Control every device
That Can Open Patient Photos
See every device connected to CureCast, end sessions remotely, and revoke a former employee's access to patient photos across their devices.
Control Every Device That Can Open Patient Photos
Device management starts with visibility. Patient records and clinical photos may be accessed from clinic computers, shared iPads, staff phones, and other authorized devices. CureCast gives practices visibility into devices connected to their account, including the associated staff member or login, device platform, operating-system version, app version, current status, login time, and last recorded activity.
If a device is lost or no longer trusted, an authorized administrator can review the associated device record and end that device’s active CureCast session. If a staff member leaves, deactivating the staff account ends active CureCast sessions associated with that staff account.
See Devices Connected to Your Practice
The CureCast Devices screen gives administrators a practical view of device records associated with their account.
Each device record can show
The Devices screen shows both active and expired device records, helping practices review current access as well as previously recorded sessions.
Administrators can use the available search and filter controls to find device records using account, staff, device, platform, operating-system, app-version, status, login-time, and last-activity information.
Why This Matters
This gives administrators a clearer view of device access to CureCast. Administrators can review:
Review Current and Expired Device Records
Not every device record represents current access.
CureCast shows the current status of each device record, including whether it is active or expired. This helps administrators distinguish devices with an active CureCast session from device records that are no longer active.
For each record, login time and last recorded activity provide useful context when reviewing a device associated with a staff member, clinic computer, phone, or tablet.
This is especially useful when:
- A clinic device is reassigned
- A staff member leaves the practice
- A device appears unfamiliar
- A practice is reviewing a suspected privacy incident
- A device is lost or no longer trusted
The Devices screen shows both active and expired device records, helping practices review current access as well as previously recorded sessions.
Administrators can use the available search and filter controls to find device records using account, staff, device, platform, operating-system, app-version, status, login-time, and last-activity information.
Re-register a Device Through a New Device Record
When a device is registered again, CureCast creates or displays a new device record in the Devices screen. The new entry can show the associated login, staff member where applicable, device details, platform, app version, status, login time, and last recorded activity.
The previous device record and its historical audit activity remain separate from the new device entry. Practices can continue reviewing historical activity in the Audit Trail according to the account’s retention arrangement.
Respond When a Device Should No Longer Have Access
A device can become a concern for many reasons:
- A staff member leaves the practice
- A clinic iPad is misplaced
- A staff phone is lost or stolen
- A shared workstation should no longer be used
- An unfamiliar device appears in the account
- A staff member changes roles
- A device is no longer approved for clinical work
When that happens, an authorized administrator can review the device record and take appropriate action from the CureCast Devices screen.
Deactivate a Staff Account to End Access Across Devices
When a staff member leaves the practice, access should be removed promptly.
Deactivating a staff account ends active CureCast sessions associated with that staff account. This helps practices remove CureCast access across the former employee’s active phone, tablet, computer, and browser sessions.
Administrators can also review the device records associated with that staff account as part of the offboarding process and use the audit trail to review recorded activity before and during offboarding.
If a Phone, Tablet, or Computer Is Lost
If a staff phone, clinic iPad, laptop, or workstation that can access CureCast is lost, stolen, or no longer trusted, start by reviewing the associated device record.
An authorized administrator can:
Review the login identity, associated staff member, device details, login time, last activity, and current status.
End the active CureCast session for that specific device from the Devices screen. Other sessions for the same staff account remain active unless the staff account is deactivated.
Review recorded activity in the CureCast audit trail by device, staff/login, patient, event, and date range.
Follow the practice's own lost-device and incident-response procedure for other systems, files, email accounts, or physical-device controls.
Ending access to CureCast is one important step. Your practice may also need to secure other systems that were accessible from the device and assess whether further investigation is required.
If the device is later recovered or registered again, the new device/session should be reviewed in the Devices screen, while the previous device's recorded activity remains available in the Audit Trail according to the account's retention arrangement.
End an Active Session
Ending a session stops CureCast access for the selected device/session only. Other active CureCast sessions for the same staff account remain active. The user on the selected device must authenticate again before continuing to use CureCast.
This can be useful when:
- A staff member leaves or changes roles
- A clinic device is handed to a different team member
- An administrator wants to stop current access while reviewing activity
- A device may have been left signed in
If you need to remove CureCast access across all active sessions associated with one staff member, deactivate that staff account instead.
End a Session, Deactivate Staff, or Use MDM
Historical Device Activity Remains Searchable
A device record and its audit history are not the same thing.
The Devices screen helps administrators review and manage device records associated with CureCast access. The Audit Trail preserves recorded activity separately.
If a device session becomes expired or a device record is deleted from the Devices screen, the recorded historical audit activity associated with that device can still be searched in the Audit Trail using the recorded device information.
This helps practices investigate past activity involving a device, including after the device is no longer listed in the Devices screen.
For example, if a clinic removes an old browser session or device record, it can still review recorded activity associated with that device, including patient-record views, clinical-photo activity, downloads, shares, bulk downloads, timestamps, and available IP-address context.
This is highly useful for:
Review Activity From a Device
Device management works together with CureCast’s audit trail, helping your practice review recorded activity associated with staff devices and sessions.
If a device is lost, unfamiliar, expired, deleted from the Devices screen, or related to a suspected privacy incident, your practice can still review recorded activity associated with that device in the Audit Trail.
The Devices screen is used to review and manage device records. The Audit Trail preserves historical recorded activity separately, including the device information associated with each event.
Filter the activity you need
Recorded activity can be reviewed using available filters for:
What the audit trail can help you review
Practice responsibility
The audit log records what happened in CureCast. Your practice remains responsible for deciding whether access was appropriate and whether any additional incident-response action is required.
Export Activity for a Lost or Suspicious Device
If a phone, tablet, computer, or browser session is lost, unfamiliar, expired, deleted from the Devices screen, or involved in a suspected privacy incident, authorized users can still review related recorded activity in the CureCast Audit Trail.
Use available filters for device, staff/login, patient, event, IP address, and date range to narrow the results. Authorized users can then export matching recorded activity in CSV or PDF format using a custom date or month range.
The exported activity can help a practice review the device-associated record of access, including recorded patient activity, clinical-photo actions, downloads, shares, bulk downloads, staff or login identity, device context, IP address, and timestamps.
The audit log records activity in CureCast. Your practice remains responsible for assessing whether access was appropriate and whether further incident-response or compliance action is required
Device Management Works With Staff Access Controls
Staff access controls determine what a person is permitted to access. Device management helps your practice review when a particular phone, tablet, computer, or session is associated with CureCast access.
For example:
Device Management Is Not Full Mobile Device Management
CureCast helps practices manage CureCast application access from connected devices. It is not a replacement for a practice’s wider device-security program.
Your practice may also need its own policies and tools for:
- Clinic-owned versus personal devices
- Device passcodes and biometric security
- Operating-system updates
- Mobile device management (MDM)
- Device encryption
- Remote wipe
- Camera-roll and local-file policies
- Workforce training
- Lost-device reporting
- Broader incident-response procedures
Device controls are one part of a HIPAA-compliant workflow, not the entire workflow.
Personal Phones and Clinic Device Policies
Whether staff may use personal phones to access CureCast is a decision for each clinic’s device, privacy, and security policy.
If a clinic permits personal-device access, administrators can still control the staff member’s CureCast permissions and review recorded in-app activity through the Audit Trail. The clinic remains responsible for its rules regarding device passcodes, encryption, local storage, screenshots, downloads, camera-roll access, and lost or stolen personal devices.
A clinic can use a shared iPad for CureCast when each staff member signs in with their own individual account.
Before another staff member uses the iPad, the previous user should log out. The next staff member should then sign in with their own credentials. This keeps application access and recorded activity associated with the correct staff account.
Shared clinic devices should use separate individual sign-ins for each person, not a shared account
Built for HIPAA-Compliant Workflows
CureCast is built to support HIPAA-compliant workflows for US healthcare practices.
Device management helps practices identify devices connected to CureCast, review active and expired device records, end one selected device/session when needed, and deactivate a staff account to end active CureCast sessions associated with that staff account. Your practice remains responsible for its own compliance obligations, including device policies, workforce procedures, physical-device security, and incident-response decisions.
Frequently asked Questions
Can I see which devices are connected to CureCast?
Yes. The Devices screen shows device records associated with your account, including login identity, associated staff member where applicable, device name, platform, operating-system version, app version where applicable, status, login time, and last recorded activity.
Can I see both active and expired device records?
Yes. The Devices screen shows device records with active or expired status, helping administrators review current and previously recorded sessions.
Can I find devices associated with a particular staff member?
The Devices screen includes staff-member and login-identity information, along with search and filter controls to help administrators locate device records using available account and device details.
Can I end an active CureCast session remotely?
Yes. Authorized administrators can select End Session for an active device record from the Devices screen. The user must authenticate again before continuing to access CureCast.
Does ending a session log a staff member out of every device?
No. Ending a session affects the selected device/session only. Other active CureCast sessions for the same staff account remain active.
How do I remove CureCast access from all devices used by a former employee?
Deactivate the staff account. Deactivating a staff account prevents further authenticated access on the next request, and active CureCast sessions associated with that account can also be ended as part of offboarding.
What should I do if a clinic phone, iPad, or computer is lost?
Review the device record, end any active CureCast session, and review related activity in the audit trail. Your practice should also follow its own lost-device and incident-response procedure for other systems and data that may be accessible from the device.
Can I review activity from a specific device?
Yes. CureCast’s audit trail can be filtered using device information, together with staff/login, patient, event, IP address, and date range, to review recorded CureCast activity.
Is CureCast device management the same as MDM or remote wipe?
No. CureCast helps administrators manage CureCast access from device records and end active sessions. It does not replace a full mobile-device-management system, remote-wipe capability, or the practice’s broader physical-device security program.
Does deleting a device record remove its audit history?
No. Deleting a device record removes it from the Devices screen, but recorded historical activity remains available in the Audit Trail for review.

See How CureCast Fits Your Practice
Discuss how CureCast fits into your clinical photo workflow, from capturing and organizing patient photos to securely managing them across your practice.
Prefer email? [email protected]