Updated September 14, 2026
This page describes how Primary Care Live protects health information, in enough detail for a practice's privacy officer or IT advisor to evaluate it. It is written to be accurate rather than reassuring; where something is planned rather than in place, it says so.
Each medical practice using Primary Care Live is a covered entity. Belmont Labs, Inc. is the practice's business associate and signs a Business Associate Agreement (BAA) with every practice before the practice sees patients. Belmont Labs uses protected health information (PHI) only to operate the Service for the practice and never for its own purposes. Vendors that could touch PHI are Belmont Labs' subcontractors and sign BAAs with Belmont Labs (see section 9). The practice's Notice of Privacy Practices, shown to patients in the app, governs how the practice itself uses PHI.
All servers are in the United States. The application, database, and file storage run on a dedicated virtual server at DigitalOcean's Atlanta region, on encrypted volumes. Nothing is stored on Belmont Labs staff laptops. Backups are encrypted with a key held only by Belmont Labs before they leave the server. There is no offshore processing or support.
The Service records who did what, when, and from where: sign-ins, chart views, report views and exports, attachment opens, consent signatures, note and reading entries, payment events, and staff changes. Audit records cannot be edited by the app. Medical-record tables are append-only: blood-pressure readings and clinical notes cannot be deleted or altered after they are written; corrections are recorded as new entries. Audit data is retained for at least six years to meet HIPAA documentation requirements.
Consents are signed in the app by typing one's full legal name, after scrolling the full document and affirming two statements. The Service records the document version and hash, the typed name and the name on record, the time, the device model and app version, and the IP address, and emails the patient a confirmation. This satisfies the federal E-SIGN Act and Texas's Uniform Electronic Transactions Act. A patient can revoke a consent in the app; the revocation is recorded with the same detail.
Push notifications, emails, and text messages never contain health details. A notification says "You have a new message" or "Video visit tomorrow at 2:30 PM"; the content is only in the app after sign-in. Patients can choose whether previews show on their lock screen. Login codes and receipts go by email through MailerSend from primarycarelive.com with SPF, DKIM, and DMARC configured.
Card numbers are entered by the patient directly into Stripe's encrypted fields and never pass through Belmont Labs' or the practice's systems; we store only a token, brand, and last four digits. Stripe is PCI DSS Level 1 certified. The practice receives payouts to its own Stripe account; Belmont Labs cannot move a practice's money. Financing is handled by Affirm under Affirm's own security program.
| Vendor | Role | PHI exposure | Agreement |
|---|---|---|---|
| DigitalOcean | Hosting (servers, database, file storage, backups) | Encrypted PHI at rest | BAA |
| Stripe | Payments and payouts | Names and payment details only; no health data | Stripe terms; not a business associate |
| Affirm | Financing | Names and purchase amount only | Affirm terms; not a business associate |
| MailerSend | Login codes, reminders, receipts | Email address and non-clinical message text | DPA; no PHI sent |
| Apple | Push notifications | Device token and non-clinical alert text | Apple developer terms; no PHI sent |
| DoseSpot / Surescripts | E-prescribing (when a practice enables it) | Prescriptions and demographics | BAA |
| Claim.MD | Claims clearinghouse (when a practice enables it) | Claims data | Practice's own account and BAA |
The database is backed up nightly, encrypted, and retained for 30 days; encryption keys are held separately from the backups. Server updates are applied automatically for security patches. Uptime for the current single-practice deployment is monitored by Belmont Labs; a second server and automated failover are planned before the Service is offered to additional practices.
Belmont Labs will notify an affected practice of any security incident involving its PHI without unreasonable delay and no later than the timeframe in the BAA, with what is known about the information involved, the people affected, and the steps taken. The practice, as covered entity, makes the notifications to patients, HHS, and media that the HIPAA Breach Notification Rule requires, and Belmont Labs assists. Suspected security problems can be reported to security@primarycarelive.com; we acknowledge reports within two business days and do not pursue researchers who report in good faith.
Patients can see their readings, visits, and messages in the app at any time; request a copy of their record or corrections from their practice; see and end signed-in devices; turn notifications and previews on or off; remove cards; change pharmacy and insurance; and ask their practice or Belmont Labs to delete their login. Medical records themselves are retained by the practice as Texas law requires.
In the interest of accuracy: Belmont Labs has not yet completed a third-party SOC 2 or HITRUST assessment; the current deployment runs on a single server without automated failover; and the legal documents (Terms, Privacy Policy, in-app consents) are under review by healthcare counsel. Each will be updated here when complete.
Privacy officers and IT advisors can reach us at security@primarycarelive.com. We'll share the BAA template, the current system diagram, and the subprocessor list on request.