This portal handles protected health information (PHI) from EMS patient care reports. Here is what it collects, how it’s used and how it’s protected.
What we collect
- Chart data read from the ESO report: incident details, patient age, sex, date of birth, history, medications, vital signs, treatments and the narrative.
- Crew information for the call: names, employee IDs, certification and role.
- Review data: findings, reviewer notes, scores and feedback text.
- Account and activity data for portal users: name, email, role, sign-in times and an audit log of actions.
What we never store
- The PDF itself. The ESO report is read inside your web browser and is never uploaded to the server.
- The patient’s name. It’s removed in your browser before anything is sent, and removed again on the server as a safeguard.
- Feedback letters. They’re generated on demand when downloaded. Only a record that a letter was created is kept.
How we use it
- Only for EMS quality assurance and quality improvement: reviewing documentation, giving feedback to crews and tracking quality trends.
- Reviewers grade charts blind. Crew names are hidden during review and appear only on the final letters and in administrator metrics.
- Records are kept until an administrator deletes them.
How we keep it private
- Encryption: chart data, reviewer notes and feedback are encrypted in the database (XChaCha20-Poly1305). The key is stored separately from the database.
- Secure connection: all traffic is encrypted with HTTPS.
- Access control: individual accounts with roles (administrator, reviewer), automatic sign-out after inactivity, and account lockout after repeated failed sign-ins.
- Accountability: sign-ins, chart views, uploads, changes and letter downloads are recorded in an audit log.
AI-assisted feedback
If a reviewer chooses Generate AI feedback, a de-identified copy of the chart is sent to OpenAI’s API with the reviewer’s findings and notes, to draft the feedback wording. Before sending, the portal removes the patient’s name, date of birth, address, phone, insurance and account numbers and the incident number, and replaces crew names with “Crew Member A/B”. Nothing is sent to the AI unless a reviewer clicks the button.
Your responsibilities
- Use the portal only for authorized QA/QI work, and don’t share your account.
- Treat letters and anything downloaded as confidential quality improvement records.
- Delete local copies of ESO PDFs once they’re uploaded, unless you need them for another authorized purpose.
- Report any suspected privacy concern to the QA/QI administrator right away.
Questions about this notice or a record in the portal? Contact your QA/QI administrator.