Data Handling & Destruction Policy
Effective July 2026 · The Tyler Group · tylerstrategy.com
Scope and Purpose
This policy governs how The Tyler Group receives, handles, stores, and destroys client materials — including case files, attorney work product, and protected health information (PHI) — submitted in connection with Adverse Read™ engagements. It applies to all file transfers, analysis workflows, and post-delivery data handling across every engagement type.
File Receipt and Storage
Client files are transmitted to The Tyler Group via a dedicated secure file request hosted on our BAA-covered file transfer platform (Dropbox Business, operated under an executed HIPAA Business Associate Agreement). Files are received into an engagement-specific folder accessible only to authorized Tyler Group personnel.
Client files are stored under an executed BAA with our secure file-transfer provider. Medical records are handled under the controls described in this policy and in your engagement agreement. Whether The Tyler Group acts as a business associate, and whether a BAA or protective order is required, is determined for each engagement before any file is transferred.
Some analysis is AI-assisted. Where medical records are involved, they are processed on local systems under The Tyler Group's control, which do not transmit records to any third party, or — where record volume requires it — within a specialist medical-records analysis service engaged for that purpose. Medical records are not submitted to general-purpose or consumer AI services. Client data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256) by our file-transfer provider, and is not disclosed to any unauthorized third party. Tyler Group personnel review all analysis output prior to delivery.
The Tyler Group may engage service providers in connection with an engagement.
PHI and Medical Records
Where an engagement legally requires a Business Associate Agreement (BAA) or a protective-order undertaking, the applicable document must be in place before the affected materials are transferred. The Tyler Group operates under a HIPAA BAA with its secure file-transfer provider (Dropbox, Inc., effective July 6, 2026).
PHI received in connection with an engagement is stored in the Dropbox Business account covered by that BAA, in a restricted intake folder that is not directly connected to AI tools. Any material selected for authorized analysis is handled through the controlled process described above. All PHI is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). PHI is not shared with unauthorized subcontractors or third-party analysts. Note that a provider BAA covers that provider's own service and does not extend to third-party applications connected to it; where an engagement requires broader coverage, that is addressed in the engagement agreement before any transfer. No PHI or matter-specific data is used to train AI models. The minimum necessary standard applies — only the PHI required to complete the specific analysis is accessed. Tyler Group personnel review all analysis output prior to delivery.
Destruction Timeline
Client materials are retained only for the engagement and the limited post-delivery periods below. The following deletion schedule applies, subject to the engagement agreement:
Upon request, The Tyler Group will provide written confirmation of deletion for any completed engagement, ordinarily within five business days. The confirmation records the folders deleted, the date each deletion was confirmed by the storage provider, and any hold or interruption that changed the schedule.
Breach Notification
In the event of a confirmed or suspected unauthorized access to client materials, The Tyler Group will notify the affected attorney of record without undue delay after confirming the incident, and ordinarily within 72 hours. Notification will include the nature of the incident, the information potentially affected, and the steps taken or underway to contain and remediate.
Our file-transfer provider (Dropbox, Inc.) is contractually obligated under the BAA to notify The Tyler Group of any breach on their platform within the timeframes required by HIPAA.
Access Controls
Access to client files is restricted to Tyler Group personnel directly involved in the specific engagement. Files are stored in engagement-specific folders with access limited by role. Two-factor authentication is enforced on all Tyler Group accounts with access to client materials. Session controls and device approval requirements are active on the secure file transfer platform.
Attorney Work Product
The Tyler Group treats all case submissions as confidential. The applicable privilege or work-product protection is a determination made by submitting counsel based on the specific matter and jurisdiction. The Tyler Group does not disclose matter details, client identities, analysis content, or any engagement information to any third party except as required by law. The Adverse Read™ is pre-demand intelligence for use by licensed counsel — it does not create an attorney-client relationship between The Tyler Group and any party to the underlying matter.
Questions and Requests
To request written destruction confirmation, report a concern, or ask questions about this policy, contact us at hello@tylerstrategy.com.