TakeCareSign in

Security & privacy

How the Clinician Portal protects client information

Clients share their health information with your practice because they trust you with it. Here’s how TakeCare protects it, and what stays in clients’ hands.

Clients stay in control

  • A practice sees a client’s information only after the client connects with the practice’s code in the TakeCare app.
  • Clients choose exactly which categories to share (such as symptoms, medications, meals or sleep) and can change them at any time.
  • When a client stops sharing, the practice’s access ends right away.

Every clinician signs in with two-step verification

  • Two-step verification is required for every account: a password plus a code from an authenticator app such as Google Authenticator or Microsoft Authenticator.
  • Passwords must be at least 12 characters. Clinicians can also sign in with Google or Apple.
  • The portal signs out automatically after 15 minutes of inactivity, with a warning first.

Encrypted, with access enforced on the server

  • Information is encrypted in transit (HTTPS) and at rest on Google Cloud.
  • Who can see what is enforced by server-side security rules, not just by the screens: a clinician can only read the clients and categories shared with their practice.
  • TakeCare doesn’t sell personal information.

Practice teams

  • Each team member has their own account and two-step verification. Logins are never shared.
  • The practice admin decides who is on the team and can remove someone at once, which ends their access.
  • In practices with more than one person, an access log shows who opened which client’s record, and when.
  • Notes and care-management records the practice keeps in the portal are visible only to the practice.

Client invitations

  • Invitations are written in the portal and sent from the clinician’s own email. TakeCare never sees or stores the clients’ email addresses.

Payments

  • Subscriptions are processed by Stripe through RevenueCat. Card details go straight to Stripe; TakeCare never sees or stores them.

Research is opt-in and de-identified

  • Clients can choose to join TakeCare’s research pool. Their data is copied without names or contact details.
  • Researchers are approved one at a time, and groups too small to stay anonymous are hidden.

Your part

  • Keep your authenticator on a device only you use, and sign out on shared computers.
  • Give each team member their own account instead of sharing a login.
  • Remove people from your practice when they leave.

Questions about security, privacy or compliance?

For questions about HIPAA, business associate agreements or a security review, email privacy@takecarehealth.org. For help with your account, email support@takecarehealth.org. Read the full privacy policy.

TakeCare is a wellness tool, not a medical device. It shows what clients log and sync; clinicians make the clinical decisions.