MeloCare

Security

Two lists: what is true of the product today, and what is not built yet. We would rather under-promise here than be caught describing controls we have not shipped.

What is true today

  • Traffic to MeloCare is served over HTTPS.
  • Patient-entered health information — condition, medications, supplements, notes, conversations — is held in the browser on the patient’s own device. It is not written to a MeloCare database. When a patient asks MeloCare a question, or photographs a visit summary or a medication label, that question and their saved care profile pass through our servers to our AI provider so an answer can be produced.
  • Church Edition care profiles also stay on the device they were typed into.
  • The only thing MeloCare stores on a server is the practice profile a clinic supplies: practice name, clinician names, disciplines, phone numbers, and after-hours instructions. It contains no patient information, and it is public by design because patients open it from a QR code without signing in.
  • Practice profiles can no longer be created or edited by the public. Changes are made by MeloCare until sign-in for offices ships.
  • Backup files are encrypted in the patient’s browser with a passphrase only they hold, and never pass through MeloCare.

What is not built yet

These are commitments for the clinic product, not descriptions of shipped controls. None of them should be relied on in procurement today.

  • Accounts and sign-in for office staff, with sessions and access removal.
  • Per-office isolation enforced by an authenticated account model.
  • Audit logging of administrative access to production data.
  • A written retention and deletion policy, a breach-notification procedure, workforce training records, and a named privacy contact.
  • Business associate agreements — ours with a clinic, and ours with every vendor underneath us that could touch protected health information, including the AI provider.

Until that list is finished, MeloCare is not sold to clinics as a HIPAA-ready service and no clinic should deploy it to patients on the strength of this page.

Guardrails in the product

MeloCare is instructed never to give a dose, never to call a combination safe or unsafe, and never to tell anyone to change treatment. MeloCare does not review a person’s specific combination of medications and supplements at all. Questions about interactions produce a printable list of what the person takes and the instruction to have a pharmacist review it.

A filter that checks every answer before a patient sees it is being built. Until it ships, these limits are instructions to the model, not an enforced control.

Reporting something

If you find a vulnerability or see an answer that crosses a line, tell us through the waitlist form and we will respond. We would rather hear it early.

This page describes how MeloCare operates. It is not legal advice, and it is reviewed as the product changes.