Security & Compliance

Built to protect patient photos and records.

CureCast combines seven security controls to manage who accesses patient information, what activity is recorded, and how data is protected at rest and in transit.

  • Staff Access Control: who can access what
  • Audit Trail : What activity is recorded
  • Device Management : Which devices have CureCast access
  • Session Timeout : How inactive sessions are handled
  • Encryption : How patient records and clinical photos are protected
  • Confidential Patient : invisible to unauthorised staff
  • Multi-Clinic : How access stays scoped to a single clinic location
Supports compliance for
HIPAA GDPR PHIPA Australia Privacy Act
SECURITY OVERVIEW
Practice Security Status
7 controls in place
All Active
👤
Staff Access Control
Active
📋
Audit Trail
Active
📱
Device Management
Active
Session Timeout
Active
🔒
Encryption
Active
🔐
Confidential Patient Access
Active
🏥
Multi-Location Access
Active
i

Good to know: CureCast security features support a practice's privacy and security workflow. They do not replace the practice's own policies, risk assessment, staff training, patient-consent process, device-security controls, or legal obligations.

How CureCast Protects Patient Information

Each control is explained in detail on its own page. Together they cover who has access, what gets recorded, which devices are trusted, how long a session stays open, how data is protected while it’s stored and moved, which individual patients need an extra layer of privacy, and how access stays scoped to a single clinic.

CureCast staff access control illustration showing module access, action permissions, and location-scoped access

Staff Access Control

Administrators control staff access to patient records, clinical photos, albums, and sensitive actions through module-level and action-level permissions. For multi-location practices, access is scoped to each clinic account.

Audit Trail

CureCast records defined activity across patient records, files, clinical modules, consent workflows, and exports — with staff, device, IP, and timestamp context. Filter and export in CSV or PDF.

See how audit trail works →

Device Management

Administrators can review every device connected to their account and end a session when a device is lost, stolen, or no longer trusted. Deactivating a staff account ends sessions across their devices.

See how device-management work →

Session Timeout

CureCast automatically ends inactive sessions after 2 hours on desktop and 4 hours on supported mobile devices, with a warning before logout and a required sign-in to continue.

Learn about reauthentication →

Encryption

Patient records and clinical photos are encrypted at rest using AES-256 and protected in transit using TLS, with TLS 1.3 as the primary protocol and TLS 1.2 supported as a fallback.

Learn about Encryption →

Confidential Patient Access

Mark a patient confidential and their record no longer appears in search results, patient lists, or before-and-after galleries for staff who don’t hold that specific permission. Only an administrator can grant it, per staff member.
Learn about Confidential Patient Access →

  Beyond the Software

Security and compliance involve more than individual software features. Practices also need policies and procedures for access reviews, patient-photo consent, device security, incident response, staff offboarding, and applicable privacy laws.

 

 

 

 

What Is HIPAA Compliance?

An ongoing program of policies, procedures, risk analysis, training,

and technical safeguards. There is no single government-issued HIPAA

certificate that makes a platform or practice compliant.

Who Should Have Access to Patient Photos?

Not every staff member needs access to every record. Module-level and
action-level permissions let a practice match access to actual job

responsibilities.


Learn about Staff Access Control →

What Should a Healthcare Audit Trail Record?

Patient-record views, file downloads, shares, failed logins, consent
activity, exports, device context, and timestamps, though a log record

activity, it doesn’t decide whether access was appropriate.


Learn about the Audit Trail →

What Should a Practice Do After a Lost Device?

Review the device record, end the CureCast session, preserve available
audit activity, and follow the practice’s broader incident-response

procedure.


Learn about Device Management →

What Is Automatic Session Timeout?

An inactive session ends after a defined period, 2 hours on desktop,
4 hours on supported mobile with a warning before logout and a

required sign-in.


Learn about Session Timeout →

How Should Practices Protect Clinical Photos?

Staff permissions, download and sharing controls, consent management,
device and session security, staff training, and lost-device procedures

together, not any one alone.



What Is Confidential Patient Access?

A per-patient privacy setting. A confidential patient doesn’t appear in
search, lists, or galleries for staff without confidential patient

access, with no locked-record indicator and no trace they exist for that

person
.


Learn about Confidential Patient Access →

Does Each Clinic Location Have Separate Data?

Yes. Each location is its own CureCast account. A staff member at one
clinic can’t see another clinic’s patients or photos unless separately

given access to that account too.


Learn about Multi-Location Access →

Book a CureCast demo for clinical photo management software

See How CureCast Fits Your Practice

Discuss how CureCast fits into your clinical photo workflow, from capturing and organizing patient photos to securely managing them across your practice.

 

Prefer email? [email protected]