The connector does not add an advertising, analytics, data-broker, or model-inference recipient. Its packaged code has no independent upload or telemetry endpoint. AHS SANGAM and Ethizo maintain their own service records; this notice describes the connector’s part of that workflow.

Connector data is used only to provide, verify, and support this chart-navigation function. It is not sold, used for advertising, used for unrelated purposes, or used to determine creditworthiness or eligibility for lending.

Temporary storage and retention

The extension uses Chrome session storage for observations grouped by staff subject and browser tab. These entries contain patient identifiers, timestamps, and whether SANGAM opened a chart. They do not contain patient names, fax documents, passwords, or authority to close a staff chart.

During a later observation, a staff/tab entry whose last update is more than one hour old is removed. Individual chart observations inside a recently active entry can remain longer than one hour. The extension does not run a guaranteed hourly deletion job. Session storage is cleared when the browser session ends; these observations are not written by the connector to Chrome sync or local persistent extension storage.

Transient launch information is processed in memory for the requested navigation. SANGAM may separately retain source-bound requests, results, and audit records under AHS operational retention policies. Closing the browser or removing this extension does not delete AHS or Ethizo records.

Access controls and user choices

The extension accepts requests only from the configured AHS SANGAM workboard origin and has host access limited to https://ehr.ethizo.com/. It uses the staff member’s existing signed-in Ethizo session. It reports missing login, ambiguous session, chart capacity, or identity mismatch conditions. It does not create or close browser tabs.

Staff can avoid invoking the connector by not selecting Open Patient Chart in SANGAM. For centrally managed installations, contact the AHS administrator to request removal or access changes. Do not close an active clinical session solely to remove temporary connector observations.

Questions and requests

Contact the AHS administrator at kravi@arizonaheartspecialists.com for connector privacy questions, access concerns, or requests concerning connector-related records. Medical-record rights and broader AHS practices are described in the AHS Notice of Privacy Practices at https://www.arizonaheartspecialists.com/notice-of-privacy-practices.php.