Questions about CureCast? Start here.
Get clear answers about patient photos, before & after workflows, security, compliance, pricing, and how CureCast fits into your practice.
BOOK A DEMO- Before & After
- Dermatology
- HIPAA & Compliance
- Medical Spas
- Patient Photos
- Plastic Surgery
- Pricing
- Secure Patient Photo Upload
- Security & Compliance
- Staff-management
- TrueAlign Match
CureCast is designed for practices that rely on clinical photography throughout the patient journey. Whether you run a plastic surgery practice, dermatology clinic, or medical spa, CureCast keeps patient photos organized from capture and follow-up through before-and-after comparison and remote photo collection. These workflows are part of CureCast’s broader clinicalphoto management system, so your team can manage clinical photography in one connected place.
CureCast brings clinical photography into one workflow, from capturing consistent photos and creating before-and-after comparisons to collecting follow-up photos from patients remotely. Practices can use overlay earlier photos as a reference when taking new images, organize photos by patient and treatment, and send a secure upload link when a patient cannot return to the clinic. This keeps clinical photos organized and connected to the patient record throughout their care.
Patient records yes, photo libraries mostly no, and we would rather tell you that before you buy. Patient demographics and records import from a spreadsheet, which is quick. Historical photographs are harder, and there is no bulk photo import. The reason is that images sitting in camera rolls, shared drives and old systems almost never carry a reliable link to a patient record, and no software can recreate that link automatically. You have two routes: staff upload historical images to the right patient record as needed, or, where your existing system has an API, we build an integration to bring the library across. Integration work is quoted separately.
Most practices are capturing photos within 24 to 48 hours of signing up. CureCast is cloud-based, so there is no server to install and no hardware to configure. Download the app, sign up, and you can begin adding patients immediately. Practice includes three hours of hands-on training, and there is no setup or implementation fee. The 14-day free trial needs no credit card, so you can run the whole setup before committing.
No. Photo, video and document storage is unlimited on every plan. Storage caps and per-gigabyte overage charges are common in this category and they tend to bite three or four years in, when a busy practice has accumulated tens of thousands of images.
No. There is no setup fee, no implementation charge, and no fee to export your data. Migration support is included, and Practice includes three hours of hands-on training. You can download your full photo library and patient records at any time, in one click.
Any phone, tablet or computer signed in to your CureCast account. Staff use individual logins, so several people can share a clinic iPad without it counting more than once. You can see and manage every connected device from the Devices screen, and end a session to free up an allowance.
Per location, with a device allowance rather than a per-seat charge. Starter covers one clinic location and three devices, Practice covers one location and five devices. That means adding a staff member does not automatically increase your bill, which is the usual behaviour in per-seat pricing. Multiple locations are quoted on Enterprise.
Patient photos used for marketing require appropriate patient authorization. In the United States, HIPAA marketing uses of protected health information are governed by 45 CFR §164.508. Practices should also follow the advertising and privacy requirements that apply in their jurisdiction.
CureCast organizes patient photos by visit date and treatment, allowing staff to select photographs from different appointments and create a comparison without manually searching through separate folders.
A patient can choose to text their own photos. HIPAA applies to your practice, not the patient. The risk is what happens after the photo arrives. It lands on a staff phone. It may sync to a personal cloud account. It sits outside your records. Standard text messaging and consumer messaging apps do not sign Business Associate Agreements. HIPAA does allow a practice to text a patient who asks for it and has been told the risks. That does not make a staff phone a safe place to keep clinical photos. A secure upload link solves this. The patient still uses their phone, but the photo goes into your practice’s account instead of a staff member’s phone. What HIPAA requires for clinical photos
Send them a secure upload link. Create the link from the patient’s record in CureCast. Send it by email or SMS at each follow-up point, such as day 7, week 4 and month 3. The patient opens it in any phone or computer browser and uploads. No app. No account. The photos save straight into their record. You still get the final after photo, even if they never book another visit.
No. Once uploaded, the files go straight to the clinic’s CureCast account and are not shown again to the person using the link.
No. The same link stays active, so the patient can use it again for future uploads.
Yes. Uploaded files appear in the patient’s file manager and chart summary, so authorized staff can review them in one place.
Yes. The secure upload link accepts photos, videos and documents, and you can review them in the patient’s CureCast record.
Yes. Share the upload link by email, SMS, WhatsApp or any channel your practice approves. The link contains no patient details. WhatsApp, SMS and email only carry the link text, when the patient taps it, it opens in their browser and the photo uploads straight to CureCast, not through the messaging app. Messaging rules differ by market, so check your local rules and practice policy before choosing a channel.
Yes. Patients can upload photos, videos or files through their browser using a secure CureCast upload link, on a mobile phone, tablet, PC or Mac, without downloading the CureCast app.
No. The feature exists precisely because most clinical photography happens handheld, in a treatment room, between appointments.
Yes, on iPhone and iPad, and photographs from both are captured at the same shape and size so a patient can move between devices between visits.
Nothing is blocked. The overlay is guidance, not a gate. You can capture at any moment, however closely the patient matches, and it will be saved normally.
Yes. Any photograph in a patient’s file can be used as the reference, including images taken before you started using this feature.
A studio isn’t necessary for consistent photos. The key is aligning the patient the same way each time. CureCast lets you use the earlier photo as a live reference while you capture the new one.
Yes. TrueAlign Match overlays the patient’s earlier photograph on the camera as a ghost image, at an opacity you control, so the follow-up can be lined up against it. It also offers the same reference as a single outline, for views that are harder to compare side by side.
Yes. Generate a secure upload link and send it by WhatsApp or email.
The patient opens it and uploads straight from their phone, no login, nothing to install. The photos land in their record automatically, and you get the notification.
Yes, and it is separate from consent to treatment. Under US HIPAA, using a patient’s photograph for marketing requires a written authorisation containing specific required elements, and it cannot be combined with a consent form that conditions treatment. CureCast includes consent forms with up to four signers and records marketing permission against the patient, so you can see whether a patient is cleared before building a gallery. Your practice remains responsible for the content of its authorisation forms.
Yes, by WhatsApp or email in one tap, without saving their number to your personal contacts.
Yes, inside CureCast, before saving or sharing. The image does not need to pass through a third-party editing app or your personal camera roll.
Every before and after you build saves in two places: the patient’s own record, and your portfolio, filed under that treatment name.
So later, you don’t search for the patient. You search the treatment, like “rhinoplasty,” and every comparison filed under it shows up.
Yes, and this is what the tagging is for.
During a consultation, search by the procedure or condition the patient is asking about. Show real results from your own practice rather than generic material.
Search by treatment name, condition, body area, or patient name.
Every photo is tagged the moment it’s captured, so nothing needs filing afterward. Search “rhinoplasty,” for example, and you get every rhinoplasty result, including before and afters you’ve already built.
Side by side, overlay, and slide.
- Side by side shows two separate photos next to each other.
- Overlay fades between the two images in the same frame.
- Slide lets you drag a divider across to reveal the change.
Yes. CureCast organises each patient’s photos by visit date automatically. Open their history, select any two photos from any two visits, and the comparison is built in seconds. One week apart or two years apart works the same way.
No. The US Department of Health and Human Services does not certify, approve, endorse or accredit any software, server, cloud provider or vendor. There is no government-issued HIPAA certificate, and no official list of approved products.
Some vendors advertise HIPAA certification anyway. What they usually mean is that they have had a third-party audit, which is a reasonable thing to do but is not a government certification and does not make a practice compliant.
What to ask instead: will you sign a BAA, how is data encrypted at rest and in transit, how is staff access controlled, and what does the audit trail record. Those are answerable questions with verifiable answers.
Patient data is stored on encrypted cloud infrastructure with AES-256 at rest and TLS in transit. CureCast holds a signed Business Associate Agreement with the infrastructure provider, and we sign one with every US practice. Tell us where you are licensed and we will confirm your account’s region in writing.
With photos taken on personal phones, usually nothing good. They stay in that person’s camera roll and personal cloud account, and the practice has no route to recover or delete them. With CureCast, deactivating the staff account ends their sessions across every device immediately and removes their access. The photos were never on their device to begin with. The audit trail retains a record of what they accessed while employed.
As of now, Meta does not sign Business Associate Agreements, so WhatsApp is not a HIPAA-covered channel for routine disclosures. HIPAA does permit a covered entity to send information to the patient themselves through a channel the patient has asked for, provided the practice has warned them of the risks and documented that. That is a patient-directed disclosure with conditions, not a compliant messaging system.
Yes. A clinical photograph that can be linked to an individual is protected health information, because an identifiable image combined with treatment information meets the definition. Facial photographs are identifiable on their own.
This applies to before and after photographs, progression series and images taken for the patient’s record. Cropping out a face does not automatically remove identifiability, since tattoos, scars and other distinguishing features can identify a person.
They can, but it creates a problem worth avoiding. A photo taken with the phone’s own camera app is saved to that staff member’s camera roll and, on most phones, synced automatically to their personal cloud account. Your clinical images then sit on a device and in an account your practice does not control, and cannot retrieve when that person leaves. Photos taken through CureCast Camera go directly into your practice account. They are never written to the camera roll and never sync to a personal cloud. If a phone is lost or a staff member leaves, the images stay with the practice.
Yes, treatment photographs taken at a medical spa are protected health information when the spa operates as a covered entity, and the usual exposure is staff phones rather than the software. CureCast supports HIPAA-compliant workflows. Photos taken through the app go straight into your practice account and are never saved to the device’s camera roll or synced to a staff member’s iCloud, so a departing injector does not leave with your clinical images. Each staff member signs in individually, access is controlled per person, and every action is updated in audit log. We sign a Business Associate Agreement with every US practice. No vendor can be “HIPAA certified,” as HHS certifies no products, so your policies, training and offboarding process remain yours.
Not necessarily. Access depends on how your locations are configured.
With separate accounts per location, staff use the appropriate account for each clinic, and each location has its own patients, photos, staff, and permissions.
With one shared clinical photo library across locations, staff can access authorized patient photos across locations using their individual staff account. Access remains controlled by location and the permissions assigned to that staff member.
Administrators can therefore decide whether locations should keep patient-photo data separate or share a clinical library across locations.
Yes. Download and share access is controlled separately from photo-viewing access.
For activity performed through an individual staff account, the audit log identifies the staff account associated with recorded photo activity.
Yes. Administrators can review the device record and end the active CureCast session from a lost, stolen, or no-longer-trusted device.
Their account can be deactivated, preventing further authenticated access on the next request. Active CureCast sessions associated with that staff account can also be ended as part of the practice’s offboarding process.
Yes. Administrators can allow appropriate internal sharing while preventing a staff member from downloading files to their device.
Yes. Administrators can restrict a contractor or photographer to selected modules and actions, such as Albums or photo viewing, without granting access to patient records, editing, deleting, downloading, or sharing.
Only authorized administrators can update staff permissions.
Module access controls which areas of CureCast a staff member can access, such as Patients, Before/After, Albums, Billing, Prescriptions, or Appointments. Action permissions control sensitive actions such as Edit/Delete and Download/Share.
Yes. Practices should review and adjust module access and sensitive action permissions when creating a staff account, based on the person’s responsibilities.
Yes. Administrators can configure module access for each staff member, including areas such as Patients, Before/After, Albums, Appointments, Prescriptions, and Billing.
Yes. CureCast supports both separate location accounts and a central clinical photo library across locations. With separate accounts, each location has its own patients, photos, staff, and permissions. With a shared library, locations can share patient and photo data while access remains controlled by location and staff permissions.
Staff use individual accounts rather than shared credentials, and an administrator can manage the appropriate location accounts.
SkinLab by Dr. Jamuna Pai operates CureCast across 20+ aesthetic clinic locations across India and UAE from a single account with centralized client records and location-specific access controls.
Yes. CureCast lets you build treatment-specific counselling galleries such as CoolSculpting, Botox, laser body contouring, skin tightening so a new client sees real results from your own practice matching their body type and goals. Every before/after you create is automatically filed into the right treatment gallery without any manual effort. The consultation becomes a visual conversation rather than a verbal pitch.
Yes. Instantly search and display similar cases based on condition, skin type, or treatment, helping improve patient understanding and conversion during consultations.
Clinical photographs are protected health information, and a dermatology practice generates thousands of them a year across progression tracking, lesion documentation and treatment records. CureCast supports HIPAA-compliant workflows for that volume. We sign a Business Associate Agreement with every US practice, images are encrypted with AES-256 at rest and TLS 1.3 in transit, staff access is controlled individually at module and action level, and every view, download and share is recorded in an audit trail. No software can be “HIPAA certified,” since HHS does not certify products. Compliance remains your practice’s programme, and CureCast is built to support it.
Yes. CureCast supports both separate accounts per location and a central clinical photo library across locations.
With separate accounts, each location keeps its own patients, photos, staff, and permissions. If locations choose to share a library, authorized staff can access relevant records across locations using their individual staff accounts and location-scoped permissions.
An administrator can manage multiple location accounts when required.
SkinLab by Dr. Jamuna Pai operates CureCast across 20+ dermatology clinic locations across India and UAE from a single account, with location-specific access controls and centralized patient records.
Yes. Send a secure upload link via WhatsApp, SMS or email in one tap. Patients can upload photos, videos, or files directly from their phone without installing CureCast app. Images are automatically saved to the correct patient record, and you receive an instant notification, ideal for tracking acne progress or post-treatment recovery.
Yes. Search by condition, treatment, or keyword such as acne, melasma, cool sculpting, laser, chemical peel, PRP and matching photos appear instantly in under 3 seconds. Each photo can be tagged under multiple conditions, so a single patient can show up in different searches without duplication.
Yes. CureCast organizes a patient’s clinical photos by visit date, making it easy to review progress across multiple appointments. For conditions such as acne, melasma, and pigmentation that may change gradually over weeks or months, you can view the patient’s photo history and compare images from different visits. Select photos from two visits to create a before-and-after comparison and show patients how their results have changed over time.
Yes. CureCast includes photo annotation tools that work directly within the app. During a consultation you can draw on photos and add text notes, useful for marking treatment areas, highlighting planned incision points, or annotating progress photos for the clinical record. The annotation tools are designed to be quick enough to use with a patient in the room without interrupting the consultation flow. Annotated photos are saved to the patient chart alongside the original. It is currently available only on iPhone and iPad
Yes. CureCast supports multi-location plastic surgery groups with two options for managing patient photos and clinical data.
Separate account per location: Each clinic has its own account with its own patients, photos, staff, and permissions. Staff at one location cannot search or view another location’s patients. One administrator can manage multiple location accounts.
One central library across locations: Locations can also share a single patient database and photo library. Staff continue to use their individual accounts, with access controlled by their assigned permissions and location. A surgeon working across multiple sites can access the patient photos they are authorized to see from their own login.
Choose separate accounts when locations are separate legal entities or franchises, patients belong to a specific site, or locations need their data held separately. Choose a shared library when locations operate as one practice, surgeons work across sites, or you want a group-wide patient-photo portfolio and reporting.
Yes. CureCast lets you build procedure-specific and condition-specific counselling galleries for every treatment you offer. For rhinoplasty, you can create galleries filtered by nose type, anatomy, or correction needed, open rhinoplasty, revision rhinoplasty, ethnic rhinoplasty so a new patient sees results that match exactly what they are seeking. For liposuction patients, build zone-specific galleries by waist, flanks, abdomen, or inner thighs separately. Every before and after you create is automatically filed into the right procedure gallery without any manual effort.
All patient photos, videos, documents and clinical records are stored on cloud infrastructure with automatic redundant backups, encrypted with AES-256 at rest and TLS 1.3 in transit. CureCast holds a signed Business Associate Agreement with the infrastructure provider. You never need to back up manually.
Yes. CureCast allows administrators to control staff access using individual user accounts and permissions. Each staff member has their own login, and administrators can assign access based on their role. Permissions can be managed at the module and action level, including access to view, edit, delete, download, and share patient photos.
Yes, if the app stores or handles protected health information on your behalf and your practice is a covered entity. HIPAA requires a covered entity to have a written BAA in place with any business associate before that vendor handles PHI.
CureCast signs a BAA with every US practice, and we hold one with the infrastructure provider, who host the storage. Ask any vendor for their BAA before you upload a single patient photo. A vendor who is vague about it is telling you something. Contact us at [email protected] to receive yours.
Yes, both. To share with a patient, select any photos, videos, docs, or before/after comparison and send directly via WhatsApp or email in one tap. Crucially, you do not need to save the patient’s phone number to your personal contacts, CureCast handles the share securely without exposing your personal information.
To share on Instagram, Facebook, or any other social media app installed on your device, add your clinic watermark and logo within CureCast first, then share directly via your device’s native share sheet. The photo never needs to be downloaded to your personal camera roll. Patient consent must be in place before any social media sharing.
Yes, before and after photographs are protected health information. A clinical image that can be linked to an individual is PHI under HIPAA even when no name appears in the frame, and facial photographs are identifiable by definition.
CureCast supports HIPAA workflows for capturing, storing and comparing them. We sign a Business Associate Agreement with every US practice, photos are encrypted with AES-256 at rest and TLS 1.3 in transit, and they are never saved to a staff member’s camera roll. Staff access is controlled individually at module and action level, and every view, download and share is recorded in an audit trail. No vendor can be “HIPAA certified,” as HHS certifies no products. Your practice remains responsible for its own policies and for patient authorisation before any photograph is used in marketing.
Yes. Send the patient a secure upload link by email, straight from CureCast. If their number or email is saved in the app, it sends in one tap. The patient uploads from their phone, no app to install. Photos, videos, and documents land in their file automatically, and you get an instant notification.
New patient – Search your portfolio by procedure, body area, or condition. Show real results from your own practice, not stock photos. They see themselves in it. They book.
Returning patient – Open their photo timeline. Build a before/after between any two visits in seconds. They see exactly what changed, and how far they’ve come. Their doubt disappears.
Yes. Search photos by procedure, treatment, patient, or other available details. CureCast describes photo retrieval in under 3 seconds, depending on search and system conditions.
No. CureCast includes unlimited storage for photos, videos, and documents on every plan and no per-file fees, no storage cap, and no surprise charges as your library grows. A busy aesthetic practice captures between 15,000 and 20,000 clinical photos per year per location. CureCast is built to handle this volume without any performance degradation. All files are stored on encrypted cloud infrastructure and are accessible from any device instantly.
CureCast supports HIPAA workflows and we sign a Business Associate Agreement with every US practice, which is what HIPAA requires of a vendor handling protected health information. Patient photos and records are encrypted with AES-256 at rest and TLS 1.3 in transit, stored on cloud infrastructure under a signed BAA between CureCast and cloud server, and accessible only to staff you authorise, with a full audit trail. No software can be “HIPAA certified,” since HHS certifies no products, so compliance remains your practice’s programme of policies, training and safeguards, and CureCast is built to support it. Contact us to receive your BAA before your trial.
No, and this is one of CureCast’s most important compliance features. When a staff member takes a photo through the CureCast app, it is uploaded directly and securely to your practice’s encrypted storage. The photo is never saved to the device’s camera roll or gallery. This means if a staff member loses their phone, leaves the practice, or their device is accessed by someone else, your patient photos remain completely protected. Your clinic data stays in your account and not on personal devices.