Security
The controls that are built and tested today.
- Effective
- September 15, 2026
- Last updated
- September 15, 2026
- Operator
- Artemius Labs LLC
CarePath is a documentation tool, not a healthcare provider. It does not practise medicine, diagnose, triage, prescribe, calculate doses or check interactions, and it never replaces a clinician's own judgment or instructions.
How CarePath protects clinicians’ and patients’ information today. Every item below is built and tested — and section 8 lists what we deliberately do not claim.
De-identification
- A separate service, with its own keys, removes identifiers before anything is stored. It runs in memory with file writes disabled by the runtime, logs only pre-approved fields, and has no endpoint that returns data.
- Output that fails an independent second check is rejected, never passed through.
- The database accepts case text only with a signed receipt from that service.
- We store a report of which kinds of identifiers were removed and how many — never the identifiers themselves.
- Uploaded source documents are used to extract text and are not retained afterwards.
No automated de-identification is perfect, and we do not claim otherwise. Clinician review before approval is part of the control, not an afterthought — see the Medical Disclaimer.
Access control and tenancy
- Row-level security on every table: clinicians see only their own cases; owners and admins see their organization’s. Background jobs are confined to one organization at a time.
- Isolation is enforced in the database rather than in application code, and is covered by an automated test suite that runs against a real Postgres instance.
- Removing a member ends their sessions immediately. Idle sessions end after 30 minutes on shared workstations.
- Roles are least-privilege by default: a clinician cannot reach billing, an admin cannot reach another organization.
Review and sharing
- Comics can be shared or exported only after a clinician approves them; editing sends them back for review and turns links off.
- Share links use at least 128 bits of randomness, expire, can be revoked instantly, and are never indexed.
- Opening a shared comic records the time and the comic — no IP address, device or fingerprint.
- Deleting a case revokes its links in the same transaction, so a link can never outlive the content it points at.
Infrastructure and data protection
- All traffic is served over TLS; HTTP is redirected. Data is encrypted at rest by the storage provider.
- Secrets live in the platform’s encrypted environment store, never in the repository, and are scoped per environment.
- Production access is limited to named individuals, requires multi-factor authentication, and is logged.
- Backups are encrypted and rotate on a 35-day cycle; deleted content falls out of them within that window.
- Dependencies are pinned and patched, and the build fails on a known critical vulnerability.
Audit
An append-only audit log records approvals, edits, links, deletions, membership and plan changes. No one — including CarePath’s own jobs — can change or delete an entry. Entries carry the actor, the organization, the action and the time, and never patient identifiers.
Owners and admins can review their organization’s log. We use it to investigate incidents and to answer “who approved this, and when”.
Vendors
Every vendor that touches data is listed, with its purpose and what it sees, on the Subprocessors page. Each is bound by contract to process data only on our instructions, and we review the list whenever the system changes.
Incident response
If an incident affects your data, we notify the affected organization without undue delay and in any event within 72 hours of becoming aware, with what we know, what we are doing, and what you should do. We do not sit on bad news while we investigate.
What we do not claim
We would rather be believed than impressive. As of the date at the top of this page, CarePath does not hold:
- a SOC 2 Type II report or ISO 27001 certification;
- HITRUST certification;
- a completed independent penetration test of the production system.
No system is perfectly secure. Everything described above is built and tested today; when that changes in either direction, this page changes with it. If your procurement process needs a questionnaire completed or evidence supplied, write to us and we will tell you honestly what we can and cannot provide.
Reporting a vulnerability
Email support@carepath.com with the subject “Security report”. Include what you found, how to reproduce it, and how you would like to be credited.
We acknowledge within 5 business days, keep you updated, and will not pursue action against researchers who act in good faith: test only against your own account, do not access another organization’s data, do not degrade the service, and give us a reasonable window to fix the issue before disclosing it. Please ask before running any automated scan — see the Acceptable Use Policy.
Questions about this document
Write to us and we'll answer within 5 business days. Use the email address on your account so we can find you.
support@carepath.comArtemius Labs LLC1209 Mountain Road Pl NE, Ste RCheyenne, WY 82001United States