Ask Rupert
CareHub is taking a phased approach to security and privacy. The beta platform is deliberately scoped to avoid broad health-data capture, while the production architecture is being shaped to support stronger HIPAA-aligned controls when those workflows are activated.
Data Scope
Minimal beta collection by design.
Transport Security
HTTPS and hardened authentication.
Continuity
Daily backups and multi-path recovery.
User Rights
Access, correction, deletion, portability.
Production Path
HIPAA-ready controls staged for launch.
Reality Check
- Current state: privacy-first beta architecture with active authentication, encrypted transport, invite controls, and backup discipline.
- Not current state: this page does not pretend that every production-grade control is already fully enforced everywhere.
- Guiding principle: collect the minimum necessary data, limit unnecessary exposure, and be explicit about what is live versus what is still being hardened.
Why This Matters
Trust is earned by clear scope, not inflated claims. This page is intended to reduce fear around privacy and data loss by explaining the current implementation plainly, including how continuity and recovery are handled today.
CareHub does not provide diagnosis or treatment. The platform is intended for information, coordination, research translation, and community support, with sensitive health-data workflows staged for more rigorous production controls.
