Frequently Asked Questions About CureCast Patient Photo Management

Review the answers to our most frequently asked questions below.

No. The US Department of Health and Human Services does not certify, approve, endorse or accredit any software, server, cloud provider or vendor. There is no government-issued HIPAA certificate, and no official list of approved products.
Some vendors advertise HIPAA certification anyway. What they usually mean is that they have had a third-party audit, which is a reasonable thing to do but is not a government certification and does not make a practice compliant.
What to ask instead: will you sign a BAA, how is data encrypted at rest and in transit, how is staff access controlled, and what does the audit trail record. Those are answerable questions with verifiable answers.

CureCast offers storage in India on Amazon Web Services under a signed Business Associate Agreement between CureCast and AWS. We add regions based on customer demand. If your practice needs storage in a particular country, raise it at your demo and we will tell you plainly whether we can do it and when. 

With photos taken on personal phones, usually nothing good. They stay in that person’s camera roll and personal cloud account, and the practice has no route to recover or delete them. With CureCast, deactivating the staff account ends their sessions across every device immediately and removes their access. The photos were never on their device to begin with. The audit trail retains a record of what they accessed while employed.

As of now, Meta does not sign Business Associate Agreements, so WhatsApp is not a HIPAA-covered channel for routine disclosures. HIPAA does permit a covered entity to send information to the patient themselves through a channel the patient has asked for, provided the practice has warned them of the risks and documented that. That is a patient-directed disclosure with conditions, not a compliant messaging system.

Yes. A clinical photograph that can be linked to an individual is protected health information, because an identifiable image combined with treatment information meets the definition. Facial photographs are identifiable on their own.
This applies to before and after photographs, progression series and images taken for the patient’s record. Cropping out a face does not automatically remove identifiability, since tattoos, scars and other distinguishing features can identify a person.

They can, but it creates a problem worth avoiding. A photo taken with the phone’s own camera app is saved to that staff member’s camera roll and, on most phones, synced automatically to their personal cloud account. Your clinical images then sit on a device and in an account your practice does not control, and cannot retrieve when that person leaves. Photos taken through CureCast Camera go directly into your practice account. They are never written to the camera roll and never sync to a personal cloud. If a phone is lost or a staff member leaves, the images stay with the practice.

Yes, treatment photographs taken at a medical spa are protected health information when the spa operates as a covered entity, and the usual exposure is staff phones rather than the software. CureCast supports HIPAA-compliant workflows. Photos taken through the app go straight into your practice account and are never saved to the device’s camera roll or synced to a staff member’s iCloud, so a departing injector does not leave with your clinical images. Each staff member signs in individually, access is controlled per person, and every action is updated in audit log. We sign a Business Associate Agreement with every US practice. No vendor can be “HIPAA certified,” as HHS certifies no products, so your policies, training and offboarding process remain yours.

Yes. CureCast supports both separate location accounts and a central clinical photo library across locations.With separate accounts, each location has its own patients, photos, staff, and permissions. With a shared library, locations can share patient and photo data while access remains controlled by location and staff permissions.

Staff use individual accounts rather than shared credentials, and an administrator can manage the appropriate location accounts.

SkinLab by Dr. Jamuna Pai operates CureCast across 20+ aesthetic clinic locations across India and UAE from a single account with centralized client records and location-specific access controls.

Yes. Send the client a secure upload link via WhatsApp or email directly from CureCast. The client uploads from their phone without installing any app. Photos auto-file into their chart on the upload date and you receive an instant push notification, ideal for collecting CoolSculpting week-4 results or post-laser recovery photos without the client needing to visit.
Yes. With client authorization in place, share photos directly from CureCast to Instagram, Facebook, or any social media app on your device via the native share sheet. Add your med spa watermark and logo within CureCast before sharing, every post looks professionally branded without any third-party editing app needed.

Yes. CureCast lets you build treatment-specific counselling galleries such as CoolSculpting, Botox, laser body contouring, skin tightening so a new client sees real results from your own practice matching their body type and goals. Every before/after you create is automatically filed into the right treatment gallery without any manual effort. The consultation becomes a visual conversation rather than a verbal pitch.

Yes. Instantly search and display similar cases based on condition, skin type, or treatment, helping improve patient understanding and conversion during consultations.

Clinical photographs are protected health information, and a dermatology practice generates thousands of them a year across progression tracking, lesion documentation and treatment records. CureCast supports HIPAA-compliant workflows for that volume. We sign a Business Associate Agreement with every US practice, images are encrypted with AES-256 at rest and TLS 1.3 in transit, staff access is controlled individually at module and action level, and every view, download and share is recorded in an audit trail. No software can be “HIPAA certified,” since HHS does not certify products. Compliance remains your practice’s programme, and CureCast is built to support it.

Yes. CureCast supports both separate accounts per location and a central clinical photo library across locations.

With separate accounts, each location keeps its own patients, photos, staff, and permissions. If locations choose to share a library, authorized staff can access relevant records across locations using their individual staff accounts and location-scoped permissions.

An administrator can manage multiple location accounts when required.

SkinLab by Dr. Jamuna Pai operates CureCast across 20+ dermatology clinic locations across India and UAE from a single account, with location-specific access controls and centralized patient records.

Yes. Send a secure upload link via WhatsApp or email in one tap. Patients can upload photos, videos, or files directly from their phone without installing CureCast app. Images are automatically saved to the correct patient record, and you receive an instant notification, ideal for tracking acne progress or post-treatment recovery.

Yes. Search by condition, treatment, or keyword such as acne, melasma, cool sculpting, laser, chemical peel, PRP and matching photos appear instantly in under 3 seconds. Each photo can be tagged under multiple conditions, so a single patient can show up in different searches without duplication.

Yes. CureCast organizes a patient’s clinical photos by visit date, making it easy to review progress across multiple appointments. For conditions such as acne, melasma, and pigmentation that may change gradually over weeks or months, you can view the patient’s photo history and compare images from different visits. Select photos from two visits to create a before-and-after comparison and show patients how their results have changed over time.

Yes. CureCast includes photo annotation tools that work directly within the app. During a consultation you can draw on photos and add text notes, useful for marking treatment areas, highlighting planned incision points, or annotating progress photos for the clinical record. The annotation tools are designed to be quick enough to use with a patient in the room without interrupting the consultation flow. Annotated photos are saved to the patient chart alongside the original.

Yes. CureCast supports multi-location plastic surgery groups with two options for managing patient photos and clinical data.

Separate account per location: Each clinic has its own account with its own patients, photos, staff, and permissions. Staff at one location cannot search or view another location’s patients. One administrator can manage multiple location accounts.

One central library across locations: Locations can also share a single patient database and photo library. Staff continue to use their individual accounts, with access controlled by their assigned permissions and location. A surgeon working across multiple sites can access the patient photos they are authorized to see from their own login.

Choose separate accounts when locations are separate legal entities or franchises, patients belong to a specific site, or locations need their data held separately. Choose a shared library when locations operate as one practice, surgeons work across sites, or you want a group-wide patient-photo portfolio and reporting.

Yes. CureCast lets you build procedure-specific and condition-specific counselling galleries for every treatment you offer. For rhinoplasty, you can create galleries filtered by nose type, anatomy, or correction needed, open rhinoplasty, revision rhinoplasty, ethnic rhinoplasty so a new patient sees results that match exactly what they are seeking. For liposuction patients, build zone-specific galleries by waist, flanks, abdomen, or inner thighs separately. Every before and after you create is automatically filed into the right procedure gallery without any manual effort.

All patient photos, videos, documents and clinical records are stored on Amazon Web Services with automatic redundant backups, encrypted with AES-256 at rest and TLS 1.3 in transit. CureCast holds a signed Business Associate Agreement with AWS. You never need to back up manually.

Yes. CureCast allows administrators to control staff access using individual user accounts and permissions. Each staff member has their own login, and administrators can assign access based on their role. Permissions can be managed at the module and action level, including access to view, edit, delete, download, and share patient photos.

Yes, if the app stores or handles protected health information on your behalf and your practice is a covered entity. HIPAA requires a covered entity to have a written BAA in place with any business associate before that vendor handles PHI.
CureCast signs a BAA with every US practice, and we hold one with AWS, who host the storage. Ask any vendor for their BAA before you upload a single patient photo. A vendor who is vague about it is telling you something.
Contact us at [email protected] to receive yours.

Yes, both. To share with a patient, select any photos, videos, docs, or before/after comparison and send directly via WhatsApp or email in one tap. Crucially, you do not need to save the patient’s phone number to your personal contacts, CureCast handles the share securely without exposing your personal information.

To share on Instagram, Facebook, or any other social media app installed on your device, add your clinic watermark and logo within CureCast first, then share directly via your device’s native share sheet. The photo never needs to be downloaded to your personal camera roll. Patient consent must be in place before any social media sharing.

Yes, before and after photographs are protected health information. A clinical image that can be linked to an individual is PHI under HIPAA even when no name appears in the frame, and facial photographs are identifiable by definition.
CureCast supports HIPAA workflows for capturing, storing and comparing them. We sign a Business Associate Agreement with every US practice, photos are encrypted with AES-256 at rest and TLS 1.3 in transit, and they are never saved to a staff member’s camera roll. Staff access is controlled individually at module and action level, and every view, download and share is recorded in an audit trail.
No vendor can be “HIPAA certified,” as HHS certifies no products. Your practice remains responsible for its own policies and for patient authorisation before any photograph is used in marketing.

Yes. Send the patient a secure upload link by Email, straight from CureCast. If their number or email is saved in the app, it sends in one tap. The patient uploads from their phone, no app to install. Photos, videos, and documents land in their file automatically, and you get an instant notification.

New patient – Search your portfolio by procedure, body area, or condition. Show real results from your own practice, not stock photos. They see themselves in it. They book.

Returning patient – Open their photo timeline. Build a before/after between any two visits in seconds. They see exactly what changed, and how far they’ve come. Their doubt disappears.

Yes. Search photos by procedure, treatment, patient, or other available details. CureCast describes photo retrieval in under 3 seconds, depending on search and system conditions.

No. CureCast includes unlimited storage for photos, videos, and documents on every plan and no per-file fees, no storage cap, and no surprise charges as your library grows. A busy aesthetic practice captures between 15,000 and 20,000 clinical photos per year per location. CureCast is built to handle this volume without any performance degradation. All files are stored on encrypted Amazon AWS S3 servers and are accessible from any device instantly.
CureCast supports HIPAA workflows and we sign a Business Associate Agreement with every US practice, which is what HIPAA requires of a vendor handling protected health information. Patient photos and records are encrypted with AES-256 at rest and TLS 1.3 in transit, stored on Amazon Web Services under a signed BAA between CureCast and AWS, and accessible only to staff you authorise, with a full audit trail. No software can be “HIPAA certified,” since HHS certifies no products, so compliance remains your practice’s programme of policies, training and safeguards, and CureCast is built to support it. Contact us to receive your BAA before your trial.

Yes. CureCast supports two multi-location setups, depending on how your practice wants to manage patient data.

Separate account per location: Each clinic has its own account with its own patients, photos, staff, and permissions. Staff at one location cannot search or view another location’s patients, and there is no setting they can change to widen that access. One administrator can manage every account.

One shared library across locations: Locations can also share a single patient database and photo library with location-scoped access controls. Staff still use their individual accounts and only see the information they are authorized to access. A clinician working across sites can use their own login to access authorized records across locations.

Choose separate accounts when locations are separate legal entities or franchises, patients belong to a specific site, or different locations need their data held in different countries. Choose a shared library when locations operate as one practice, clinicians work across sites, or you want group-wide reporting and a shared portfolio.

Yes. CureCast automatically organises every patient’s photos by visit date, making before and after creation instant. Simply open a patient’s photo history, select any two photos from any two visits whether one week apart or two years apart and CureCast creates a side-by-side or overlay comparison in seconds. You can add your clinic watermark, logo, and custom text before saving it to your before/after portfolio or sharing it. The before and after is automatically saved to the patient’s file and to your treatment-specific portfolio for future consultations.
Yes, and this is CureCast’s core strength. You can find photos by any treatment name you define whether that’s rhinoplasty, liposuction, breast augmentation, Botox, laser resurfacing, chemical peel, or any custom procedure name your practice uses. When a photo is added, it is tagged with the treatment name, diagnosis, body area, and date. During consultation, simply search by treatment name and every matching photo appears in under 3 seconds, making it effortless to show a new patient real results from the exact procedure they are considering.
Yes. You can migrate existing patient photos into CureCast in two ways. For bulk migration, your existing photos can be uploaded in batches from your computer, organised by patient name or folder. For ongoing capture, staff can photograph existing patient records and upload them directly through the app. During onboarding, our team assists you with migration planning, so your historical records are accessible from day one. Most practices are fully migrated within one to two weeks.

Your patient data always belongs to you. If you decide to end your CureCast subscription, you can download all your patient photos and health records in bulk at any time, in batches, organised by patient, directly to your computer. We provide a full data export before your account is closed. You are never locked in or held hostage to your data. We recommend downloading a backup periodically regardless, which CureCast makes easy with one click from your dashboard.

No, and this is one of CureCast’s most important compliance features. When a staff member takes a photo through the CureCast app, it is uploaded directly and securely to your practice’s encrypted AWS storage. The photo is never saved to the device’s camera roll or gallery. This means if a staff member loses their phone, leaves the practice, or their device is accessed by someone else, your patient photos remain completely protected. Your clinic data stays in your account and not on personal devices.
Most practices are fully set up and capturing patient photos within 24 to 48 hours of signing up. CureCast is a cloud-based app, there is nothing to install on a server and no hardware to configure. Download the app on your phone or tablet, sign up on the website, and you can begin adding patients and capturing photos immediately. If you are migrating existing photos from another system or a phone gallery, our team helps you plan and execute that migration, most clinics complete their full photo history migration within one to two weeks. A 14-day free trial is available with no credit card required, so you can run the full setup before committing.
Yes. This is one of the most valuable features for aesthetic practices that struggle to collect post-operative photos from patients who don’t return for follow-up visits. From within the CureCast app, generate a secure upload link for any patient. If their phone number and email are saved in the app, the link is automatically sent via WhatsApp or email in one tap. The patient receives the link, uploads their photos, videos, or documents from their own phone without needing to install anything, and the files are automatically moved into that patient’s chart as a new entry on the date uploaded. You receive an instant push notification the moment a patient uploads. This makes it easy to build complete before/after documentation even when patients cannot visit the clinic in person.
Yes. CureCast includes basic photo annotation tools, doctors can draw on photos and add textdirectly within the app. This is useful for marking areas of treatment, highlighting progress, or adding clinical notes directly to an image before saving it to the patient record or sharing it. The annotation tools are designed to be quick and practical for a clinical setting, straightforward enough for use during a patient consultation without slowing down the workflow.

Yes. CureCast works across iPhone, Android smartphones, iPad, Android tablets, and desktop or laptop computers through a web browser. Staff use their individual CureCast accounts, and access is controlled by their assigned permissions and clinic location.

Patient data stays synchronized across supported devices. For example, a staff member can capture photos on a clinic smartphone while an authorized doctor reviews and presents them on an iPad or desktop during a consultation.