Trust

Where the boundaries are

Monitoring platforms accumulate the most sensitive data in health care and then describe their posture in adjectives. Here are the specifics, including the places where we are deliberately narrower than a competitor might claim.

Protected health information

Encrypted in transit and at rest. Per-tenant encryption keys. Access is role-scoped and logged at the record level. A business associate agreement is executed before any production data moves, without exception and without negotiation over whether it is necessary.

Tenancy

Isolation is structural. A cross-tenant query is not blocked by policy, it is not expressible. Sponsored programs are separate tenants from the clinical programs that generate data, and the boundary between them is a consented export, not a shared view.

Consent

Consent is a field-level, versioned, revocable object scoped per data category per recipient. Revocation propagates to downstream exports. Behavioral health risk items, and any category we classify as high sensitivity, are excluded from sponsor flows by default and cannot be enabled by configuration alone. That requires a named human decision and a record of it.

Audit

Append-only event log covering enrollment, orders, device binding, every observation with its provenance, every threshold firing, every disposition, every export, and every permission change. A per-patient per-month defense packet is generated on demand rather than reconstructed under pressure.

Regulatory boundary

Gathermed is monitoring infrastructure. Where a specific measurement function makes the software a medical device under its intended use, that function is developed under design controls and documented as such, and where a customer builds a regulated product on our API, the customer is the manufacturer of that product and we are a supplier with the traceability that role requires. We put this in writing rather than leaving it ambiguous, because ambiguity here resolves badly for everyone.

What we do not do

We do not submit claims. We do not take a percentage of collections. We do not hold HCPCS codes. We do not sell identified patient data under any arrangement. We do not accept a sponsor arrangement in which our revenue depends on enrollment volume in a program the sponsor funds and a provider bills.

This website

We do measure this site, and it is worth saying exactly how, because a company that argues about consent for a living should be able to describe its own marketing page. No third party is involved: there is no advertising pixel, no session recorder, no data broker, and no person-level de-anonymization vendor. The page reports to this origin’s own endpoint, the identifier is a cookie set HttpOnly so no script can read it and SameSite=Lax so it never leaves this site, your IP address is hashed on arrival and never stored, and a browser sending Global Privacy Control is not recorded at all. Where we can tell which organization a visit came from, it is because the network’s public reverse-DNS record says so — the same fact any server you connect to can see. None of this touches patient data or the platform; it is a marketing site, and it is measured like one.

On certifications

Ask us directly for the current status of any specific attestation, its audit period, and the report itself under NDA. We would rather answer a pointed question than display a badge, and a vendor who leads with badges rather than reports is worth a second look.