This premium domain and site are available for acquisition. Owned byArrowTech Marketing.Inquire now →
Legal & Compliance

Data Handling & HIPAA Disclosure

How we protect candidate and facility data with HIPAA-compliant practices.

Last updated: January 2026

1. Our commitment to data protection

Falcon Locums handles sensitive professional data, including medical licenses, board certifications, and credentialing documents. While we are not a covered entity under HIPAA in all scenarios, we maintain full HIPAA-compliant infrastructure to safeguard protected health information (PHI) and personally identifiable information (PII) that may flow through our recruitment processes.

2. Encryption

  • In transit: All data submitted via falconlocums.com is transmitted over TLS 1.2+ encrypted channels (HTTPS).
  • At rest: Uploaded documents are stored in encrypted object storage with server-side encryption (AES-256) or a HIPAA-eligible DMS.
  • Backups: Encrypted backups with restricted key access.

3. Access controls

  • Role-based access control (RBAC) — only authorized recruiters and credentialing staff access candidate files.
  • Multi-factor authentication (MFA) required for all internal systems.
  • Audit logging of document access and downloads.
  • Principle of least privilege — access is scoped to the minimum necessary for each role.

4. Document handling

Documents uploaded via the Candidate Portal (CVs, licenses, certifications, DEA registrations) are processed as follows:

  1. Validated for file type and size at the API layer.
  2. Streamed to encrypted storage — never logged in plaintext.
  3. Accessed only by authorized personnel for verification.
  4. Retained per regulatory requirements, then securely deleted.

5. Business associate agreements (BAAs)

Falcon Locums executes a Business Associate Agreement (BAA) with every covered entity client. We require BAAs with all subprocessors that handle PHI.

6. Incident response

We maintain an incident response plan covering detection, containment, notification, and remediation. In the event of a data breach affecting PHI, we notify affected individuals and regulators as required by applicable law.

7. GDPR alignment

For EEA residents, we honor GDPR rights as described in our Privacy Policy, including data subject access requests, erasure, and portability.

8. Candidate responsibilities

  • Upload only documents you are authorized to share.
  • Do not include unnecessary PHI (e.g., patient records) in uploaded files.
  • Use secure email when corresponding about sensitive credentials.

9. Contact

For data protection inquiries, contact our Data Protection Officer at [email protected].

Questions about your data?

Contact our Data Protection Officer at [email protected] or call (800) 555-0100.