RohaChart
Home Sign in

Privacy

RohaChart Privacy Policy

Effective date: August 6, 2026

Roha IT Solutions LLC operates RohaChart, a hosted service and Windows desktop client for residential-care organizations. This policy explains how RohaChart processes personal information and protected health information (PHI).

Contents Scope Information we process How we use information How we disclose information Your choices and rights Retention and security Contact us

1. Scope and responsibilities

This policy applies to the RohaChart service, the RohaChart Windows desktop client, the public RohaChart website, and information submitted for onboarding or support. Customer organizations decide which authorized users may access RohaChart and why resident and workforce information is entered. Each customer remains responsible for its own privacy notices, legal permissions, record-management duties, and responses to residents and other individuals.

In this policy, Customer Data means information that a customer or its authorized users submit to, store in, or generate through RohaChart, including personal information and PHI.

When Roha IT Solutions LLC processes PHI for a customer that is a covered entity or business associate, the applicable Business Associate Agreement governs that processing. This policy does not replace a care facility's Notice of Privacy Practices.

2. Information we process

Depending on how a customer configures and uses RohaChart, we may process:

  • Organization and account information, such as facility names and addresses, licensing information, contact details, authorized-user names and email addresses, roles, credentials, facility assignments, authentication information, and MFA status.
  • Resident and care information, such as demographics, contacts, diagnoses, allergies, medications and administration records, vitals, assessments, care or service plans, incidents, documents, communications, billing records, and related PHI.
  • Operational and security information, such as user and device identifiers, actions performed, timestamps, IP address, request identifiers, audit history, and security or error records.
  • Subscription, integration, support, and outreach information, such as plan and billing status, customer-enabled integration records, implementation details, training requests, access-request or support messages, business contact details, and communication preferences. Payment providers process payment details under their own privacy practices.

We receive this information from customers and their authorized users, from integrations a customer chooses to enable, and automatically from devices and browsers when they connect to RohaChart.

3. How we use information

We use information as necessary to:

  • provide, administer, maintain, and support RohaChart;
  • authenticate users and enforce organization, facility, role, and permission boundaries;
  • perform customer-directed resident-care, medication, assessment, documentation, communication, reporting, and billing workflows;
  • maintain audit trails and detect, investigate, prevent, and respond to security or operational events;
  • provide onboarding, training, customer support, and service communications;
  • send requested or permissioned product information and maintain communication preferences;
  • meet contractual, regulatory, and legal obligations; and
  • use Customer Data as necessary to provide, secure, support, improve, and administer RohaChart under the applicable customer agreement and Business Associate Agreement, and use de-identified or aggregated information for product analytics, benchmarking, and reporting.

RohaChart processes sensitive resident and health information only when an authorized customer supplies it or directs its processing for care, documentation, compliance, or related operations.

4. Cookies, browser storage, and the desktop client

RohaChart uses essential session and security cookies to authenticate users, protect requests, and maintain secure sessions. The web application may store a non-credential identity snapshot and interface preferences in browser storage. RohaChart does not use Customer Data or PHI for third-party behavioral advertising.

Some pages retrieve public fonts or media from content-delivery providers. Those providers receive ordinary connection information, such as IP address, browser type, and request time, when the browser requests the resource.

The Windows desktop client displays the hosted RohaChart service in an isolated browser session with disk caching disabled. It clears its browser cache, cookies, browser storage, and authentication cache when the client quits. Information a user deliberately prints, exports, downloads, copies, or opens in another application is outside that automatic clearing process and remains subject to the customer's device and records policies.

5. How we disclose information

We may disclose information only as needed:

  • to the customer organization and its authorized users according to configured access controls;
  • to service providers and subcontractors that help host, authenticate, secure, communicate, bill, monitor, support, or operate RohaChart, subject to contractual safeguards and a BAA when required;
  • through integrations the customer chooses to enable, such as identity, pharmacy, payment, accounting, or messaging services;
  • to comply with law, legal process, regulatory requirements, or a valid government request; or
  • to protect the rights, safety, integrity, and security of customers, users, residents, Roha IT Solutions LLC, or the public.

Roha IT Solutions LLC processes and discloses Customer Data and PHI only for the purposes described in this policy and the applicable customer agreement. It does not sell or rent Customer Data or PHI, and does not use it for third-party targeted advertising.

6. Your choices and rights

Authorized users may review or correct information in RohaChart as their permissions allow, and customer administrators can manage account and facility access. Residents, family members, and customer workforce members should ordinarily direct requests about facility-controlled records to the facility that maintains those records. Roha IT Solutions LLC assists customers with access, amendment, accounting, export, restriction, return, or deletion obligations when required by the applicable agreement or law.

To ask about personal information that Roha IT Solutions LLC controls directly, or to request access, correction, deletion, or another privacy right available in your jurisdiction, email info@rohachart.com. We may need to verify your identity and authority before acting, and some information may be retained when required by law, contract, security, or record-integrity obligations. Promotional email recipients may also use the unsubscribe instructions in the message.

7. Retention and security

We retain Customer Data, audit records, system logs, and backups according to the applicable customer agreement, customer configuration, legal and regulatory requirements, and security and disaster-recovery practices. During the subscription term, customers may use available tools or request supported exports. After termination, information is returned or destroyed when feasible; information retained in backups, audit evidence, or because destruction is infeasible remains protected and is limited to the purpose requiring retention.

We use administrative, physical, and technical safeguards designed to protect information, including encryption protections, access controls, audit logging, secure authentication, network safeguards, and workforce security practices. No system can guarantee absolute security. Customers are responsible for configuring users and permissions appropriately and protecting their own devices, exports, and workflows.

8. Children and minors

RohaChart is a business service for care organizations and is not marketed directly to children. A customer may use RohaChart to maintain records about a resident who is a minor when permitted by law. In that situation, the customer is responsible for the legal authority, notices, and permissions required to provide and use the information, and Roha IT Solutions LLC processes it for the customer under the applicable agreement.

9. Changes to this policy

We may update this policy when RohaChart, our practices, or applicable requirements change. The current version will remain available at this URL and will show its effective date. We will provide additional notice when required by law or the applicable customer agreement.

10. Contact us

Roha IT Solutions LLC
Email: info@rohachart.com

Contract terms governing customer use of the service are available in the RohaChart SaaS Subscription Agreement.

RohaChart Residential-care operations software
Home Subscription agreement Privacy policy Contact © 2026 RohaChart