Understanding Health Information Collection
This notice explains how Collective Care Compass collects, uses, and protects your Protected Health Information (PHI). We want you to fully understand what health data we collect, why we need it, and how we keep it safe.
1. What is Protected Health Information (PHI)?
Protected Health Information (PHI) is any health information that can identify you, including:
- Medical diagnoses and conditions
- Medications and treatments
- Lab results and test reports
- Doctor's notes and visit summaries
- Health insurance information
- Symptoms and health tracking data
- Mental health and emotional wellbeing records
We ask for your explicit consent before we collect or share any of it.
A note on which laws apply. Collective Care Compass is a personal care coordination tool, not a healthcare provider, health plan, or clearinghouse, so we are not a covered entity under the US health privacy law known as HIPAA. The rules that do apply to us include the FTC Health Breach Notification Rule and, for California residents, the California Confidentiality of Medical Information Act. We hold your health information to the standard of care described on this page regardless of which statute names us.
2. What Health Information We Collect
2.1 Medication Information
- Medication names and generic equivalents
- Dosages, frequencies, and schedules
- Prescribing doctors and pharmacies
- Start and end dates
- Medication adherence tracking
- Side effects and reactions
- Prescription label images (OCR processed)
2.2 Medical Appointments
- Appointment dates, times, and locations
- Healthcare provider names and specialties
- Appointment types and purposes
- Pre-appointment questions and concerns
- Post-appointment notes and summaries
- Follow-up tasks and recommendations
2.3 Symptoms and Health Tracking
- Symptom descriptions and severity ratings
- Mood tracking data (daily mood, triggers)
- Energy levels and sleep quality
- Pain levels and locations
- Vital signs (if you choose to track them)
- Physical activity and exercise
- Diet and nutrition notes
2.4 Medical Conditions and Diagnoses
- Current diagnoses and conditions
- Medical history and past conditions
- Allergies and adverse reactions
- Immunization records
- Family medical history
2.5 Healthcare Providers and Insurance
- Primary care physician information
- Specialist doctor information
- Hospital and clinic details
- Health insurance provider and policy numbers
- Insurance claims and coverage information
2.6 Medical Documents
- Lab results and test reports
- Imaging reports (X-rays, MRIs, CT scans)
- Discharge summaries
- Treatment plans and care plans
- Advance directives and living wills
- Insurance cards and coverage documents
2.7 Mental Health and Emotional Wellbeing
- Journal entries and reflections
- AI chat conversations (if opted in)
- Mood patterns and emotional states
- Stress levels and coping strategies
- Gratitude logs and positive experiences
- Caregiver burnout indicators
3. Why We Collect This Information
We collect health information to help you:
3.1 Coordinate Care
- Keep track of medications to avoid missed doses
- Remember appointment details and prepare questions
- Share relevant information with your care team
- Identify patterns in symptoms or side effects
3.2 Simplify Medical Tasks
- Generate doctor visit summaries
- Translate medical jargon into plain language
- Organize insurance documents
- Track FMLA leave and documentation
3.3 Support Emotional Wellbeing
- Provide AI-powered reflection and emotional support
- Detect early signs of caregiver burnout
- Offer personalized coping resources
- Celebrate progress and positive moments
3.4 Enable Family Collaboration
- Share updates with family members
- Coordinate transportation and support
- Distribute caregiving responsibilities
- Keep everyone informed without repeated phone calls
4. Your Consent and Control
4.1 Consent is Required
We will NOT collect any health information without your explicit consent. During onboarding, you choose:
- Whether to allow PHI collection at all (required to use core features)
- Whether to share PHI with care team members (optional)
- Whether to use AI features that process PHI (optional)
4.2 Granular Permissions
You control exactly what each care team member can see:
- Full Access: Can view all health information
- Medication Only: Can only see medication schedules
- Calendar Only: Can only see appointment dates (no medical details)
- No Access: Can only view non-medical care feed updates
4.3 Revoke Access Anytime
You can revoke access at any time:
- Remove individual care team members
- Opt out of AI features
- Delete specific health records
- Export and delete all your data
5. How We Protect Your Health Information
5.1 Encryption
All PHI is encrypted using military-grade encryption:
- AES-256-GCM: Industry-standard encryption at rest
- TLS 1.3: Secure transmission over the internet
- Encrypted Backups: Even backups are encrypted
- Key Management: Encryption keys stored separately from data
5.2 Access Controls
We strictly limit who can access your PHI:
- Role-based access control (RBAC)
- Multi-factor authentication (2FA)
- Session timeouts after 30 minutes of inactivity
- Failed login attempt limits
5.3 Audit Logging
Every access to your PHI is logged:
- Who accessed your information
- When they accessed it
- What they viewed or modified
- From what IP address and device
You can review your access logs in Settings > Privacy > Access History
5.4 Secure Infrastructure
We use enterprise-grade security:
- Neon PostgreSQL database with encryption at rest
- Replit Object Storage with encrypted file storage
- Regular security audits and penetration testing
- Vulnerability scanning and patching
- Incident response plan and 24/7 monitoring
6. Who Can Access Your Health Information
6.1 You
You always have full access to all your health information.
6.2 Authorized Care Team Members
Only people you explicitly invite and grant permissions to can view specific parts of your health information.
6.3 Service Providers
Limited technical access for:
- OpenAI: Processes AI chat messages (zero-retention API, data not used for training)
- Neon/Replit: Hosts encrypted database and files (no access to decrypted data)
Each of these providers is bound by its data processing terms with us, which restrict what they may do with your information and forbid using it to train models. Our AI processing runs against zero-retention endpoints, and our database and file host holds your data encrypted, without the keys needed to read it.
6.4 Our Staff
Our employees have NO access to your PHI except:
- Technical support staff (only with your explicit permission and only to resolve your specific issue)
- All staff access is logged and audited
- All staff sign confidentiality agreements
6.5 Legal Requirements
We may be legally required to disclose PHI:
- Court orders or subpoenas
- Law enforcement investigations (with proper legal authority)
- Public health reporting (communicable diseases)
- Preventing serious harm (imminent threat of violence)
We will notify you of such requests unless prohibited by law.
7. AI Processing of Health Information
7.1 How AI Uses Your Data
If you opt in to AI features, your health information may be processed to:
- Generate personalized reflections in AI chat
- Translate medical terminology into plain language
- Summarize doctor visit notes
- Identify patterns in symptoms or mood
- Provide faith-based affirmations and resources
7.2 AI Data Protection
When using AI features:
- We use OpenAI's zero-retention API
- Your data is NOT used to train AI models
- AI conversations are encrypted and stored securely
- You can delete AI chat history at any time
- We remove personally identifiable information before AI processing when possible
7.3 AI Limitations
Important: AI-generated content:
- May contain errors or inaccuracies
- Should NOT be used for medical diagnosis or treatment
- Is for informational and emotional support purposes only
- Must be verified with healthcare professionals
8. Your Rights Regarding Health Information
8.1 Right to Access
You have the right to view and download all your health information at any time through the app.
8.2 Right to Correct
You can update or correct any inaccurate health information.
8.3 Right to Delete
You can delete specific health records or your entire account. Deleted data is permanently removed within 30 days.
8.4 Right to Export
You can export your health information in machine-readable format (JSON) or PDF.
8.5 Right to Accounting of Disclosures
You can request a list of all times your PHI was disclosed to third parties (available in Settings > Privacy > Access History).
8.6 Right to Restrict Processing
You can opt out of AI processing while still using other features.
9. Data Retention
We retain your health information:
- While Active: As long as your account is active
- After Deletion: PHI permanently deleted within 30 days
- Audit Logs: Retained for 6 years so there is a durable record of who accessed what, then anonymized after account deletion
- Backups: Removed from backups within 90 days
10. Breach Notification
If your health information is ever compromised:
- We will notify you within 72 hours
- We will explain what information was affected
- We will describe steps we are taking to mitigate harm
- We will offer remediation (credit monitoring if needed)
- We will report to HHS and other authorities as required
11. Questions or Complaints
If you have questions about how we handle your health information or want to file a complaint:
Privacy Officer
Email: privacy@collectivecarecompass.com
Phone: 1-800-XXX-XXXX
You also have the right to file a complaint with:
- US: Department of Health and Human Services, Office for Civil Rights
- Canada: Office of the Privacy Commissioner of Canada
We will not retaliate against you for filing a complaint.
Your health information is sacred. We treat it with the highest level of security and respect, and we give you complete control over who can access it.