Privacy Policy

Effective Date: June 2026


1. Our Privacy Approach

DEUN LLC (operating the National Implants Registry, "Sietch") is built on a "Privacy by Design" architecture. We do not store plain-text Social Security Numbers, dates of birth, or any other directly identifying patient information on our servers. Patient identifiers are converted into a one-way cryptographic hash before transmission and storage.

2. How Patient Identification Works

To enable cross-clinic implant identification, providers collect a patient's Social Security Number and Date of Birth at the point of care, with the patient's written consent. These values are combined and processed using a peppered HMAC-SHA256 cryptographic hash. Only the resulting hash is transmitted to and stored in our database. The original SSN and DOB are never persisted on our servers. The hash cannot be reversed to recover the underlying values without the secret pepper, which is held exclusively by DEUN LLC.

3. Information We Collect

4. Information We Do Not Store

5. Patient Consent

Before any record is created, the treating clinician must confirm that the patient has provided written consent for their de-identified record to be indexed in the Sietch registry. The clinician maintains the patient's original consent documentation in accordance with their own clinical recordkeeping practices.

6. HIPAA Compliance

DEUN LLC operates as a Business Associate to our subscribing clinics under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). We execute a Business Associate Agreement (BAA) with each subscribing clinic and maintain administrative, physical, and technical safeguards consistent with the HIPAA Security Rule. Our hash-based architecture is designed so that the data we store is not directly identifying, but we apply HIPAA-grade safeguards regardless.

7. Recall Notification

When the FDA publishes a recall affecting a device logged in our registry, we identify the originating clinic of each affected record and notify the clinic directly. The clinic — not DEUN LLC — is responsible for identifying and notifying the patient using their own clinical records. We never contact patients directly.

8. Data Sharing

We do not sell, rent, or share patient-linked records with third parties. Aggregate, de-identified data may be used internally for product improvement, system monitoring, and research purposes. Any future data partnership with a payer, OEM, or research organization will be disclosed in updates to this policy and limited to aggregate, de-identified data only.

9. Security

Our infrastructure runs on AWS with encrypted storage, enterprise authentication via Auth0, audit logging, and regular third-party security assessments. We have completed an independent penetration test by Casco Security and remediated all findings.

10. Data Retention

Patient-linked records are retained for the lifetime of the clinical relationship between the originating clinic and Sietch. If a clinic terminates its account, we retain the records in archived form to preserve the registry's value for future cross-clinic lookups. Clinics may request deletion of specific records by contacting support.

11. Your Rights

Patients with questions about records held about them should contact the originating clinic, which holds the unhashed identifiers required to locate any specific record. Clinics may request audit logs, data exports, or record corrections by contacting support@nationalimplantsregistry.com.

12. Updates to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to all subscribing clinics via email. The "Effective Date" at the top of this page reflects the most recent revision.

13. Contact

For questions about this policy or our privacy practices, contact support@nationalimplantsregistry.com.