My log stays mine.
You are the custodian of your record. Nobody else has access by default. You give consent one person at a time, choose which data categories they see and for how long, and revoke it whenever you want.
Granting, limiting and revoking access, in 16 seconds. No sound.
Locked to you
Biometric login with your face or fingerprint, backed by multi-factor authentication. Your log opens for you and no one else.
You hold the keys
Consent is yours to give and to withdraw. Family, caregivers and social workers see your record only with your explicit permission.
Yours to move
Data portability by default. Export your record whenever you want in HL7 FHIR, the interoperability standard health systems already use.
Every view is logged
A full audit trail: who accessed your record, what they looked at and when. Sync history logs every import and export too.
Never sold
Your health data is never sold and never used for advertising. Sponsors and insurers get nothing unless you share it.
Yours to delete
Delete your whole log whenever you want. When you delete it, it is gone from our systems too.
We take security seriously.
HealthLog.si is being built to the standards that hospitals, regulators and auditors expect of anyone holding health information. Each audit and certification will be listed here as it is completed.
Privacy, Security and Breach Notification Rules, with Business Associate Agreements (BAAs) for providers who send records.
Independent audit of our security, availability and confidentiality controls.
The healthcare industry's security certification framework.
The federal rule that covers personal health record apps.
Interoperability and patient access under the 21st Century Cures Act.
Extra protection for substance use disorder treatment records.
Including California's CCPA and Washington's My Health My Data Act.
AES-256 at rest, TLS in transit, multi-factor authentication, role-based access and regular penetration testing.