Authorized channels only
PSSOL maintains secure data-exchange and client-portal capabilities for authorized users when appropriate for a client engagement or authorized prospective engagement discussion. Access to any portal, upload area, shared workspace, or data-exchange tool is restricted and governed by applicable engagement terms, confidentiality obligations, and any
instructions provided by PSSOL.
Credentials and user responsibilities
Portal credentials, secure links, and upload links are confidential and personal to the authorized user. They may not be shared, forwarded, reused by unauthorized persons, or used outside the purpose for which access was granted.
Users are responsible for maintaining the security of their devices, accounts, passwords, and links; scanning files for malware before upload; maintaining current contact information where applicable; and promptly notifying PSSOL if credentials, links, or uploaded materials may have been accessed by an unauthorized person.
Restricted Data warning
Clients and prospective clients should not upload Restricted Data unless PSSOL has expressly authorized that upload in a signed written agreement and has confirmed the approved secure exchange process. Restricted Data includes protected health information, patient-level data, regulated data, sensitive personal information, export-controlled information, or highly confidential business information.
Scope and security
Most PSSOL engagements are strategic advisory, commercialization, governance, or program-support engagements and are non-PHI in scope unless otherwise expressly agreed in writing. Where additional data-handling obligations are required, they should be addressed in the applicable client agreement before data is transmitted.
PSSOL uses reasonable administrative, technical, and organizational measures designed to support secure exchange. No internet transmission, email system, portal, upload link, or platform can be guaranteed to be completely secure.
Access controls and file handling
PSSOL may restrict, suspend, revoke, remove, or refuse portal access, files, or submissions if access or uploaded content appears unauthorized, unsafe, inconsistent with engagement terms, outside the agreed scope, no longer necessary, or otherwise presents a security, confidentiality, or operational concern.
Files and submissions may be monitored, scanned, screened, quarantined, removed, or refused for security, malware, authorization, scope-control, or operational reasons.
No automatic engagement
Uploading information through a portal, secure link, general website form, or standard email does not by itself create a client relationship, expand the scope of any engagement, or modify the terms of any signed agreement.
