Safety & security
Measured controls, explicit gaps.
Substrate MD is designed for HIPAA-regulated clinical workflows. That is a design and operating posture—not a blanket certification claim.
Identity and authority
First-party accounts, mandatory MFA, passkeys, short-lived sessions, capability-based server checks and stricter credential-reset authority protect the clinical surface. Hiding a button is never treated as authorisation.
Data and evidence
Clinic databases use SQLCipher and are separated by file. Original artifacts are retained only on confirmed encrypted storage. Values retain provenance, source locators and lineage. Parsers refuse ambiguity instead of guessing.
Audit and emergency use
Audit and AI receipts are hash chained and tamper-evident. They are not described as tamper-proof. Emergency access is bounded, attributable, notified, independently reviewed and never expands the professional capabilities of the person opening it.
Launch boundary
Identified patient data remains disabled until agreements, backup restore, independent key custody, notification delivery, MFA posture, data-source validation, retention and an end-to-end rehearsal have been proven. Current validation blockers are shown in Administration rather than hidden.
Report a concern
The public contact route records a security-contact request without asking for patient content. Do not place PHI, credentials or exploit material in a public request.