Staff Acceptable Use of the Portal
Version 2026-09-06
As a member of the MaxGen Labs workforce with access to the operations console, you can see and act on protected health information for every practice and every patient we serve. This policy says how that access is to be used. It applies alongside the HIPAA policies you have been trained on, and it is accepted again on every new version and at least once a year.
1. Minimum necessary
Open a patient's record, results, documents or messages only when the task in front of you requires it. Search for the record you need; do not browse. When a task can be done with less information (a sample id rather than a name, a status rather than a report), use less.
2. Your own credentials, always
Sign in only as yourself, with the multi-factor sign-in the portal requires. Never share your credentials, never sign in on another person's behalf, and lock or sign out of any workstation you leave. Every action is recorded under the identity that performed it.
3. Previews and "View as"
"View as" and "preview as the patient" show you what another person sees, so that you can support them. They are recorded as your session, they never save symptoms or accept an agreement on that person's behalf, and they are for support only. Do not use a preview to browse a practice's patients, and exit a preview as soon as the task is done.
4. No export outside audited paths
Copy results, reports or patient details out of the portal only through the download and delivery features that record the action. Do not paste patient information into email, chat, tickets, spreadsheets, screenshots, AI tools or any system outside the portal unless that system is approved for protected health information. Never put a patient name, date of birth or email address in a URL, a search box that lands in a log, or a subject line.
5. Invitations and addresses
Send a patient's sign-in invitation only to an address you have confirmed is theirs, from the record. Re-pointing a patient's address changes who can see their results; confirm before you do it, and note why.
6. Interpretation is not our role
Staff do not interpret results for patients or practitioners. Questions about what a result means go to the practitioner of record. If a patient contacts us directly, help them reach their practitioner and their own portal.
7. Report anything suspect, immediately
If you see access that looks wrong, a misdirected email, a lost device, a suspicious sign-in, or you make a mistake with patient information, report it to the Security Officer the same day. Reporting a mistake is expected and protected; hiding one is not.
8. Devices and networks
Use the portal only from devices that meet our workstation standards (current operating system, disk encryption, screen lock) and from networks you trust. Do not save reports to personal devices or personal cloud storage.
9. Sanctions
Access to patient information beyond what your role and task require, sharing credentials, exporting outside audited paths, or failing to report an incident are violations of this policy and of our HIPAA policies. Violations lead to retraining, loss of access, termination, and, where the law requires, reporting to authorities.
10. Questions
Ask the Security Officer or write to help@maxgenlabs.com. The Privacy Notice, the Notice of Privacy Practices and the HIPAA policies are the documents this one sits beside.
Acceptance line. I have read this policy, I understand that my access to patient information is recorded and reviewed, and I agree to follow it. I will accept it again when a new version is issued and at least once a year.