Patient photos encrypted
at rest and in transit.
Clinical photos and patient records are encrypted with AES-256 at rest and TLS 1.3 in transit. Verified by the CureCast technical team
Encryption for Clinical Photos and Patient Records
Reviewed by the CureCast team · 31st August 2026
Patient records and clinical photos in CureCast are encrypted with AES-256 at rest and TLS in transit, with TLS 1.3 preferred and TLS 1.2 supported as a fallback. This applies to data stored in CureCast and to data moving between a device and CureCast’s servers.
Encryption At Two Different Stages
Encryption protects data in two different states: while it’s sitting in storage, and while it’s moving across the network. CureCast encrypts both.
Encryption at Rest
Clinical photos, patient records, and other data stored in CureCast are encrypted using AES-256, a widely used encryption standard. This applies to data as it's stored, not just while it's being accessed.
Encryption in Transit
Data moving between a device and CureCast's servers is encrypted using TLS. CureCast's TLS configuration prefers TLS 1.3, the current version of the protocol, with TLS 1.2 supported as a fallback for compatibility. Older, deprecated versions (TLS 1.0, TLS 1.1, SSL 3.0) are disabled.
The TLS 1.3 configuration uses TLS_AES_256_GCM_SHA384 with X25519/ECDHE key exchange, which supports forward secrecy. HTTP traffic is redirected to HTTPS, and the certificate is issued by Let’s Encrypt.
This encryption configuration has been verified through an independent TLS audit of CureCast’s infrastructure.
Access Control, Audit Trail, and Session Timeout
Encryption protects data itself. It works alongside other CureCast controls that manage who can reach that data and what happens while they’re using it.
- Staff access controls determine who can access patient records and photos.
- The audit trail records key activity associated across that access.
- Session timeout ends inactive sessions after a set period.
Encryption doesn’t replace any of these. It’s the layer that protects data itself, regardless of who is or isn’t supposed to have access at a given moment.
Built for HIPAA-Compliant Workflows
Strong encryption is one part of a HIPAA-compliant workflow, not the whole of it. CureCast’s use of AES-256 at rest and TLS in transit is designed to support the technical safeguards a HIPAA-compliant workflow depends on.
CureCast is built to support HIPAA-compliant workflows. Each practice remains responsible for its own compliance obligations and risk assessment.
Frequently asked Questions
How is patient data encrypted at rest?
Patient records and clinical photos stored in CureCast are encrypted using AES-256.
How is patient data encrypted in transit?
Data moving between a device and CureCast’s servers is encrypted using TLS, with TLS 1.3 preferred and TLS 1.2 supported as a fallback. Older, deprecated protocol versions are disabled.
Has CureCast’s encryption been independently verified?
Yes. CureCast’s TLS configuration has been confirmed through an independent audit of its infrastructure.
Does CureCast use HTTPS?
Yes. HTTP traffic is redirected to HTTPS, and the certificate is issued by Let’s Encrypt.
Does encryption alone make CureCast HIPAA compliant?
No. Encryption is one part of a HIPAA-compliant workflow. Each practice remains responsible for its own broader compliance obligations and risk assessment.

See How CureCast Fits Your Practice
Discuss how CureCast fits into your clinical photo workflow, from capturing and organizing patient photos to securely managing them across your practice.
Prefer email? [email protected]