Privacy notice
Development demo · updated July 21, 2026
What this demo collects
The demo uses seeded identities, fictional health answers, case events, and operational data to exercise development and QA workflows. It may also process sign-in cookies and technical diagnostics needed to run the application.
How data is separated
Patient, doctor, operator, and network roles are designed around minimum-necessary access. Clinical detail is structurally separated from operational records, and database row-level policies form the primary authorization boundary.
Production readiness
Before real regulated data is accepted, hosting, vendors, logging, backups, retention, incident response, encryption key management, business associate agreements, and the complete HIPAA security program must pass the launch checklist documented with this project.
Your choices
This demo is resettable. Production patient experiences will support access, correction, communication preferences, retention requirements, and legally required privacy rights through verified workflows.