Skip to main content

OCRS Policy

OCRS Security & Trust

This page summarises, at a level suitable for procurement review, the security and privacy practices implemented in the Occupancy & Capacity Reporting System. It deliberately omits configuration detail, internal endpoints and rule definitions.

Effective date
September 7, 2026
Last updated
September 7, 2026
Version
1.0.0-draft
Policy owner / operator
the OCRS platform operator (legal entity pending owner confirmation) — Occupancy & Capacity Reporting System
Status
Implemented — pending legal/owner review

1. Platform model

OCRS is a multi-tenant reporting platform with a fixed hierarchy of state jurisdiction, provider organization and facility. Every record is owned by an organization and a facility, and every request is evaluated against the requesting user's role and organization scope before data is returned.

2. Identity and access control

  • Named individual accounts with email verification and administrative approval before activation. There is no anonymous or self-activating sign-up.
  • Role-based access using a defined role set — state reviewer, organization administrator, provider administrator, facility manager, reporter and read-only auditor — with roles held in a dedicated authorization table rather than on user profiles.
  • Multi-factor authentication is required for global administrator access.
  • Least-privilege administrative access, with an audited role-preview capability that is read-only.
  • Accounts are deactivated rather than deleted, preserving the audit record.

3. Tenant isolation

Authorization is enforced at the data layer, not only in the interface: stored records carry row-level authorization so a request authenticated as one organization's user cannot read or modify another organization's records, including by manipulating identifiers in a URL or calling the API directly. Cross-tenant isolation and per-role authorization are exercised by an executable verification suite that runs against the production system and records its results immutably.

4. Data handled

OCRS handles facility-level aggregate occupancy and capacity information — bed configuration, bed status, census submissions and report artifacts — together with account, organization and facility records. The product provides no fields for patient identity, contact or clinical information, and users acknowledge at registration that Protected Health Information must not be entered unless expressly authorized by the responsible state authority. See the Privacy Policy.

5. Encryption

All traffic to the public site, the application and the API is served over encrypted transport (HTTPS/TLS). The platform runs on managed cloud database, storage and authentication services, and passwords are held only as salted hashes by the managed authentication service.

Pending legal/owner review: Specific encryption-at-rest, key-management and cipher statements will be published only once confirmed in writing against the current hosting configuration.

6. Audit and accountability

  • An append-only audit record captures sign-in events, multi-factor challenges, account and role changes, census submissions, report generation, transmission and delivery outcomes.
  • Each event records the acting user or system identity, the organization and facility context, the action, the target record, the result and the time, plus a correlation identifier for the run it belongs to.
  • Audit records, census submissions and generated report artifacts are not editable or deletable through the application.
  • Administrators can review audit history and delivery history in the product.

7. Reporting safeguards

  • Scheduled reporting is idempotent, so a reporting cycle cannot be duplicated for the same facility and window.
  • Production report recipients must be explicitly activated; verification and test activity is confined to sandbox routing and cannot deliver to production recipients.
  • Production screens and statistics are restricted to production records, separated from sandbox, test and demo data by an explicit environment classification.
  • Delivery outcomes, retries and failures are recorded and reviewable.

8. Verification and change management

Releases are gated by executable verification suites covering authorization, tenant isolation, reporting workflow, accessibility, mobile behaviour, performance and public-site integrity. Runs execute against the live system and each result is written as an append-only verification record with the build version and timestamp. Automated dependency and platform security scanning is run against the project.

9. Availability and continuity

OCRS runs on managed cloud infrastructure with managed database backups, and the platform records a verified backup configuration and recovery-rehearsal attestation as part of its launch controls.

Pending legal/owner review: Backup frequency, retention, point-in-time recovery window, recovery time and recovery point objectives, and the date of the last recovery rehearsal are held in the operator's attestation record and are published only after owner review.

10. Subprocessors and hosting

OCRS uses third-party managed services for application hosting, database and authentication, file storage and outbound transactional email.

Pending legal/owner review: A named subprocessor list with roles, hosting regions and contractual terms, and any data-processing addendum, is provided on request following owner review.

11. Compliance

Pending legal/owner review: OCRS makes no certification or regulatory compliance claim on this page. No SOC 2, ISO 27001, HIPAA, StateRAMP, FedRAMP or equivalent attestation is asserted. Any compliance statement must be supported by a completed assessment and approved by the policy owner and counsel before publication.

12. Reporting a security concern

Report suspected vulnerabilities, account compromise or misuse to admin@ocrsportal.org with the subject line "Security". Please include enough detail to reproduce the issue and avoid accessing, modifying or retaining any data that is not your own. Do not run scanning or load testing against the platform without written authorization. Reports are acknowledged and triaged by the OCRS operator.

What helps us investigate: the affected URL or screen, the steps to reproduce, the date and time, and what you observed. Please report privately first and give OCRS a reasonable opportunity to remediate before publishing details. This page sets no response-time, remediation, reward, acknowledgement, immunity or safe-harbour commitment; any such commitment requires owner and legal approval before publication.

This channel is also published for automated discovery at /.well-known/security.txt (RFC 9116).

For procurement questionnaires or a security review package, use the contact form.

Questions about this document

Write to admin@ocrsportal.org or use the contact form. Include the document title and version identifier shown above.