Device Management

Control every device
That Can Open Patient Photos

See every device connected to CureCast, end sessions remotely, and revoke a former employee's access to patient photos across their devices.

View all connected devices, platforms and session status
End active sessions remotely for any device
Deactivate a staff account to end access across all devices
Connected Devices
4 records · 3 active
Filter / Search
Staff / Device Platform Status Action
M
Mark T.
iPhone 14
iOS 17
Active
End
S
Sarah K.
Clinic iPad
iPadOS 17
Active
End
J
Julia R.
Chrome · Mac
Desktop
Active
End
D
Dan W.
Android · Phone
Android 13
Expired
Deactivate staff to end all sessions
Live monitoring
Device lost?
End session remotely
Staff left?
Deactivate account

Control Every Device That Can Open Patient Photos

Device management starts with visibility. Patient records and clinical photos may be accessed from clinic computers, shared iPads, staff phones, and other authorized devices. CureCast gives practices visibility into devices connected to their account, including the associated staff member or login, device platform, operating-system version, app version, current status, login time, and last recorded activity.

If a device is lost or no longer trusted, an authorized administrator can review the associated device record and end that device’s active CureCast session. If a staff member leaves, deactivating the staff account ends active CureCast sessions associated with that staff account.

See Devices Connected to Your Practice

The CureCast Devices screen gives administrators a practical view of device records associated with their account.

 

Each device record can show

Login identity
Associated staff member, where applicable
Device name
Platform, including iOS, Android, or Desktop
Operating-system version
CureCast app version, where applicable
Current device/session status
Login time
Last recorded activity

 

The Devices screen shows both active and expired device records, helping practices review current access as well as previously recorded sessions.

Administrators can use the available search and filter controls to find device records using account, staff, device, platform, operating-system, app-version, status, login-time, and last-activity information.

 

Why This Matters

This gives administrators a clearer view of device access to CureCast. Administrators can review:

Who or which login used the device
Which device or browser session was used
Whether the session is active or expired
When the device signed in
When it was last active

Review Current and Expired Device Records

Not every device record represents current access.

 

CureCast shows the current status of each device record, including whether it is active or expired. This helps administrators distinguish devices with an active CureCast session from device records that are no longer active.

 

For each record, login time and last recorded activity provide useful context when reviewing a device associated with a staff member, clinic computer, phone, or tablet.

 

This is especially useful when:

 

  • A clinic device is reassigned
  • A staff member leaves the practice
  • A device appears unfamiliar
  • A practice is reviewing a suspected privacy incident
  • A device is lost or no longer trusted

The Devices screen shows both active and expired device records, helping practices review current access as well as previously recorded sessions.

 

Administrators can use the available search and filter controls to find device records using account, staff, device, platform, operating-system, app-version, status, login-time, and last-activity information.

Re-register a Device Through a New Device Record

When a device is registered again, CureCast creates or displays a new device record in the Devices screen. The new entry can show the associated login, staff member where applicable, device details, platform, app version, status, login time, and last recorded activity.

 

The previous device record and its historical audit activity remain separate from the new device entry. Practices can continue reviewing historical activity in the Audit Trail according to the account’s retention arrangement.

Respond When a Device Should No Longer Have Access

A device can become a concern for many reasons:

  • A staff member leaves the practice
  • A clinic iPad is misplaced
  • A staff phone is lost or stolen
  • A shared workstation should no longer be used
  • An unfamiliar device appears in the account
  • A staff member changes roles
  • A device is no longer approved for clinical work

When that happens, an authorized administrator can review the device record and take appropriate action from the CureCast Devices screen.

Deactivate a Staff Account to End Access Across Devices

When a staff member leaves the practice, access should be removed promptly.

Deactivating a staff account ends active CureCast sessions associated with that staff account. This helps practices remove CureCast access across the former employee’s active phone, tablet, computer, and browser sessions.

Administrators can also review the device records associated with that staff account as part of the offboarding process and use the audit trail to review recorded activity before and during offboarding.

If a Phone, Tablet, or Computer Is Lost

If a staff phone, clinic iPad, laptop, or workstation that can access CureCast is lost, stolen, or no longer trusted, start by reviewing the associated device record.

An authorized administrator can:

 

1

Review the login identity, associated staff member, device details, login time, last activity, and current status.

2

End the active CureCast session for that specific device from the Devices screen. Other sessions for the same staff account remain active unless the staff account is deactivated.

3

Review recorded activity in the CureCast audit trail by device, staff/login, patient, event, and date range.

4

Follow the practice's own lost-device and incident-response procedure for other systems, files, email accounts, or physical-device controls.

Ending access to CureCast is one important step. Your practice may also need to secure other systems that were accessible from the device and assess whether further investigation is required.

If the device is later recovered or registered again, the new device/session should be reviewed in the Devices screen, while the previous device's recorded activity remains available in the Audit Trail according to the account's retention arrangement.

End an Active Session

Ending a session stops CureCast access for the selected device/session only. Other active CureCast sessions for the same staff account remain active. The user on the selected device must authenticate again before continuing to use CureCast.

This can be useful when:

  • A staff member leaves or changes roles
  • A clinic device is handed to a different team member
  • An administrator wants to stop current access while reviewing activity
  • A device may have been left signed in

If you need to remove CureCast access across all active sessions associated with one staff member, deactivate that staff account instead.

 

End a Session, Deactivate Staff, or Use MDM

 

Action What It Affects What It Means
End Session One selected device/session Stops CureCast access for that specific device/session. Other sessions for the same staff account remain active.
Deactivate Staff All active sessions associated with one staff account Ends active CureCast sessions associated with that staff account and prevents continued CureCast access through that account.
Expired Session One device/session record The device/session record is no longer active in CureCast.
Device Record Management Device record Administrators can manage device records from the Devices screen. The exact effect of Delete should follow CureCast's device-management workflow.
Remote Wipe Physical device Removes data from the physical phone, tablet, or computer. CureCast should not be described as providing remote wipe unless separately confirmed.
Mobile Device Management (MDM) Organization-managed devices A separate category of software used to enforce physical-device policies, remote wipe, encryption, OS requirements, and organization-wide device controls.

Historical Device Activity Remains Searchable

A device record and its audit history are not the same thing.

 

The Devices screen helps administrators review and manage device records associated with CureCast access. The Audit Trail preserves recorded activity separately.

 

If a device session becomes expired or a device record is deleted from the Devices screen, the recorded historical audit activity associated with that device can still be searched in the Audit Trail using the recorded device information.

 

This helps practices investigate past activity involving a device, including after the device is no longer listed in the Devices screen.

 

For example, if a clinic removes an old browser session or device record, it can still review recorded activity associated with that device, including patient-record views, clinical-photo activity, downloads, shares, bulk downloads, timestamps, and available IP-address context.

 

This is highly useful for:

  • Former employee offboarding.
  • Internal compliance reviews.
  • Suspicious browser-session review.
  • Patient-photo access investigations.
  • Privacy-incident evidence gathering.
  • Lost or stolen device investigations.

Review Activity From a Device

Device management works together with CureCast’s audit trail, helping your practice review recorded activity associated with staff devices and sessions.

If a device is lost, unfamiliar, expired, deleted from the Devices screen, or related to a suspected privacy incident, your practice can still review recorded activity associated with that device in the Audit Trail.


The Devices screen is used to review and manage device records. The Audit Trail preserves historical recorded activity separately, including the device information associated with each event.

Filter the activity you need

Recorded activity can be reviewed using available filters for:

Device
Staff / Login
Patient
Event
IP Address
Date Range

What the audit trail can help you review

Patient records viewed
Clinical-photo activity
File downloads
File shares
Bulk downloads
Consent-form activity
Failed login attempts
Data-export activity

Practice responsibility

The audit log records what happened in CureCast. Your practice remains responsible for deciding whether access was appropriate and whether any additional incident-response action is required.

Export Activity for a Lost or Suspicious Device

If a phone, tablet, computer, or browser session is lost, unfamiliar, expired, deleted from the Devices screen, or involved in a suspected privacy incident, authorized users can still review related recorded activity in the CureCast Audit Trail.

 

Use available filters for device, staff/login, patient, event, IP address, and date range to narrow the results. Authorized users can then export matching recorded activity in CSV or PDF format using a custom date or month range.

 

The exported activity can help a practice review the device-associated record of access, including recorded patient activity, clinical-photo actions, downloads, shares, bulk downloads, staff or login identity, device context, IP address, and timestamps.

 

The audit log records activity in CureCast. Your practice remains responsible for assessing whether access was appropriate and whether further incident-response or compliance action is required

 

Device Management Works With Staff Access Controls

Staff access controls determine what a person is permitted to access. Device management helps your practice review when a particular phone, tablet, computer, or session is associated with CureCast access.

For example:

A front-desk staff member may be allowed to access patient records but not clinical photos.
A clinical staff member may access photos but not download or share them.
If that staff member leaves, the practice can deactivate the staff account to end active CureCast sessions associated with that staff account.

Learn about Staff Access Controls

Device Management Is Not Full Mobile Device Management

CureCast helps practices manage CureCast application access from connected devices. It is not a replacement for a practice’s wider device-security program.

Your practice may also need its own policies and tools for:

  • Clinic-owned versus personal devices
  • Device passcodes and biometric security
  • Operating-system updates
  • Mobile device management (MDM)
  • Device encryption
  • Remote wipe
  • Camera-roll and local-file policies
  • Workforce training
  • Lost-device reporting
  • Broader incident-response procedures

Device controls are one part of a HIPAA-compliant workflow, not the entire workflow.

 

Personal Phones and Clinic Device Policies

Whether staff may use personal phones to access CureCast is a decision for each clinic’s device, privacy, and security policy.

 

If a clinic permits personal-device access, administrators can still control the staff member’s CureCast permissions and review recorded in-app activity through the Audit Trail. The clinic remains responsible for its rules regarding device passcodes, encryption, local storage, screenshots, downloads, camera-roll access, and lost or stolen personal devices.

 

A clinic can use a shared iPad for CureCast when each staff member signs in with their own individual account.

 

Before another staff member uses the iPad, the previous user should log out. The next staff member should then sign in with their own credentials. This keeps application access and recorded activity associated with the correct staff account.

Shared clinic devices should use separate individual sign-ins for each person, not a shared account

Built for HIPAA-Compliant Workflows

CureCast is built to support HIPAA-compliant workflows for US healthcare practices.

 

Device management helps practices identify devices connected to CureCast, review active and expired device records, end one selected device/session when needed, and deactivate a staff account to end active CureCast sessions associated with that staff account. Your practice remains responsible for its own compliance obligations, including device policies, workforce procedures, physical-device security, and incident-response decisions.

 

Summary of the HIPAA Security Rule 

Frequently asked Questions

Can I see which devices are connected to CureCast?

Yes. The Devices screen shows device records associated with your account, including login identity, associated staff member where applicable, device name, platform, operating-system version, app version where applicable, status, login time, and last recorded activity.

Can I see both active and expired device records?

Yes. The Devices screen shows device records with active or expired status, helping administrators review current and previously recorded sessions.

Can I find devices associated with a particular staff member?

The Devices screen includes staff-member and login-identity information, along with search and filter controls to help administrators locate device records using available account and device details.

Can I end an active CureCast session remotely?

Yes. Authorized administrators can select End Session for an active device record from the Devices screen. The user must authenticate again before continuing to access CureCast.

Does ending a session log a staff member out of every device?

No. Ending a session affects the selected device/session only. Other active CureCast sessions for the same staff account remain active.

How do I remove CureCast access from all devices used by a former employee?

Deactivate the staff account. Deactivating a staff account prevents further authenticated access on the next request, and active CureCast sessions associated with that account can also be ended as part of offboarding.

What should I do if a clinic phone, iPad, or computer is lost?

Review the device record, end any active CureCast session, and review related activity in the audit trail. Your practice should also follow its own lost-device and incident-response procedure for other systems and data that may be accessible from the device.

Can I review activity from a specific device?

Yes. CureCast’s audit trail can be filtered using device information, together with staff/login, patient, event, IP address, and date range, to review recorded CureCast activity.

Is CureCast device management the same as MDM or remote wipe?

No. CureCast helps administrators manage CureCast access from device records and end active sessions. It does not replace a full mobile-device-management system, remote-wipe capability, or the practice’s broader physical-device security program.

Does deleting a device record remove its audit history?

No. Deleting a device record removes it from the Devices screen, but recorded historical activity remains available in the Audit Trail for review.

Plastic surgeon using CureCast photo management app during patient consultation

See How CureCast Fits Your Practice

Discuss how CureCast fits into your clinical photo workflow, from capturing and organizing patient photos to securely managing them across your practice.

 

Prefer email? [email protected]