Current website behavior
What the PHP package does.
Production hosting, email, analytics, LMS, CRM, payment, and vendor decisions can change the privacy posture. Those systems require a revised notice and formal review before activation.
| Function | Current behavior | Control requirement |
|---|---|---|
| Public browsing | Loads local pages, styles, images, and scripts. No third-party advertising or analytics code is included. | Review hosting logs, cookie behavior, CDN, analytics, and vendor contracts before production. |
| Session cookie | A first-party PHP session supports CSRF protection and temporary form-status messages. | Use HTTPS, secure cookie settings, appropriate session lifetime, and hosting security. |
| Contact, discovery, and cohort forms | Collect limited administrative information and store validated submissions in protected server-side JSONL files; optional email routing can be enabled. | Use private storage outside the web root, least-privilege access, retention rules, backups, incident response, and monitored ownership. |
| CE / learning organizer | Stores the user’s personal entries in that browser’s local storage and permits a local JSON download. | The record is not automatically transmitted or verified and is not an official Reach One, board, state, or university transcript. |
| Transcript verification | Checks a controlled local registry by record ID and returns limited status information. | Establish issuance, correction, revocation, identity, audit, retention, and registrar procedures before issuing live records. |
| Learner portal | No learner authentication or production LMS connection is active in this package. | Complete privacy, security, accessibility, identity, role-permission, support, and record-governance review before activation. |
Information principles
Need, notice, separation, access, retention, and correction.
Minimum necessary
Ask only for information reasonably needed to route or respond to the administrative purpose.
Purpose separation
Training, employment, university, supervision, credential, and clinical records remain in their authorized systems.
Access discipline
Named roles receive only the access required for their responsibility, with review and removal when the role changes.
Retention and deletion
Each record class requires a defined retention period, litigation/hold process, secure deletion method, and owner.
Correction
Records must support transparent correction without silently obscuring the original controlled entry.
Incident response
Suspected loss, unauthorized access, misrouting, or disclosure requires prompt containment, assessment, documentation, notice, and corrective action.
Questions and requests
Use the general contact channel without adding sensitive records.
Email contact@reachoneclinicalservices.com or call (513) 518-5596. Describe the administrative privacy issue at a high level. Reach One will identify the appropriate secure channel when additional information is necessary.
