Demonstration only — do not enter real patient information.
Security
What we do to protect the records you put in OurCareBook, who else touches them, and a plain account of where our compliance paperwork stands today.
Controls
Access is decided in the database by membership of the client's circle or care team — not only in the application. A bug in a screen cannot return a record the viewer has no right to.
Legal, insurance, identity and financial documents are restricted by default to the family and senior staff. Coordinators and hired carers see the care record, not the paperwork around it.
Uploaded documents sit in a private bucket and are only ever served through links that expire within minutes. Nothing is public, and there is no guessable address.
Nothing the model extracts becomes part of a record until a named person approves it, and their name is stored against it.
Extractions, confirmations, deletions and joins are recorded with who and when. Owners and managers can read it inside the product.
Anyone who can see a record can export everything they can see, as a file, without asking us. Deletion requests are recorded and confirmed before anything is erased.
AI
The model is a transcriber. It does not practise medicine and it does not write to the record.
Subprocessors
| Service | What it does | Where |
|---|---|---|
| Supabase | Database, authentication, document storage | United States (East) |
| Vercel | Web application hosting | United States |
| Railway | Application API | United States |
| Anthropic | Reading uploaded documents | United States |
Compliance status
OurCareBook is built for a HIPAA business associate agreement: the controls above, consent capture, and a breach-notification record exist today.
The agreements with every subprocessor that would touch real client records are not all signed yet. Until they are, pilots run on de-identified or synthetic documents, and the product itself says so on every screen.
Ask us on the first call and we will tell you exactly which are signed and which are not. If a vendor ever tells you they are “fully compliant” without being able to show you the same list, ask them for it.
Ask us directlyTell us before anyone else. We will acknowledge within two working days and keep you informed while we fix it.