1. Introduction & scope
SHS TAR Agent is an internal Chrome/Chromium browser extension built by Safer Health Solutions ("SHS", "we", "us") for its own authorized billing staff. It automatically fills the Partnership HealthPlan (PHC) provider portal with Treatment Authorization Request (TAR) data drawn from the SHS RCM web app, so staff do not have to re-key member and service details by hand.
The extension is distributed privately (Unlisted) on the Chrome Web Store and is not a public consumer product. This policy covers the browser extension specifically — its data handling, storage, permissions, and security. It does not replace SHS's broader organizational privacy and HIPAA policies, which govern the SHS RCM app and the workplace more generally.
2. Information we process
To fill a TAR in the PHC portal, the extension processes protected health information (PHI) and personally identifiable information (PII) for the member on that request. Depending on the TAR, this may include:
- Member name
- Date of birth
- CIN / member ID
- Social Security number (SSN)
- Diagnoses (ICD-10 codes)
- Service and authorization details
- Provider details
The extension processes only the fields needed to fill the corresponding portal form — the minimum necessary for the task. It does not gather browsing history, keystrokes, or any data unrelated to the TAR being submitted.
3. How the information is used
The information is used for a single purpose: to pre-fill the PHC provider portal form that the user has open, using the TAR data from the SHS RCM app. When a biller clicks "Submit to MCP" on a TAR, the extension receives that TAR's data, locates the user's open PHC portal tab (or opens PHC Member Search), and populates the relevant fields.
The biller then reviews the pre-filled form and submits it within the PHC portal. The extension never submits a TAR on its own, and the data is not used for any purpose beyond this pre-fill.
4. How the information moves & is stored
All processing happens within the user's own browser. Data flows from the SHS RCM app tab, through the extension, into the PHC portal tab the user opened. It is not transmitted to any server operated by the extension.
While a submission is in progress, the payload is cached only in the browser's local extension storage (chrome.storage.local). This local cache is encrypted at rest using AES-GCM and is never synced to the cloud. It is automatically deleted after a short time-to-live (about 20 minutes) and when the user finishes the task.
5. What we do NOT do
- We do not sell or rent your data.
- We do not share data with any third party.
- We do not run advertising, tracking, analytics, or telemetry.
- We do not load or execute remote code.
- We do not use data for creditworthiness or lending decisions.
6. Permissions
The extension requests the least-privilege permissions it needs to do its job:
Temporarily cache the encrypted payload so it survives across the portal's multiple pages during a single submission.
Find and focus the correct PHC portal tab so the data lands in the right place.
Purge expired cached data automatically once its short time-to-live has passed.
The extension runs only on SHS app domains and the PHC portal domains. It has no access to any other website.
7. Data retention & deletion
Cached TAR data is short-lived by design. It is automatically purged after a short time-to-live (about 20 minutes) via the alarms permission, and it is cleared when the user finishes the task.
Uninstalling the extension removes all data it stored in local extension storage. Because nothing is synced to the cloud or sent to an external server, there is no separate copy for us to retain or delete elsewhere.
8. Security
The extension applies several safeguards: the cached payload is encrypted at rest with AES-GCM; permissions are kept to the least privilege needed; and messaging is origin-scoped so data only moves between the SHS app and PHC portal origins.
These extension-level protections are additional to SHS's primary safeguards. Endpoint full-disk encryption and staff access controls are managed by SHS and remain the main line of defense for devices used by billing staff.
9. HIPAA & regulatory context
Safer Health Solutions handles protected health information under applicable law and its own HIPAA policies. SHS TAR Agent is used within that context, by authorized staff, as part of SHS's regulated workflows. It is an internal operational tool, not a consumer service, and its use is governed by SHS's organizational compliance program.
10. Children's privacy
The extension is an internal business tool and is not directed to children. We do not knowingly collect information from children through the extension. Any member information processed relates to SHS's health-plan operations, not to any direct interaction with a child user.
11. Changes to this policy
We may update this policy as the extension evolves. When we do, we will revise the "Last updated" date above and communicate material changes to authorized staff through SHS's internal channels. Continued use of the extension after an update reflects the current policy.
12. Contact
Questions about this policy or the extension's data practices can be directed to: