North StarNurse Delegation
Terms of Use Privacy Policy Acceptable Use
←

Acceptable Use Policy

Effective 2026-09-22Draft — under review by the agency's counsel

What this says, in short

This is the rulebook for using the staff platform. Open client records only to care for clients — every opening is recorded — keep your sign-in to yourself, and keep client information inside the platform, not in email, texts, or outside tools. If something goes wrong, report it to the office right away; honest, good-faith reporting is protected.

Contents

  1. Who does this policy apply to?
  2. What is the one rule everything else follows from?
  3. Which records can I open, and how much?
  4. Who can use my sign-in?
  5. What about the device I work on?
  6. Where does client information belong?
  7. How do I use the AI features?
  8. What is never allowed?
  9. What do I do if something goes wrong?
  10. What happens if this policy is broken?
  11. How does this policy fit with everything else?

1Who does this policy apply to?

This policy applies to everyone who signs in to the North Star Nurse Delegation staff platform: nurses, administrators, and the owner. Following it is a condition of using the platform and of working with North Star.

The platform is for staff only. Clients and families never sign in. Every account belongs to a member of our workforce, and every account holder is bound by HIPAA, by Oregon law, and by this policy.

The policy covers the platform itself and any client information you learn through it, wherever that information goes afterwards.

Owner & counsel: how staff formally acknowledge this policy — a signed acknowledgment at onboarding, or acceptance in the sign-in flow

2What is the one rule everything else follows from?

Client records exist so you can care for the client. That is the only reason to open one.

Every sign-in, every record you open, and every change you make is recorded in an audit trail that cannot be edited or erased. Nothing in the platform is anonymous, and nothing is quietly deleted.

If something in a record is wrong, correct it with an addendum. Records are never deleted or overwritten — that is by design.

Opening a record out of curiosity is a breach. It does not matter that you told no one. It does not matter that the client is a relative, a friend, a neighbor, or someone people are talking about. If you have no care-related reason to open a record, do not open it.

3Which records can I open, and how much?

The law calls this the minimum necessary standard. In practice it means: open the records of the clients you serve, look at the parts you need for the task at hand, and stop there.

Your access is set up to match your work, but no permission system is a substitute for judgment. If you can technically open something you do not need, that is not an invitation to open it.

If your work changes and your access no longer matches it, tell the office so it can be adjusted.

4Who can use my sign-in?

Only you. You sign in with your North Star Microsoft account (Microsoft Entra ID). We never see or store your password — Microsoft handles that. Accounts are created only by an administrator; there is no self-service sign-up.

  • Never share your sign-in. Not with a colleague covering a shift, not with a manager, not with anyone. Everything done under your account is recorded as done by you.
  • Never reuse your work password anywhere else. It should not appear on any other website or app.
  • Sign out on shared devices. If a computer or tablet is not exclusively yours, sign out when you finish.
  • Report suspected compromise immediately. If you think someone else may know your password or has used your account, tell the office right away — see the reporting section below.

North Star will never ask for your password. Not by email, not by text, not by phone, not on any web page. A page or a person that asks for your password is an attack. Do not answer it — report it.

5What about the device I work on?

  • Set a lock screen with a short auto-lock time on every device you use for work, and lock it when you step away.
  • Keep the device's operating system and browser up to date. Install updates when they are offered.
  • Never put client information in screenshots, photos of the screen, personal cloud storage, personal note apps, or anywhere else outside the platform.
  • If a device you use for work is lost or stolen, report it immediately.

Your browser stores only functional things for the platform — your theme, layout preferences, unsent drafts, and sign-in convenience. It is not a place where client records live, and you should not make it one.

6Where does client information belong?

The platform is where client information lives. It is built for that: access is controlled and everything is audited. Email, text messages, and chat are not built for it.

  • No client health information in email or text. Not names paired with diagnoses, not medication details, not care notes. If it belongs in the record, put it in the record — then, if needed, send a message that points a colleague to it.
  • No client details in access requests. When you ask for access or report a problem, describe what you need without pasting client information into the request.
  • Calendar entries carry initials only. Events pushed to your Outlook calendar show client initials, the time, and the address — never a diagnosis or anything else clinical. Keep it that way in anything you add or edit.

7How do I use the AI features?

Some parts of the platform can produce an AI-generated draft. These features are built into the platform and set up by the owner. Two rules apply.

Review every draft before you keep it. An AI draft is a starting point, not a record. You are responsible for the accuracy of anything you save, sign, or send. Read it, correct it, and only then keep it.

Never paste client identifiers into anything outside the platform. The platform's own AI features never send a client's name, date of birth, Medicaid ID, Social Security number, address, phone, or email from the record, and when one reads a document, the whole document goes to Microsoft under the agency's business associate agreement. Neither protection exists outside the platform. Personal AI tools, chatbots, translation sites, and search engines have no such rule and no agreement with us — client information must never be typed or pasted into them.

8What is never allowed?

The following are prohibited without exception:

  • Opening any client record without a care-related reason. Curiosity, concern, and personal connection are not care-related reasons.
  • Sharing client records or client information with anyone not entitled to receive it — inside or outside the agency.
  • Attempting to get around access controls, using someone else's account, or reaching records your role does not permit.
  • Probing, scanning, or testing the platform's security without written permission from the owner. If you find a weakness by accident, report it — do not explore it.
  • Scraping, mass-downloading, or bulk-exporting records outside workflows the owner has approved.
  • Using the platform for anything unlawful, or for anything other than North Star's work.

9What do I do if something goes wrong?

Report anything that puts client information or the platform at risk. That includes, among other things:

  • a password or account you suspect is compromised;
  • a lost or stolen device used for work;
  • client information sent to the wrong place — a mis-addressed email, a document left where others could see it;
  • a record you or someone else opened without a reason, even by accident;
  • a page, message, or phone call asking for your password;
  • a security weakness you stumble on.

Report it to the office: call 1-877-732-2631 or email info@nsndelegation.com. Speed matters more than certainty — report first, sort out the details after.

Reporting in good faith is protected. You will not face retaliation for honestly reporting a concern, including a mistake of your own. Finding problems early is exactly what we want.

10What happens if this policy is broken?

Violations are taken seriously, because our clients' trust depends on it. Depending on what happened, consequences may include:

  • suspension of your access while the matter is reviewed;
  • termination of your employment or working relationship with North Star;
  • notification of regulators or law enforcement, where the law requires it.

Some consequences are not North Star's to decide. Unlawful access to health records can carry personal liability under HIPAA and Oregon law, and licensed staff may face professional discipline.

An honest mistake, promptly reported, is treated very differently from concealment or intentional misuse.

Owner & counsel: have counsel confirm this sanctions language aligns with staff employment and contractor agreements and Oregon employment law

11How does this policy fit with everything else?

This policy sits alongside — it does not replace — your HIPAA training, your confidentiality agreement, and the professional obligations that come with your license. Where rules overlap, the stricter one applies.

Questions about this policy go to the office: info@nsndelegation.com or 1-877-732-2631.

North Star may update this policy. When it changes in a way that matters, you will be told.

Back to sign inAbout North Star