HIPAA Compliance Statement

Effective Date: October 7, 2025

Important Notice: Local Data Isolation

Flare to Care is configured for local-only execution. Your data is stored directly on your computer's local drive and is not sent to any cloud database.

Local Isolation: Your database is stored locally in `db.json` on your device. Your medical records, symptoms, diet logs, and medications never leave your local environment.

Data Access: Since the database is stored locally, only you have access to it. We treat all patient data with the utmost confidentiality and never share or sell information.

1. Our Commitment to Your Privacy

At Flare to Care, we are deeply committed to protecting your health information. As we grow and develop this platform, achieving full HIPAA compliance is a top priority. We are transparent about our current status and the steps we're taking to ensure your data is secure.

2. Current Security Measures

While running in local mode, we emphasize these security practices:

  • Local-First Storage: Data is kept offline in your workspace directory
  • Encryption at Rest: We recommend securing your drive using BitLocker or standard OS disk encryption
  • No Network Transmission: Zero health data is sent over the Internet, eliminating transit risks
  • Access Controls: Access is limited to anyone with access to your local machine

3. Protected Health Information (PHI)

We collect and store the following PHI to provide our services:

  • Personal identifiers (name, email, date of birth)
  • Symptom logs and health status
  • Dietary intake and food tolerances
  • Medication schedules and infusion dates
  • Laboratory test results (CRP, fecal calprotectin, etc.)
  • Medical reports generated for healthcare providers

4. Your Rights Under HIPAA Principles

Even as we work toward full compliance, we honor HIPAA's patient rights:

  • Right to Access: View all your health information at any time
  • Right to Amend: Correct inaccurate information
  • Right to Delete: Request deletion of your account and all data
  • Right to Export: Download your complete health record
  • Right to Restrict: Control how your information is used
  • Right to Confidentiality: Expect your data to remain private

5. Limitations & Disclosures

We only share your PHI in these situations:

  • When you generate a medical report to share with your doctor (your choice)
  • If required by law or court order
  • To prevent serious harm to you or others (emergency situations only)

We NEVER sell your health information for any reason.

6. Administrative Access

Platform administrators (hitanmaykirani@gmail.com and atul.kuchi@gmail.com) have technical access to the database for maintenance, troubleshooting, and platform improvements. We maintain strict internal policies against unauthorized viewing of patient data and only access health information when necessary for technical support or at a user's explicit request.

7. Path to Full HIPAA Compliance

We are actively working toward full HIPAA compliance by:

  • Upgrading to HIPAA-compliant hosting infrastructure with BAAs
  • Implementing comprehensive audit logging
  • Conducting regular security assessments
  • Developing formal policies and procedures
  • Training staff on HIPAA requirements
  • Establishing incident response protocols

8. Breach Notification

In the unlikely event of a data breach affecting your health information, we will notify you within 60 days as required by HIPAA breach notification rules. Notification will include what happened, what information was involved, and steps you can take to protect yourself.

9. Contact & Complaints

For questions about our privacy practices or to file a complaint:

Privacy Officer: hitanmaykirani@gmail.com
Support: atul.kuchi@gmail.com
Location: Cumming, Georgia

You also have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights if you believe your privacy rights have been violated.

10. Updates to This Statement

We will update this HIPAA Compliance Statement as we implement new security measures and achieve full compliance. We will notify users of significant changes via email and platform notifications.

By using Flare to Care, you acknowledge that you have read and understood this HIPAA Compliance Statement and the current limitations of the platform. We appreciate your trust as we build a secure, compliant platform for the IBD community.