OCRS Policy
OCRS Privacy Policy
This policy describes the information the Occupancy & Capacity Reporting System (OCRS) collects from participating organizations and their authorized users, how that information is used, and the controls implemented in the platform today.
- Effective date
- September 7, 2026
- Last updated
- September 7, 2026
- Version
- 1.0.0-draft
- Policy owner / operator
- the OCRS platform operator (legal entity pending owner confirmation) — Occupancy & Capacity Reporting System
- Contact
- admin@ocrsportal.org
- Status
- Implemented — pending legal/owner review
1. Scope of this policy
OCRS is an operational reporting platform used by state agencies, provider organizations and licensed residential care facilities to record and report bed capacity and occupancy. This policy covers the OCRS public website and the authenticated OCRS application. It does not cover the internal systems of participating organizations or state agencies.
2. Occupancy data is not patient data
OCRS is built for facility-level, aggregate occupancy and capacity reporting: bed counts, bed availability, bed status, level-of-care groupings and submission history. The product does not provide fields for patient names, contact details, diagnoses, treatment records or clinical notes, and users are instructed during registration not to enter Protected Health Information unless expressly authorized by the responsible state authority.
Some bed records support broad, non-identifying operational attributes such as an age band or an expected admission or discharge indicator. These exist to support capacity planning and are not intended to identify an individual.
3. Information OCRS collects
- Account information. Name, work email address, assigned role, organization and facility assignment, account status, and authentication records managed by the platform's authentication service. Passwords are stored only as salted hashes by that service; OCRS never receives them in readable form.
- Registration information. The organization, facility, licensing and reporting-authority details supplied when access is requested, together with the acknowledgments recorded at registration.
- Organization and facility information. Organization and facility names, OCRS facility identifiers, jurisdiction, addresses and geographic coordinates used for mapping, licensed bed configuration and contact details.
- Occupancy and capacity reporting data. Census submissions, bed configuration and bed status, submission timestamps, generated report artifacts and delivery records.
- System and audit information. An append-only audit record of sign-in events, multi-factor challenges, account changes, census submissions, report generation and report delivery, including the acting user or system identity, the affected organization or facility, the action, the result and the time.
- Technical information. Session storage used to keep you signed in, and standard request information processed by the hosting and email infrastructure. OCRS does not run advertising trackers and does not sell information.
4. How OCRS uses information
- Authenticating users and enforcing role-based and organization-scoped access.
- Recording, validating and reporting facility occupancy and capacity.
- Generating and delivering scheduled and on-demand capacity reports to authorized recipients.
- Administering accounts, approvals, organization status and platform configuration.
- Maintaining audit history for accountability and compliance review.
- Sending operational email: verification, approval decisions, password resets, reporting reminders and security notices.
- Diagnosing errors and maintaining the reliability and security of the service.
5. Authorized disclosure
Occupancy and capacity submissions are visible to authorized reviewers of the state jurisdiction the reporting facility belongs to, and to authorized administrators of the facility's own provider organization. Access is enforced per request at the database level, so users of one organization cannot read another organization's records.
OCRS also discloses information to the service providers described below, and where disclosure is required by law or is necessary to protect the security of the service.
Pending legal/owner review: Any additional statutory reporting obligations, public-records handling, or agency data sharing agreements specific to a deployment must be confirmed by the policy owner and counsel before being stated here.
6. Service providers
OCRS runs on managed cloud infrastructure and uses third-party services for application hosting, the managed database and authentication service, file storage and outbound transactional email. These providers process information on OCRS's behalf in order to deliver the service.
Pending legal/owner review: A named subprocessor list, with each provider's role, processing location and contractual terms, is prepared separately and published only after owner review.
7. Security
Controls implemented in the product today include encrypted transport for all traffic, row-level authorization on stored records so each request is limited to the requester's organization and role, mandatory multi-factor authentication for global administrator access, email verification and administrative approval before an account is activated, and an append-only audit trail of security-relevant events. See the Security & Trust page for procurement-level detail.
No service can guarantee absolute security. Report a suspected vulnerability or account compromise to admin@ocrsportal.org.
8. Retention
Census submissions, report delivery records and audit events are retained as an append-only historical record and are not edited or deleted through the application, so that reporting history remains verifiable. Account records are retained while an account is active and are deactivated rather than erased when access ends, to preserve the integrity of the audit trail.
Pending legal/owner review: Specific retention periods, including data-retention limits associated with individual service plans and any archival or disposal schedule, require owner and legal confirmation before publication.
9. Requests about your information
Accounts are created and administered by the participating organization or agency, so requests to correct account details or end access should normally be made to your OCRS organization administrator. You may also write to admin@ocrsportal.org and OCRS will route the request to the responsible administrator. Requests that would alter the append-only reporting or audit record cannot be granted.
Pending legal/owner review: Statutory privacy rights that may apply to a given deployment and the formal response timelines for them are subject to legal review.
10. Changes to this policy
Material changes are published on this page with a new version identifier and an updated effective date. Continued use of OCRS after an update constitutes acknowledgment of the published version.
11. Contact
Policy owner and platform operator: OCRS — Occupancy & Capacity Reporting System. Email admin@ocrsportal.org, or use the contact form.
Questions about this document
Write to admin@ocrsportal.org or use the contact form. Include the document title and version identifier shown above.
