Security and HIPAA

Updated September 14, 2026

This page describes how Primary Care Live protects health information, in enough detail for a practice's privacy officer or IT advisor to evaluate it. It is written to be accurate rather than reassuring; where something is planned rather than in place, it says so.

1. Roles under HIPAA

Each medical practice using Primary Care Live is a covered entity. Belmont Labs, Inc. is the practice's business associate and signs a Business Associate Agreement (BAA) with every practice before the practice sees patients. Belmont Labs uses protected health information (PHI) only to operate the Service for the practice and never for its own purposes. Vendors that could touch PHI are Belmont Labs' subcontractors and sign BAAs with Belmont Labs (see section 9). The practice's Notice of Privacy Practices, shown to patients in the app, governs how the practice itself uses PHI.

2. Where data lives

All servers are in the United States. The application, database, and file storage run on a dedicated virtual server at DigitalOcean's Atlanta region, on encrypted volumes. Nothing is stored on Belmont Labs staff laptops. Backups are encrypted with a key held only by Belmont Labs before they leave the server. There is no offshore processing or support.

3. Encryption

4. Access control

5. Audit trail

The Service records who did what, when, and from where: sign-ins, chart views, report views and exports, attachment opens, consent signatures, note and reading entries, payment events, and staff changes. Audit records cannot be edited by the app. Medical-record tables are append-only: blood-pressure readings and clinical notes cannot be deleted or altered after they are written; corrections are recorded as new entries. Audit data is retained for at least six years to meet HIPAA documentation requirements.

6. Electronic signatures and consents

Consents are signed in the app by typing one's full legal name, after scrolling the full document and affirming two statements. The Service records the document version and hash, the typed name and the name on record, the time, the device model and app version, and the IP address, and emails the patient a confirmation. This satisfies the federal E-SIGN Act and Texas's Uniform Electronic Transactions Act. A patient can revoke a consent in the app; the revocation is recorded with the same detail.

7. Notifications, email, and text messages

Push notifications, emails, and text messages never contain health details. A notification says "You have a new message" or "Video visit tomorrow at 2:30 PM"; the content is only in the app after sign-in. Patients can choose whether previews show on their lock screen. Login codes and receipts go by email through MailerSend from primarycarelive.com with SPF, DKIM, and DMARC configured.

8. Payments

Card numbers are entered by the patient directly into Stripe's encrypted fields and never pass through Belmont Labs' or the practice's systems; we store only a token, brand, and last four digits. Stripe is PCI DSS Level 1 certified. The practice receives payouts to its own Stripe account; Belmont Labs cannot move a practice's money. Financing is handled by Affirm under Affirm's own security program.

9. Subcontractors (business associates of Belmont Labs)

VendorRolePHI exposureAgreement
DigitalOceanHosting (servers, database, file storage, backups)Encrypted PHI at restBAA
StripePayments and payoutsNames and payment details only; no health dataStripe terms; not a business associate
AffirmFinancingNames and purchase amount onlyAffirm terms; not a business associate
MailerSendLogin codes, reminders, receiptsEmail address and non-clinical message textDPA; no PHI sent
ApplePush notificationsDevice token and non-clinical alert textApple developer terms; no PHI sent
DoseSpot / SurescriptsE-prescribing (when a practice enables it)Prescriptions and demographicsBAA
Claim.MDClaims clearinghouse (when a practice enables it)Claims dataPractice's own account and BAA

10. Availability and backups

The database is backed up nightly, encrypted, and retained for 30 days; encryption keys are held separately from the backups. Server updates are applied automatically for security patches. Uptime for the current single-practice deployment is monitored by Belmont Labs; a second server and automated failover are planned before the Service is offered to additional practices.

11. Incident response and breach notification

Belmont Labs will notify an affected practice of any security incident involving its PHI without unreasonable delay and no later than the timeframe in the BAA, with what is known about the information involved, the people affected, and the steps taken. The practice, as covered entity, makes the notifications to patients, HHS, and media that the HIPAA Breach Notification Rule requires, and Belmont Labs assists. Suspected security problems can be reported to security@primarycarelive.com; we acknowledge reports within two business days and do not pursue researchers who report in good faith.

12. Patients' rights

Patients can see their readings, visits, and messages in the app at any time; request a copy of their record or corrections from their practice; see and end signed-in devices; turn notifications and previews on or off; remove cards; change pharmacy and insurance; and ask their practice or Belmont Labs to delete their login. Medical records themselves are retained by the practice as Texas law requires.

13. What is not yet in place

In the interest of accuracy: Belmont Labs has not yet completed a third-party SOC 2 or HITRUST assessment; the current deployment runs on a single server without automated failover; and the legal documents (Terms, Privacy Policy, in-app consents) are under review by healthcare counsel. Each will be updated here when complete.

14. Questions

Privacy officers and IT advisors can reach us at security@primarycarelive.com. We'll share the BAA template, the current system diagram, and the subprocessor list on request.