Ataana Visits

Privacy Policy

A service of Ata&Ana LLC (dba Ata&Ana Home Health Agency)

A service of Ata&Ana LLC (dba Ata&Ana Home Health Agency)

Effective: June 1, 2026

Last updated: June 1, 2026

At a glance

We do not sell your data

We do not sell your personal information, and we do not use it for third-party advertising or behavioral profiling.

Location verifies visits

GPS is collected at visit check-in and check-out to meet federal and state Electronic Visit Verification rules, never for advertising.

Records are kept by law

Because the App creates medical and Medicaid billing records, retention periods are set by law and are typically at least six years.

Authorized workforce only

Ataana Visits is a private tool for Ata&Ana’s employees and contractors. It is not a consumer product and is not directed to children.

Section 01

Overview

Overview

This Privacy Policy explains how Ata&Ana LLC, doing business as Ata&Ana Home Health Agency (“Ata&Ana,” “we,” “us,” or “our”), collects, uses, shares, secures, retains, and deletes information in connection with the Ataana Visits app (the “App”).

The App is a private, employee-only tool used by Ata&Ana’s authorized workforce (employees and contractors) to verify home-health visits, record time, capture signatures, and document client care. This Policy applies to information processed through the App and the corresponding pages on ataanah.com. By using the App, you acknowledge this Policy.

Section 02

HIPAA and the Two Kinds of Information

HIPAA and the Two Kinds of Information

The App handles two distinct categories of information, governed by different rules:

  • Your personal information as an App user (an employee or contractor) — such as your identity, login, device, location, and time records. This Policy describes how we handle that information.

  • Protected Health Information (“PHI”) about clients that you enter or access while doing your job — such as care notes, services delivered, and client signatures. PHI is governed primarily by the Health Insurance Portability and Accountability Act (“HIPAA”), the HITECH Act, Ata&Ana’s HIPAA policies, and applicable state law. Clients’ rights regarding their own PHI are described in Ata&Ana’s Notice of Privacy Practices, provided separately to clients. Vendors that process PHI on our behalf do so under Business Associate Agreements.

Section 03

Information We Collect

Information We Collect

We collect only what is needed to operate the App and to meet legal and program requirements.

a. Identity and account information. Your name, employee/contractor identifier, username, and authentication credentials. Accounts are issued and controlled by Ata&Ana; users do not self-register.

b. Visit and location information. To verify that home-health visits actually occurred — as required by federal and state Electronic Visit Verification (EVV) rules — the App may collect the date, time, and geographic location (GPS) of visit check-in and check-out, the service performed, the client served, and the worker providing the service.

c. Time and work records. Clock-in/clock-out times, hours, shift notes, and related entries used for payroll and billing.

d. Signatures. Electronic signatures that you and clients (or authorized representatives) provide to confirm services.

e. Care documentation (PHI). Information you enter about clients in the course of providing care. See Section 2.

f. Device and usage information. Device type, operating system, app version, unique device or installation identifiers, IP address, crash data, and activity logs used for security, troubleshooting, and audit.

g. Communications. Information you provide when you contact us for support or to make a report.

We do not knowingly collect information from anyone under 18. The App is not directed to children.

Section 04

How We Collect Information

How We Collect Information

We collect information (a) directly from you when you log in, enter records, capture signatures, or contact us; (b) automatically from your device when you use the App (for example, location at check-in, device and log data); and (c) from Ata&Ana, which provisions your account and assignments.

Section 05

How We Use Information

How We Use Information

  • Authenticate you and secure access to the App;

  • Verify visits and meet EVV and program-integrity requirements;

  • Calculate and process payroll;

  • Create and maintain medical and billing records and submit claims to Medicaid and other payers;

  • Meet regulatory, audit, and compliance obligations (HIPAA, CMS, Virginia DMAS, and other federal, state, and local requirements);

  • Detect, investigate, and prevent fraud, waste, abuse, and security incidents;

  • Provide support and respond to your reports;

  • Maintain audit trails as required by law; and

  • Comply with legal obligations and enforce our Terms.

We do not sell your personal information, and we do not use it for third-party advertising or behavioral profiling.

Section 07

How We Share Information

How We Share Information

We share information only as needed and as permitted by law:

  • Payers and government programs — Medicaid, Virginia DMAS, CMS, and other insurers/payers, for claims, EVV, and program integrity.

  • Service providers (processors) — vendors that host, store, or support the App (such as cloud hosting and EVV systems) under contract, and under Business Associate Agreements where PHI is involved. They may use the information only to provide services to us.

  • Regulators and authorities — when required by law, audit, or subpoena, or to report fraud, waste, abuse, or suspected abuse or neglect of a client.

  • Legal and safety — to comply with law, enforce our Terms, or protect the rights, safety, and property of Ata&Ana, our clients, our workforce, or others.

  • Business transfers — in connection with a merger, acquisition, or asset transfer, subject to this Policy and applicable law.

We do not sell personal information.

Section 08

Data Retention

Data Retention

We retain information for as long as needed to provide the App and to meet legal, program, audit, and recordkeeping requirements. Because the App creates medical and Medicaid billing records, retention periods are generally set by HIPAA, CMS, Virginia DMAS, and other applicable law, and are typically at least six (6) years, and in some cases longer. When information is no longer required, we delete or de-identify it in accordance with our retention schedule.

Section 09

How We Protect Information

How We Protect Information

We use administrative, physical, and technical safeguards designed to meet the HIPAA Security Rule, including encryption of data in transit and at rest, access controls and unique user authentication, audit logging, and limiting access on a least-privilege, minimum-necessary basis. You also play a role: keep your credentials confidential and secure your device. No system is perfectly secure, but we work to protect your information and to respond promptly to any incident.

Section 10

Account and Data Deletion

Account and Data Deletion

Accounts are issued and managed by Ata&Ana. To request deletion of your account or associated personal data, contact us at services@ataanah.com or 571-449-7402.

Because the App creates medical and government-billing records, we are required to retain certain information even after your access ends — for example, to meet HIPAA, CMS, Virginia DMAS, audit, fraud-prevention, security, and other legal obligations. We will delete information that we are not required to retain.

Section 11

Location Information

Location Information

The App may use your device’s location to verify visit check-in and check-out, as required by EVV rules. Location is collected in connection with your work duties. You can control location permissions through your device settings; however, disabling location may prevent the App from verifying visits and may affect your ability to perform your job. We do not use this location data for advertising.

Section 12

Your Privacy Rights

Your Privacy Rights

Depending on where you live, you may have rights under laws such as the Virginia Consumer Data Protection Act (VCDPA) or similar laws — for example, to access, correct, or delete certain information. Some of these laws contain exceptions for employment data and for information governed by HIPAA. To make a request, contact us using the details below; we will respond as required by applicable law and may need to verify your identity.

Section 13

Children’s Privacy

Children’s Privacy

The App is intended only for authorized adult workforce members (18 and older). We do not knowingly collect personal information from children. If you believe a child has provided information, contact us and we will address it.

Section 14

Third-Party Services

Third-Party Services

The App may rely on third-party infrastructure and tools, such as cloud hosting and EVV systems. These providers process information on our behalf under contract and, where PHI is involved, under Business Associate Agreements.

Section 15

Where Information Is Processed

Where Information Is Processed

Information is processed and stored in the United States. If we ever process information outside the U.S., we will do so consistent with applicable law and this Policy.

Section 16

Changes to This Policy

Changes to This Policy

We may update this Policy from time to time. When we do, we will revise the “Last Updated” date and, where appropriate, provide additional notice. Your continued use of the App after an update means you accept the updated Policy.

Section 17

Contact Us

Contact Us

Company

Ata&Ana LLC (dba Ata&Ana Home Health Agency)

Attn

Zahra Siahi, Compliance Officer

Mailing address

8304 Old Courthouse Rd, Unit D, Vienna, VA 22182, USA

Illustration of a caregiver supporting an older adult

Ata&Ana

Ata&Ana

To us, you’re family.

To us, you’re family.

Contact

(571) 449-7402

services@ataanah.com

© 2012 Ata&Ana Home Health Agency. Licensed by the Virginia Department of Health.

© 2012 Ata&Ana Home Health Agency. Licensed by the Virginia Department of Health.