Trust

Where the boundaries are

Monitoring platforms accumulate the most sensitive data in health care and then describe their posture in adjectives. Here are the specifics, including the places where we are deliberately narrower than a competitor might claim.

Protected health information

Encrypted in transit and at rest. Per-tenant encryption keys. Access is role-scoped and logged at the record level. A business associate agreement is executed before any production data moves, without exception and without negotiation over whether it is necessary.

Tenancy

Isolation is structural. A cross-tenant query is not blocked by policy, it is not expressible. Sponsored programs are separate tenants from the clinical programs that generate data, and the boundary between them is a consented export, not a shared view.

Consent

Consent is a field-level, versioned, revocable object scoped per data category per recipient. Revocation propagates to downstream exports. Behavioral health risk items, and any category we classify as high sensitivity, are excluded from sponsor flows by default and cannot be enabled by configuration alone. That requires a named human decision and a record of it.

Audit

Immutable event log covering enrollment, orders, device binding, every observation with its provenance, every threshold firing, every disposition, every export, and every permission change. A per-patient per-month defense packet is generated on demand rather than reconstructed under pressure.

Regulatory boundary

Gathermed is monitoring infrastructure. Where a specific measurement function makes the software a medical device under its intended use, that function is developed under design controls and documented as such, and where a customer builds a regulated product on our API, the customer is the manufacturer of that product and we are a supplier with the traceability that role requires. We put this in writing rather than leaving it ambiguous, because ambiguity here resolves badly for everyone.

What we do not do

We do not submit claims. We do not take a percentage of collections. We do not hold HCPCS codes. We do not sell identified patient data under any arrangement. We do not accept a sponsor arrangement in which our revenue depends on enrollment volume in a program the sponsor funds and a provider bills.

On certifications

Ask us directly for the current status of any specific attestation, its audit period, and the report itself under NDA. We would rather answer a pointed question than display a badge, and a vendor who leads with badges rather than reports is worth a second look.