Data Handling & Destruction Policy
Effective July 2026 · The Tyler Group · tylerstrategy.com
Scope and Purpose
This policy governs how The Tyler Group receives, handles, stores, and destroys client materials — including case files, attorney work product, and protected health information (PHI) — submitted in connection with CLARA™ pre-litigation intelligence engagements. It applies to all file transfers, analysis workflows, and post-delivery data handling across every engagement type.
File Receipt and Storage
Client files are transmitted to The Tyler Group via a dedicated secure file request hosted on our BAA-covered file transfer platform (Dropbox Business, operated under an executed HIPAA Business Associate Agreement). Files are received into an engagement-specific folder accessible only to authorized Tyler Group personnel.
Client files are stored under an executed BAA with our secure file-transfer provider. Medical records and PHI are processed under protocols that comply with the BAA and applicable HIPAA requirements.
Analysis is conducted using proprietary CLARA™ methodology, which may incorporate specially designed, HIPAA-compliant AI-assisted research tools operating exclusively within BAA-covered infrastructure. All client data — including medical records, client identifiers, and attorney work product — is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256), stored and processed exclusively within the United States, and is not disclosed to any unauthorized third party. Tyler Group personnel review all analysis output prior to delivery.
PHI and Medical Records
Matters involving protected health information (PHI) or medical records require an executed Business Associate Agreement (BAA) between the referring attorney's firm and The Tyler Group prior to file transfer. The Tyler Group operates under a HIPAA BAA with its secure file-transfer provider (Dropbox, Inc., effective July 6, 2026).
PHI received in connection with an engagement is processed within CLARA™'s BAA-covered infrastructure and may be analyzed using specially designed, HIPAA-compliant AI tools that operate exclusively within the United States. All PHI is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). PHI is not shared with unauthorized subcontractors, third-party analysts, or any system outside the BAA-covered infrastructure. No PHI or matter-specific data is used to train AI models. The minimum necessary standard applies — only the PHI required to complete the specific analysis is accessed. Tyler Group personnel review all analysis output prior to delivery.
Destruction Timeline
The Tyler Group does not retain client materials after delivery. The following destruction schedule applies to all engagements:
Upon request, The Tyler Group will provide written confirmation of destruction for any completed engagement within five business days.
Breach Notification
In the event of a confirmed or suspected unauthorized access to client materials, The Tyler Group will notify the affected attorney of record within 72 hours of discovery, consistent with HIPAA breach notification requirements. Notification will include the nature of the incident, the information potentially affected, and the steps taken or underway to contain and remediate.
Our file-transfer provider (Dropbox, Inc.) is contractually obligated under the BAA to notify The Tyler Group of any breach on their platform within the timeframes required by HIPAA.
Access Controls
Access to client files is restricted to Tyler Group personnel directly involved in the specific engagement. Files are stored in engagement-specific folders with access limited by role. Two-factor authentication is enforced on all Tyler Group accounts with access to client materials. Session controls and device approval requirements are active on the secure file transfer platform.
Attorney Work Product
The Tyler Group treats all case submissions as confidential. The applicable privilege or work-product protection is a determination made by submitting counsel based on the specific matter and jurisdiction. The Tyler Group does not disclose matter details, client identities, analysis content, or any engagement information to any third party except as required by law. CLARA™ analysis is pre-litigation intelligence for use by licensed counsel — it does not create an attorney-client relationship between The Tyler Group and any party to the underlying matter.
Questions and Requests
To request written destruction confirmation, report a concern, or ask questions about this policy, contact us at hello@tylerstrategy.com.