1. Purpose & Scope
This policy defines the acceptable use of the PaceSetter application by all individuals who hold a login account — PaceSetter Healthware LLC personnel and, more commonly, the workforce members of each client organization using PaceSetter to schedule and coordinate patient care. It is enforced technically: every user must acknowledge this policy (or a superseding version) via a click-wrap prompt before continuing to use the application, and that acceptance is timestamped and logged.
PaceSetter Healthware LLC is a Business Associate providing the PaceSetter software; this policy governs use of the tool itself. It does not replace, and is not a substitute for, each client organization's own HIPAA workforce policies, which remain that organization's responsibility as the Covered Entity.
2. Authorized Use
- Access patient, scheduling, and clinical data in PaceSetter only as needed to perform your assigned job duties.
- Keep your login credentials private. Do not share your account or password with any other person, including coworkers.
- Enable and maintain multi-factor authentication where your organization requires it.
- Lock or log out of any device before leaving it unattended while logged in to PaceSetter.
3. Prohibited Actions
- Attempting to bypass, disable, or circumvent access controls, encryption, or audit logging.
- Exporting, copying, printing, or transmitting patient data outside the approved workflows built into the application.
- Viewing or searching for records of patients outside your job responsibilities ("browsing"), even out of curiosity.
- Using another user's credentials, or knowingly allowing anyone else to use your own.
- Installing or connecting unauthorized software, browser extensions, or integrations that could expose PaceSetter data.
4. Incident Reporting
Report any suspected security incident, a lost or stolen device with access to PaceSetter, or any unauthorized data exposure to your organization's administrator immediately. PaceSetter Healthware LLC personnel report internally per the Incident Response Runbook (IRP-2026-01).
5. Acknowledgment & Enforcement
Every user must accept the current version of this policy at login before accessing PaceSetter. Acceptance (user, version, and timestamp) is recorded and auditable. When this policy is materially revised, its version number is incremented and all users are re-prompted to review and re-accept before continuing.
6. Consequences
Violation of this policy may result in suspension of PaceSetter account access by PaceSetter Healthware LLC. Any further disciplinary action is determined by the user's employing organization under its own HIPAA compliance and personnel policies.