Security & Trust
Built for regulated care from the first line of code.
Patient information is the most sensitive thing a practice holds. These protections come with every plan. We never charge extra for safety.
How we protect information
Protection built into the platform itself.
Two-step sign-in
Required for every team account, with authenticator apps and passkeys. Sessions sign out automatically.
Minimum necessary access
Each role sees only what its job needs, and the rule is enforced in the database, not just hidden on screen.
Each practice kept separate
One practice can never see another's patients, orders or messages. Partners see only the practices they are connected to.
Encryption
Information is encrypted in transit and at rest. Card details go straight to the payment processor and never touch our servers.
Full audit trail
Every change and every view of sensitive records is logged with who, what and when.
Records stay intact
Signed records are never deleted or overwritten. Corrections are added alongside the original, with a reason.
License checks
A case only reaches a provider with a verified license in the patient's state. Expiring credentials trigger a warning.
Signature integrity
Each consent stores the exact text that was signed, who signed it and when, so it can be shown later.
Practice-approved support
Our own team can open patient records only when the practice approves, for a set time. Access ends on its own.
Who can see what
The right information for each role, and no more.
| Role | Can see | Cannot see |
|---|---|---|
| Practice owner and staff | Their own patients, orders, messages and payouts | Any other practice's information |
| Provider | The chart, intake and history for cases they are licensed to take | Patients in states where they hold no license |
| Pharmacist | The prescription, date of birth, allergies and shipping details | Intake answers and the full chart |
| Shipping staff | The delivery address and the item to ship | Directions, allergies and anything clinical |
| Laboratory | The request it needs to fulfil | The patient's chart |
| Bare Health support | Nothing by default. Records open only with the practice's approval, for a set time | Patient records without an approved, logged request |
HIPAA and our role
Your practice owns its patient information.
Under HIPAA, Bare Health acts as a business associate to each practice. We handle patient information only on the practice's behalf and under a written agreement.
- Before any patient information is stored, we sign a business associate agreement with the practice.
- Our vendors that handle patient information sign business associate agreements with us.
- An independent security review is completed before we open to real patients.
- We never sell personal information or use health information for advertising.
Read our Privacy Policy and Terms of Use.

Report a security concern. Email it@barehealthtechnologies.com. Please do not include patient information in your message.
Read the Privacy Policy