Privacy Policy
Last updated
JBH Pulse is a business-to-business analytics platform operated by JBH Consulting Group, LLC (d/b/a JBH) for hospital and health-system clients under contracted engagements. This policy explains what the platform collects, what it deliberately does not, and how that data is protected.
What Pulse does not collect
This belongs first because it is the most common question from hospital security teams. Pulse does not store, receive, or process:
- Protected health information (PHI) of any kind
- Patient-identifiable information, or personally identifiable information for patients
- Clinical or electronic health record (EHR) data
- Claims, billing detail, remittances, or line-item invoices attributable to individual patients
Because Pulse does not handle PHI, a HIPAA Business Associate Agreement is not required for the platform as it operates today. Should any future module ingest individual-level data, that classification is re-evaluated before the module ships.
What Pulse does collect
Client operational data. Provided by the hospital client or its designated vendors: vendor spend, general-ledger roll-ups, departmental and cost-center summaries, food-and-nutrition and environmental-services productivity, quality and usage measures, and aggregate average daily census. Census is stored as a facility-level count, never as individual patient records.
Platform account information. For each authorized user: name, work email address, assigned role, and the facilities and service lines they are permitted to see. Authentication is handled by Clerk; Pulse does not store passwords.
Operational and audit records. Access events, data changes, and administrative actions are recorded in a per-tenant audit log, together with technical diagnostics needed to keep the service reliable and secure.
Our role, and who controls the data
For client operational data, JBH Advisory Group acts as a service provider processing data on the client's behalf and on its instructions. The hospital client owns and controls its data. If you are an employee of a client health system and want to know how your organization governs the data it sends to Pulse, that question is best directed to your own organization; we will support any request it makes of us.
How the data is used
- To deliver the analytics, reporting, and benchmarking the client has contracted for
- To provide support, investigate issues, and maintain an audit trail
- To secure the platform and detect misuse
- To maintain, improve, develop, and enhance the platform itself
- To create aggregated, anonymized, and de-identified benchmark, statistical, and analytical information
On that last point, plainly: peer benchmarking is a core part of what JBH Pulse does, and client services agreements grant JBH Advisory Group a continuing right to create and publish aggregated, anonymized, de-identified benchmark and statistical information derived from client data — a right that survives the end of an engagement. That information is constructed so that no individual client or facility can reasonably be identified from it. If your organization needs to understand exactly how that works, the governing clause is in your services agreement and we will walk through it with you.
JBH Pulse does not sell client data. There is no advertising on the platform, no advertising or third-party tracking technology embedded in it, and client data is not used to train any external AI model.
Cookies
jbhpulse.com uses strictly necessary cookies only: a session cookie set by our authentication provider to keep you signed in, and a preference cookie that remembers the last health system you were viewing so you return to it on your next visit. There are no advertising, marketing, or third-party analytics cookies. Blocking the session cookie will prevent sign-in from working.
Subprocessors
Pulse relies on a small set of United States-based subprocessors, each operating under its own SOC 2 Type II or equivalent attestation:
| Subprocessor | Purpose | Region |
|---|---|---|
| Vercel | Application hosting and storage for uploaded source files | United States |
| Neon | PostgreSQL database | United States |
| Clerk | Identity, authentication, and multi-factor authentication | United States |
| Anthropic | Optional AI assistance. Currently disabled platform-wide — with no API key configured the platform makes no external AI call. | United States |
How the data is protected
- Tenant isolation. Every client is a separate tenant, enforced by PostgreSQL row-level security policies at the database layer rather than by application code alone. Cross-tenant access by advisory staff requires an explicit, audit-logged switch.
- Encryption. TLS 1.2 or higher in transit; AES-256 at rest for both the database and uploaded source files.
- Authentication. Multi-factor authentication is required for administrative roles. Federated SAML single sign-on is supported for client identity providers.
- Authorization. Role-based access control scoped by system, tenant, facility, department, and module.
- Audit logging. Every data change, access event, and administrative action is recorded per tenant.
- Infrastructure. United States hosting. The database is reachable only over TLS through a managed connection pool; there is no publicly reachable database endpoint and no database credential is ever present in the browser.
- No client-side footprint. Pulse is delivered entirely in the browser. No software is installed on client endpoints and there is no remote access into client networks.
Retention
Audit logs are retained for the term of the client agreement plus one year, and are available to the client on written request. Retention is a floor rather than a storage strategy: older periods move to archival storage rather than being discarded, and no record inside the committed window is deleted.
Client operational data is retained for the term of the agreement. Following expiry or termination, a client may request an export of its data in a commonly used electronic format; under our standard terms that request should be made within 90 days. After that, JBH Advisory Group may retain archival copies to the extent needed for legal, regulatory, compliance, audit, backup, disaster recovery, and benchmarking purposes, as the applicable services agreement permits. Your own agreement governs these periods and prevails over this summary.
Security incidents
JBH Advisory Group maintains administrative, technical, and physical safeguards designed to protect client data against unauthorized access, use, disclosure, alteration, or destruction. Where we become aware of unauthorized access to a client's data, we notify that client and work with its security and IT teams on investigation and remediation.
Notification timeframes and any further obligations are set by the client's services agreement and by applicable law, and those control over this summary.
Requests and questions
Authorized users may request access to, correction of, or deletion of their platform account information by writing to jbhadmin@jbhadvisorygroup.com. Requests concerning client operational data are fulfilled through the hospital client that owns it. Full contact details are on the contact page.
Changes to this policy
Material changes are reflected in the “last updated” date above. Where a change affects how client data is handled, clients are notified directly rather than by a silent revision to this page.