Ask Rupert
CareHub is taking a phased approach to security and privacy. The beta platform is deliberately scoped to avoid broad health-data capture, while the production architecture is being shaped to support stronger HIPAA-aligned controls when those workflows are activated.
Data Scope
Minimal beta collection by design.
Transport Security
HTTPS and hardened authentication.
Continuity
Daily backups and multi-path recovery.
User Rights
Access, correction, deletion, portability — see Privacy Policy.
Production Path
HIPAA-ready controls staged for launch.
Reality Check
- Current state: privacy-first beta architecture with active authentication, encrypted transport, invite controls, and backup discipline.
- Not current state: this page does not pretend that every production-grade control is already fully enforced everywhere.
- Guiding principle: collect the minimum necessary data, limit unnecessary exposure, and be explicit about what is live versus what is still being hardened.
Why This Matters
Trust is earned by clear scope, not inflated claims. This page explains the current implementation plainly — including continuity and recovery — and separates beta reality from the production control path.
CareHub does not provide diagnosis or treatment. The platform is intended for information, coordination, research translation, and community support, with sensitive health-data workflows staged for more rigorous production controls.
Formal policy language (collection, use, rights, cookies, international) lives in the Privacy Policy.
