Idle sessions end.
Access stays protected.
CureCast automatically ends inactive sessions after 2 hours on desktop and 4 hours on iOS. Users return with Face ID or password sign-in.
Why this matters
- A workstation left open at the front desk.
- A tablet set down mid-consultation and forgotten.
- A browser tab left running overnight.
Every one of these is a session that stays authenticated, and visible, until something ends it. If a laptop is left open in a treatment room or a shared front-desk computer sits idle between patients, that session remains active until the inactivity timeout is reached.
CureCast’s inactivity timeout is one part of a practice’s broader security workflow. It doesn’t replace a clinic’s device screen-lock policy, staff offboarding process, lost-device procedure, or wider HIPAA risk assessment. It’s a backstop for the sessions that get left running, not a substitute for locking the device itself.
Desktop and iOS timeout periods
CureCast automatically ends inactive sessions after:
Desktop
Applies to browser sessions on any desktop or laptop computer.
iPhone and iPad
Applies to the CureCast app on iOS devices.
These periods apply to all CureCast users, including administrators.
The timeout period is set globally by CureCast and isn’t currently configurable per clinic.
What counts as inactive
For website sessions, inactivity is based on the absence of continued interaction with CureCast. Activity in another browser tab or a different application does not reset the CureCast timeout. If you’re actively using CureCast during a consultation, whether reviewing photos, entering notes, or navigating between patients, the session stays active and the timeout doesn’t trigger. It’s specifically about sessions left idle, not sessions in active use.
For iPhone and iPad sessions, inactivity is based on the same principle. Switching to another app, like checking a message or taking a call, does not reset the CureCast timeout. Active use during a consultation keeps the session running.
Activity in another browser tab or a different application doesn’t reset the CureCast timeout. If CureCast is open but idle while you work in another tab, the countdown continues, and the same warning prompt will still appear.
The “Are you still there?” warning
Five minutes before a session ends, CureCast shows a warning prompt: on desktop, this appears at 1 hour 55 minutes of inactivity; on iOS, at 3 hours 55 minutes. Responding to the prompt keeps the session going, so a session in the middle of use doesn’t need to restart.
If the prompt isn’t answered, the session ends at the full timeout mark, 2 hours on desktop or 4 hours on iPhone and iPad. The user must sign back in with their CureCast password to continue.
What happens when a session times out
The warning prompt appears 5 minutes before the timeout.
If there is no response, the session ends at the full timeout period.
The screen does not automatically clear or hide patient information when the timeout occurs.
The user must sign in again before continuing.
On iPhone and iPad, the app displays a white screen with the CureCast logo. If Face ID was previously enabled for CureCast, the user can sign in with Face ID. Otherwise, the user must enter their CureCast passcode.
Desktop users sign in again with their CureCast password.
Signing back in after timeout
When a session times out, the user must sign in again before continuing.
On iOS, the app displays a white screen with the CureCast logo. If Face ID was previously enabled for CureCast, the user can use Face ID instead of entering a password. If Face ID is unavailable or has not been enabled, the user must enter their CureCast password.
Desktop users sign in again with their CureCast password.
This is a full session end. The previous session has ended and must be re-established through sign-in.
What this timeout does not do
CureCast’s inactivity timeout ends the CureCast session. It does not:
Practices should keep their own separate policies for device passcodes, operating-system screen locks, encryption, personal devices, shared workstations, lost devices, and local photo storage.
Works alongside staff access control and the audit trail
Session timeout is one layer among several. Staff access controls determine what a person can access in the first place, and deactivating a staff account ends all of that person’s active sessions immediately. Session timeout is narrower: it ends one inactive session after a set period, without touching the rest of that person’s access.
Session timeout and automatic logoff safeguard
Security Rule lists automatic logoff as an addressable technical safeguard, meaning covered entities must implement a way to end an electronic session after a period of inactivity, without HIPAA and other market compliances specifying one required duration. CureCast’s inactivity timeout is designed to support that kind of safeguard as part of a practice’s broader session-security approach.
Built for HIPAA-compliant workflows
CureCast’s inactivity timeout can support a practice’s approach to unattended-session risk. It’s one part of a HIPAA-compliant workflow, not the whole of it.
CureCast is built to support HIPAA-compliant workflows, but a timeout feature alone doesn’t make a practice HIPAA compliant. Each practice remains responsible for its own security risk assessment, device policies, staff procedures, and compliance decisions.
Frequently asked Questions
Does CureCast automatically log out inactive users?
Yes. A warning prompt appears 5 minutes before the session ends. If there’s no response, the session ends and the user must sign in again.
How long before a desktop session times out?
2 hours of inactivity, with a warning prompt at 1 hour 55 minutes.
How long before an iOS session times out?
4 hours of inactivity, with a warning prompt at 3 hours 55 minutes.
Does the timeout apply to administrators?
Yes, to all CureCast users including administrators.
Does this satisfy HIPAA’s automatic logoff requirement?
HIPAA’s Security Rule lists automatic logoff as an addressable safeguard requiring a way to end a session after inactivity, without specifying an exact duration. CureCast’s timeout is designed to support that kind of safeguard, but whether it fully meets a specific practice’s requirements depends on that practice’s own risk assessment.
Will the timeout interrupt a live patient consultation?
No. The timeout is based on inactivity, not on how long the session has been open. As long as you’re actively using CureCast during the consultation, the session stays active.
Can I extend my session if I’m in the middle of something?
Yes. Responding to the “Are you still there?” warning prompt keeps the session active without needing to sign in again.
Can my clinic set its own timeout period?
No. The desktop and iOS timeout periods are set globally by CureCast and aren’t currently configurable per clinic.
Can I sign back in with Face ID instead of my password?
On iPhone and iPad, users can sign in with Face ID if it was previously enabled for CureCast. If Face ID is unavailable or has not been enabled, the user must enter their CureCast passcode. Desktop users sign in again with their CureCast password.

See How CureCast Fits Your Practice
Discuss how CureCast fits into your clinical photo workflow, from capturing and organizing patient photos to securely managing them across your practice.
Prefer email? [email protected]