Patient Care Circle Back to home
Security & compliance

Security documentation

Last updated 17 September 2026

Patient Care Circle is a care-coordination layer that sits above the systems where clinicians already work — it is not an electronic health record. Security is built into the product rather than bolted on. This page describes the safeguards actually implemented today, in plain terms, along with an honest account of what is still in progress.

Encryption

  • In transit: TLS 1.2+ for every connection — browser to app, and app to each of our subprocessors.
  • At rest: AES-256 provided by our database and object-storage subprocessors.
  • Application-level field encryption: the most sensitive fields — secure-message bodies and multi-factor authentication secrets — are additionally encrypted with AES-256-GCM (authenticated encryption) before they are written, so they are never stored in plaintext.

Authentication

  • Passwords are hashed with argon2id using OWASP-aligned parameters; we never store or log a raw password.
  • Sessions use an HttpOnly, Secure, SameSite cookie holding only an opaque token hash. They time out after 20 minutes of inactivity and are capped at 12 hours absolute, and can be revoked server-side (logout, password reset, or account suspension).
  • Optional two-factor authentication (TOTP) with one-time recovery codes; sensitive actions can require a fresh step-up.
  • Automatic lockout after repeated failed logins, plus durable rate limiting on authentication, password reset, invitations, and document sharing.

Authorization & consent

Every request for protected data passes through a single policy decision point that is deny-by-default. Access requires an active treatment relationship and the patient's consent for that specific category of information.

  • Patient-controlled: consent is granted per category (for example treatment summaries, medication information, messaging) and can be revoked at any time.
  • Minimum necessary: a provider sees only the categories a patient has shared with them; especially sensitive material (e.g. psychotherapy notes) requires explicit sharing and is withheld from the patient portal by default.
  • No automatic administrator access: platform and organization administrators do not gain access to patient records by virtue of their role. Administrative access is a separate axis from clinical access.

Auditing

Security-relevant events are written to an append-only, hash-chained audit log: each entry is chained to the previous one with SHA-256, making tampering detectable. The application role cannot update or delete audit rows, and a chain-integrity check can be run at any time.

Logging & data lifecycle

  • Application logs redact emails and tokens and never contain record contents; no protected health information is placed in URLs, logs, analytics, or email subject lines.
  • Operational data is disposed of on a schedule (expired tokens, sessions, and rate-limit counters within a day; notifications after 90 days). The audit log is retained permanently.
  • Deleting a document removes its bytes from object storage; non-identifying metadata is retained for the audit trail.

Transport & browser hardening

The app sends HSTS, a strict Content-Security-Policy, X-Frame-Options: DENY, X-Content-Type-Options: nosniff, a locked-down Permissions-Policy, and a strict referrer policy.

What we are honest about

  • Not end-to-end encrypted. Encryption is platform-controlled: the service can process message bodies to deliver the product. It is not zero-knowledge, and it does not protect against a full compromise of the application itself.
  • Key management is being hardened. We are moving field-encryption keys to a dedicated, independently-rotated key-management service.
  • Compliance is a program, not a checkbox. We are not SOC 2 certified. We maintain HIPAA Business Associate Agreements with every subprocessor that handles protected health information, run an ongoing breach-notification and risk-analysis program, and operate the platform for production use with real patient information.

Related

See our subprocessors and how to report a security issue. Security questions: security@patientcarecircle.com.