E&E Technology LLC E&E Technology
  • Home
  • Our Apps
  • About
  • Contact
← Back to Home

Privacy Policy

EHR Scanning

Last updated: January 31, 2026

E&E Technology LLC ("we," "us," "our") operates the EHR Scanning mobile application (the "App"). This policy explains what data the App collects, how it's used, and how it's protected.

Who this app is for

EHR Scanning is a workplace tool used by hospital staff, provisioned and configured by their employer's IT department, to scan patient wristband barcodes and relay them to a clinician's own already-authenticated electronic health record (EHR) session running in a desktop browser. It is not a consumer health app, and it is not directed at the general public or at children.

Information we collect

Account information (via Microsoft sign-in). The App requires signing in with your organization's Microsoft (Entra ID) account. We receive your name, email address or username, and internal Microsoft account/tenant identifiers from Microsoft as part of that sign-in. We do not receive or store your Microsoft password — authentication is handled entirely by Microsoft.

Scanned barcode data. When you scan a patient wristband (or enter a code manually), that code is transmitted to our relay server and forwarded to your own signed-in browser session so it can populate a field in your EHR system. Depending on your hospital's wristband format, this code may constitute or be associated with patient health information. The App itself does not interpret, display, or retain the meaning of scanned codes — it relays an opaque value.

Shift PIN. After signing in, you set a short PIN to quickly unlock the App for the rest of your shift instead of signing in with Microsoft every time. This PIN is never transmitted anywhere and never stored in plain text: only a salted, heavily-hashed version is stored, encrypted, on your device. We cannot see or recover your PIN.

Camera. The App uses your device's camera solely to read barcodes in real time, on-device. Camera images and video are never saved, stored, or transmitted anywhere, by us or any third party.

Technical/connection data. As with any networked app, our servers necessarily process your device's IP address and standard connection metadata while a session is active. We do not use this for tracking or profiling.

Organization-managed settings. If your hospital manages this App through its mobile device management (MDM) system, your IT department may configure settings such as which relay server or Microsoft tenant the App connects to. This configuration is controlled by your employer, not by us, and is not personal data we collect about you.

What we do not do

  • We do not sell your data.
  • We do not use your data for advertising, and the App contains no advertising or analytics SDKs.
  • We do not access your photos, contacts, location, microphone, or files.
  • We do not share data with third parties except as described below.

Who we share data with

  • Microsoft, as the identity provider for sign-in. Your use of the App is also subject to Microsoft's own privacy practices for its identity platform.
  • Your own employer's systems, via the browser session you've already authenticated into — scanned codes are relayed only to the session you selected, matched to your own account and organization.
  • Cloud infrastructure providers, which host our relay server infrastructure, strictly as infrastructure processors — not as independent users of your data.

We do not share data with any other third party.

How we protect your data

  • All network communication between the App and our relay server uses encrypted TLS (wss://) connections; unencrypted connections are not permitted except for local development on the same machine.
  • Your shift PIN is protected with a salted hash (100,000 iterations) stored in your device's hardware-backed secure storage (Android Keystore), never in plain text.
  • The App blocks screenshots and screen recording while in use, and excludes all app data from device backups.
  • Session identity is independently re-verified against your authenticated Microsoft identity on every action — a nurse can only ever route scans to a session actually tied to her own account and organization.

Data retention

We do not retain scanned barcode values or Microsoft ID tokens after your session ends. Your shift PIN is cleared from your device automatically at sign-out, at the end of your shift window, or after repeated incorrect attempts. Connection logs and scan events are retained only for operational troubleshooting and security purposes, with automatic deletion after 30 days.

Your choices and rights

You may sign out of the App at any time, which ends your session and clears locally stored authentication data and your PIN. Because the App is provisioned by your employer for workplace use, some settings (such as which relay or Microsoft tenant you connect to) are controlled by your employer's IT department rather than by you individually. For questions about data handled by your employer's EHR system itself, contact your employer's privacy or compliance office.

To exercise privacy rights regarding data we control directly (such as requesting information about what we hold), contact us at info@eetechnologyllc.com.

Health data and regulatory compliance

Where this App is used by a HIPAA-covered entity (such as a hospital) or its workforce, any obligations regarding protected health information (PHI) are governed by a separate written agreement (e.g., a Business Associate Agreement) between E&E Technology LLC and that entity, not by this public-facing policy. This policy describes our general data-handling practices and does not itself constitute or replace any such agreement.

Children's privacy

The App is intended for use by adult healthcare workers as part of their employment and is not directed at, nor knowingly used by, children.

Changes to this policy

We may update this policy from time to time. We will revise the "Last updated" date above when we do. Continued use of the App after changes constitutes acceptance of the updated policy.

Limitation of liability

The App is provided "as is" and "as available." To the fullest extent permitted by law, E&E Technology LLC disclaims all warranties, express or implied, and is not liable for any indirect, incidental, or consequential damages arising from use of the App, including but not limited to reliance on relayed data accuracy. Nothing in this policy limits liability where such limitation is not permitted by applicable law.

Contact us

E&E Technology LLC
Email: info@eetechnologyllc.com
Website: eetechnologyllc.com

© 2026 E&E Technology LLC. All rights reserved.

Privacy Policy Terms of Service EHR Scanning Privacy Delete Account