Security and Compliance

Last updated: 2026-09-19

Template — review by counsel required before production use.

These pages are starter content for a youth-sports athletic-injury platform. Real deployment requires customization by a qualified attorney for your jurisdiction, your school district's legal posture, the actual subprocessors you've signed agreements with, and the specific risks of your operation. Atlerts (the software) does not constitute legal advice.

Atlerts is a product of Bridgelines Inc., a Delaware corporation. On this page, “Atlerts” and “the Service” mean the software, and “we”, “us” and “our” mean Bridgelines Inc. — the company that provides it and the party to any agreement with your school.

Atlerts holds every district to the same standard, regardless of which state it is in and regardless of whether that district is a covered entity under HIPAA. Where federal and state requirements differ, we apply whichever is stricter, as a single policy, to every customer. A district does not have to negotiate for the protections described here and does not have to tell us which rules apply to it.

The standard we hold

We operate to the HIPAA Security Rule (45 CFR §§164.308, 164.310, 164.312 and 164.316) as the technical and administrative baseline for all athlete health information, whether or not that information is protected health information in a given district's hands. Student records are additionally handled as education records under FERPA, and information about students under 13 under COPPA.

HIPAA is a minimum. Several states impose stricter duties on medical information, breach timing and student data than federal law does, and those duties are not preempted. The commitments below are set to the stricter figure in each case.

How the data is protected

  • Encrypted in transit (TLS 1.2+) and at rest.
  • Access is enforced in the database itself, by row-level security keyed to school and role — not by application code that could be bypassed. A member of staff at one school cannot read another school's records by any route.
  • Clinical detail is scoped by role. Coaches receive participation status — who is available and who is not — and not diagnoses, symptoms or treatment notes.
  • Two-factor authentication is required for staff accounts.
  • An append-only audit log records access to and changes of athlete records, satisfying §164.312(b). Entries cannot be edited or deleted by any application role.
  • Audit records are retained for at least six years, satisfying §164.316(b)(2).
  • Regular backups, with point-in-time recovery on production tiers.

Breach notification

We notify the affected district without unreasonable delay and in no case later than 30 days after discovery. HIPAA §164.410 allows 60 days for a business associate; a number of states require 30 or fewer, so 30 is what we commit to everywhere. Where a state requires faster notice than 30 days, that shorter period governs.

What we do not do with student data

These are commitments in every contract, not a description of current practice that could change:

  • We do not sell student data, and we do not transfer it as an asset in a sale except to a successor bound by these same terms.
  • We do not use student data for targeted advertising, on this service or anywhere else.
  • We do not build profiles of students for any purpose other than the educational and athletic purposes the district directs.
  • We do not use student data to train machine-learning models.

The district's data remains the district's

  • The district owns and controls its records. We hold them as a service provider acting on the district's instructions.
  • Parents and eligible students may inspect, review, obtain an electronic copy of, and request correction of the records we hold, through the district (HIPAA §164.524, FERPA §99.10). The record is downloadable from the dashboard.
  • On termination, the district's data is returned or deleted at the district's election.
  • We do not disclose athlete health information to anyone outside the district except as the district directs, as the family authorizes in writing, or as law requires.

Subprocessors and agreements

Our subprocessors are listed in the Privacy Policy, each bound by a written agreement prohibiting use of district data outside the scope of serving us. Where a district is a covered entity, we execute a Business Associate Agreement, and we hold corresponding agreements with the subprocessors that handle protected health information.

Districts commonly require specific contract terms covering data ownership, parental review, breach notice, restrictions on secondary use and deletion on termination. We include those terms as standard rather than by negotiation.

Contact

Security and compliance questions, including requests for our current subprocessor list or a Business Associate Agreement: atlerts@gmail.com