Frequently Asked Questions About CureCast Patient Photo Management
Review the answers to our most frequently asked questions below.
No. The US Department of Health and Human Services does not certify, approve, endorse or accredit any software, server, cloud provider or vendor. There is no government-issued HIPAA certificate, and no official list of approved products.
Some vendors advertise HIPAA certification anyway. What they usually mean is that they have had a third-party audit, which is a reasonable thing to do but is not a government certification and does not make a practice compliant.
What to ask instead: will you sign a BAA, how is data encrypted at rest and in transit, how is staff access controlled, and what does the audit trail record. Those are answerable questions with verifiable answers.
CureCast offers storage in India on Amazon Web Services under a signed Business Associate Agreement between CureCast and AWS. We add regions based on customer demand. If your practice needs storage in a particular country, raise it at your demo and we will tell you plainly whether we can do it and when.
With photos taken on personal phones, usually nothing good. They stay in that person’s camera roll and personal cloud account, and the practice has no route to recover or delete them. With CureCast, deactivating the staff account ends their sessions across every device immediately and removes their access. The photos were never on their device to begin with. The audit trail retains a record of what they accessed while employed.
As of now, Meta does not sign Business Associate Agreements, so WhatsApp is not a HIPAA-covered channel for routine disclosures. HIPAA does permit a covered entity to send information to the patient themselves through a channel the patient has asked for, provided the practice has warned them of the risks and documented that. That is a patient-directed disclosure with conditions, not a compliant messaging system.
Yes. A clinical photograph that can be linked to an individual is protected health information, because an identifiable image combined with treatment information meets the definition. Facial photographs are identifiable on their own.
This applies to before and after photographs, progression series and images taken for the patient’s record. Cropping out a face does not automatically remove identifiability, since tattoos, scars and other distinguishing features can identify a person.
They can, but it creates a problem worth avoiding. A photo taken with the phone’s own camera app is saved to that staff member’s camera roll and, on most phones, synced automatically to their personal cloud account. Your clinical images then sit on a device and in an account your practice does not control, and cannot retrieve when that person leaves. Photos taken through CureCast Camera go directly into your practice account. They are never written to the camera roll and never sync to a personal cloud. If a phone is lost or a staff member leaves, the images stay with the practice.
Yes, treatment photographs taken at a medical spa are protected health information when the spa operates as a covered entity, and the usual exposure is staff phones rather than the software. CureCast supports HIPAA-compliant workflows. Photos taken through the app go straight into your practice account and are never saved to the device’s camera roll or synced to a staff member’s iCloud, so a departing injector does not leave with your clinical images. Each staff member signs in individually, access is controlled per person, and every action is updated in audit log. We sign a Business Associate Agreement with every US practice. No vendor can be “HIPAA certified,” as HHS certifies no products, so your policies, training and offboarding process remain yours.
Yes. CureCast supports both separate location accounts and a central clinical photo library across locations.With separate accounts, each location has its own patients, photos, staff, and permissions. With a shared library, locations can share patient and photo data while access remains controlled by location and staff permissions.
Staff use individual accounts rather than shared credentials, and an administrator can manage the appropriate location accounts.
SkinLab by Dr. Jamuna Pai operates CureCast across 20+ aesthetic clinic locations across India and UAE from a single account with centralized client records and location-specific access controls.
Yes. CureCast lets you build treatment-specific counselling galleries such as CoolSculpting, Botox, laser body contouring, skin tightening so a new client sees real results from your own practice matching their body type and goals. Every before/after you create is automatically filed into the right treatment gallery without any manual effort. The consultation becomes a visual conversation rather than a verbal pitch.
Yes. Instantly search and display similar cases based on condition, skin type, or treatment, helping improve patient understanding and conversion during consultations.
Clinical photographs are protected health information, and a dermatology practice generates thousands of them a year across progression tracking, lesion documentation and treatment records. CureCast supports HIPAA-compliant workflows for that volume. We sign a Business Associate Agreement with every US practice, images are encrypted with AES-256 at rest and TLS 1.3 in transit, staff access is controlled individually at module and action level, and every view, download and share is recorded in an audit trail. No software can be “HIPAA certified,” since HHS does not certify products. Compliance remains your practice’s programme, and CureCast is built to support it.
Yes. CureCast supports both separate accounts per location and a central clinical photo library across locations.
With separate accounts, each location keeps its own patients, photos, staff, and permissions. If locations choose to share a library, authorized staff can access relevant records across locations using their individual staff accounts and location-scoped permissions.
An administrator can manage multiple location accounts when required.
SkinLab by Dr. Jamuna Pai operates CureCast across 20+ dermatology clinic locations across India and UAE from a single account, with location-specific access controls and centralized patient records.
Yes. Send a secure upload link via WhatsApp or email in one tap. Patients can upload photos, videos, or files directly from their phone without installing CureCast app. Images are automatically saved to the correct patient record, and you receive an instant notification, ideal for tracking acne progress or post-treatment recovery.
Yes. Search by condition, treatment, or keyword such as acne, melasma, cool sculpting, laser, chemical peel, PRP and matching photos appear instantly in under 3 seconds. Each photo can be tagged under multiple conditions, so a single patient can show up in different searches without duplication.
Yes. CureCast organizes a patient’s clinical photos by visit date, making it easy to review progress across multiple appointments. For conditions such as acne, melasma, and pigmentation that may change gradually over weeks or months, you can view the patient’s photo history and compare images from different visits. Select photos from two visits to create a before-and-after comparison and show patients how their results have changed over time.
Yes. CureCast includes photo annotation tools that work directly within the app. During a consultation you can draw on photos and add text notes, useful for marking treatment areas, highlighting planned incision points, or annotating progress photos for the clinical record. The annotation tools are designed to be quick enough to use with a patient in the room without interrupting the consultation flow. Annotated photos are saved to the patient chart alongside the original.
Yes. CureCast supports multi-location plastic surgery groups with two options for managing patient photos and clinical data.
Separate account per location: Each clinic has its own account with its own patients, photos, staff, and permissions. Staff at one location cannot search or view another location’s patients. One administrator can manage multiple location accounts.
One central library across locations: Locations can also share a single patient database and photo library. Staff continue to use their individual accounts, with access controlled by their assigned permissions and location. A surgeon working across multiple sites can access the patient photos they are authorized to see from their own login.
Choose separate accounts when locations are separate legal entities or franchises, patients belong to a specific site, or locations need their data held separately. Choose a shared library when locations operate as one practice, surgeons work across sites, or you want a group-wide patient-photo portfolio and reporting.
Yes. CureCast lets you build procedure-specific and condition-specific counselling galleries for every treatment you offer. For rhinoplasty, you can create galleries filtered by nose type, anatomy, or correction needed, open rhinoplasty, revision rhinoplasty, ethnic rhinoplasty so a new patient sees results that match exactly what they are seeking. For liposuction patients, build zone-specific galleries by waist, flanks, abdomen, or inner thighs separately. Every before and after you create is automatically filed into the right procedure gallery without any manual effort.
All patient photos, videos, documents and clinical records are stored on Amazon Web Services with automatic redundant backups, encrypted with AES-256 at rest and TLS 1.3 in transit. CureCast holds a signed Business Associate Agreement with AWS. You never need to back up manually.
Yes. CureCast allows administrators to control staff access using individual user accounts and permissions. Each staff member has their own login, and administrators can assign access based on their role. Permissions can be managed at the module and action level, including access to view, edit, delete, download, and share patient photos.
Yes, if the app stores or handles protected health information on your behalf and your practice is a covered entity. HIPAA requires a covered entity to have a written BAA in place with any business associate before that vendor handles PHI.
CureCast signs a BAA with every US practice, and we hold one with AWS, who host the storage. Ask any vendor for their BAA before you upload a single patient photo. A vendor who is vague about it is telling you something. Contact us at [email protected] to receive yours.
Yes, both. To share with a patient, select any photos, videos, docs, or before/after comparison and send directly via WhatsApp or email in one tap. Crucially, you do not need to save the patient’s phone number to your personal contacts, CureCast handles the share securely without exposing your personal information.
To share on Instagram, Facebook, or any other social media app installed on your device, add your clinic watermark and logo within CureCast first, then share directly via your device’s native share sheet. The photo never needs to be downloaded to your personal camera roll. Patient consent must be in place before any social media sharing.
Yes, before and after photographs are protected health information. A clinical image that can be linked to an individual is PHI under HIPAA even when no name appears in the frame, and facial photographs are identifiable by definition.
CureCast supports HIPAA workflows for capturing, storing and comparing them. We sign a Business Associate Agreement with every US practice, photos are encrypted with AES-256 at rest and TLS 1.3 in transit, and they are never saved to a staff member’s camera roll. Staff access is controlled individually at module and action level, and every view, download and share is recorded in an audit trail. No vendor can be “HIPAA certified,” as HHS certifies no products. Your practice remains responsible for its own policies and for patient authorisation before any photograph is used in marketing.
Yes. Send the patient a secure upload link by Email, straight from CureCast. If their number or email is saved in the app, it sends in one tap. The patient uploads from their phone, no app to install. Photos, videos, and documents land in their file automatically, and you get an instant notification.
New patient – Search your portfolio by procedure, body area, or condition. Show real results from your own practice, not stock photos. They see themselves in it. They book.
Returning patient – Open their photo timeline. Build a before/after between any two visits in seconds. They see exactly what changed, and how far they’ve come. Their doubt disappears.
Yes. Search photos by procedure, treatment, patient, or other available details. CureCast describes photo retrieval in under 3 seconds, depending on search and system conditions.
Yes. CureCast supports two multi-location setups, depending on how your practice wants to manage patient data.
Separate account per location: Each clinic has its own account with its own patients, photos, staff, and permissions. Staff at one location cannot search or view another location’s patients, and there is no setting they can change to widen that access. One administrator can manage every account.
One shared library across locations: Locations can also share a single patient database and photo library with location-scoped access controls. Staff still use their individual accounts and only see the information they are authorized to access. A clinician working across sites can use their own login to access authorized records across locations.
Choose separate accounts when locations are separate legal entities or franchises, patients belong to a specific site, or different locations need their data held in different countries. Choose a shared library when locations operate as one practice, clinicians work across sites, or you want group-wide reporting and a shared portfolio.
Your patient data always belongs to you. If you decide to end your CureCast subscription, you can download all your patient photos and health records in bulk at any time, in batches, organised by patient, directly to your computer. We provide a full data export before your account is closed. You are never locked in or held hostage to your data. We recommend downloading a backup periodically regardless, which CureCast makes easy with one click from your dashboard.
Yes. CureCast works across iPhone, Android smartphones, iPad, Android tablets, and desktop or laptop computers through a web browser. Staff use their individual CureCast accounts, and access is controlled by their assigned permissions and clinic location.
Patient data stays synchronized across supported devices. For example, a staff member can capture photos on a clinic smartphone while an authorized doctor reviews and presents them on an iPad or desktop during a consultation.