Terms of service and platform governance.
These terms govern your use of the Cura longitudinal health memory platform, setting out patient identity governance, proxy contributor boundaries, clinical liability, and data protection safeguards.
Emergency Medical Disclaimer: Not for Acute Crises
Cura is strictly an asynchronous, between-visit health memory and tracking platform. Cura is NOT an emergency response system, real-time monitoring service, or diagnostic device. If you are experiencing a medical emergency, acute chest pain, severe shortness of breath, sudden weakness, or any life-threatening condition, immediately call 911 (US), 999 (UK), 112 (EU), or your local emergency services.
Platform Purpose & Between-Visit Scope
Cura is designed to capture, organize, and synthesize asynchronous between-visit health observations reported by patients and authorized carers. The platform provides structured longitudinal timelines and pre-visit synthesis briefs to facilitate informed consultations between patients and their licensed healthcare professionals.
Cura does not provide live medical consultations, triage dispatch, or emergency medical monitoring. All information processed by Cura is intended exclusively for retrospective clinical review during scheduled healthcare encounters.
Clinician-in-the-Loop Governance & Medical Responsibility
Cura does not practice medicine, formulate diagnoses, prescribe medications, or replace the clinical judgment of qualified practitioners. All clinical decisions, treatment plans, prescriptions, and symptom interpretations remain the sole professional responsibility of the treating clinician.
- Zero Autonomous Prescribing: The software cannot alter, adjust, or initiate medication dosages autonomously.
- Human-Verified Summaries: Pre-visit briefs and deterioration alerts serve as memory aids and require clinician verification prior to clinical action.
- Medical Duty of Care: Clinical liability and care plan oversight remain strictly between the attending physician and the patient.
User Roles & Access Architecture
Cura enforces a strict tripartite role hierarchy with bounded cryptographic scopes:
The primary account holders and subjects of care. Patients verify transcripts, view complete health timelines, and hold exclusive authority to grant or revoke carer proxy access.
Delegated observational contributors authorized by patient consent or clinical assignment. Carers submit symptom logs on the patient’s behalf with mandatory author provenance.
Attending physicians, GPs, and care team members bound by professional licensing and ethics. Clinicians establish clinical tenancy and maintain medical duty of care.
Patient Profile Creation, Clinical Tenancy & Proxy Authorization Safeguards
4.1 Lawful Pathways for Establishing Patient Profiles
To protect patient health sovereignty, prevent identity fabrication, and ensure clinical oversight, every patient medical profile within Cura must be established through one of two authorized pathways:
4.2 Strict Prohibition on Unilateral Carer Profile Creation
Carers, family members, guardians, and third parties are strictly prohibited from independently creating, registering, or self-provisioning a new patient profile on their own without prior clinical establishment or direct patient initiation. This rule is rooted in non-negotiable legal and clinical safeguards:
- GDPR Article 9 (Special Category Health Data): Processing of sensitive medical data is prohibited under European Union law unless explicit, freely given consent is provided directly by the data subject (the patient) or an officially certified legal power of attorney. Third parties cannot lawfully consent to the creation of a digital medical dossier on behalf of another competent adult.
- HIPAA 45 CFR § 164.502(g) (Personal Representatives): Under federal health privacy standards, proxy authority requires verified legal standing (such as court-appointed guardianship or a healthcare power of attorney). Unverified self-service creation of patient profiles by third parties violates privacy regulations and invites unauthorized medical profiling.
- Clinical Duty of Care & Malpractice Prevention: Cura generates pre-visit synthesis briefs and early-warning deterioration alerts. If third parties could create unattached "orphan" patient records without an accountable attending physician, critical deterioration alerts would go unmonitored, creating lethal clinical risk and severe legal liability.
- Anti-Coercion & Anti-Surveillance Safeguard: Restricting profile creation ensures vulnerable individuals, elderly family members, or domestic partners cannot be subjected to unauthorized surveillance, coercive digital tracking, or falsified proxy health histories without their explicit awareness and consent.
4.3 Lawful Carer Proxy Delegation & Consent Hard Gate
A carer may only be linked to a patient profile through: (1) an invitation initiated by the registered patient via their secure account settings, or (2) formal care team assignment by the attending clinician with the patient’s documented approval. Before any proxy logging occurs, the patient must execute the Carer Proxy Logging Consent gate (consent_type = "carer_proxy_logging"), establishing an active, time-bounded CarerPatientRelationship.
4.4 Immutable Provenance & Unalienable Patient Revocation Rights
Every health observation entered by a carer is permanently marked with is_carer_entry = true and bound to the carer’s authenticated author ID. Carers can never overwrite or disguise entries as direct patient statements. In accordance with GDPR Article 7(3), the patient retains the absolute, unalienable right to view all proxy submissions and unilaterally revoke carer proxy access at any time with immediate effect. Carers cannot modify medication regimens, dismiss alerts, or delete historical records.
Verbatim Source-Grounded AI Extraction Warranty
Cura enforces strict Pydantic v2 JSON schemas and verbatim string substring grounding validators on all AI model pipelines. Every extracted symptom, vital sign, or medication event is strictly verified against the raw patient or carer text to prevent unauthorized inference.
The system guarantees zero hallucination: AI models are prohibited from diagnosing conditions, guessing unmentioned symptoms, or speculating on prognosis. All extracted entities link directly to verbatim character offsets in the verified source text.
Protected Health Information (PHI) Security & Cryptographic Isolation
All Protected Health Information is encrypted at rest using AES-256-GCM envelope encryption and in transit via TLS 1.3 with forward secrecy. Medication names and search targets are indexed exclusively via salted HMAC-SHA256 blind indexing to ensure zero searchable plaintext in database indexes.
Multi-tenant isolation is enforced at the database layer via PostgreSQL Row-Level Security (RLS) operating in fail-closed mode. Patient data is strictly hosted within European Union data centers, is never used to train public foundation models, and is never sold or shared with commercial advertising brokers.
Patient Data Rights & Statutory Archive Retention (GDPR / AVG / WGBO)
Patients have the unalienable right under GDPR Articles 15–20 to access, export, rectify, and request erasure of their self-reported health narratives. Account exports are provided in open, structured formats.
Where health records form an integrated part of formal medical consultations, requests for deletion are balanced against mandatory statutory medical archive retention obligations (such as the 20-year retention rule under the Dutch Medical Treatment Contracts Act / WGBO). Non-clinical account information is erased upon request.
Constitutional Platform Boundaries & Prohibitions
Users, carers, and integrated healthcare systems agree to the following absolute boundaries:
- No Live Consultation Recording: Cura must never be used to ambiently record, scribe, or listen to live doctor-patient visits inside consultation rooms. Cura is strictly a between-visit asynchronous memory platform.
- No Billing or Claims Manipulation: The platform does not generate billing codes (ICD/CPT) or invoice calculation logic and must not be used for financial reimbursement disputes or commercial claims generation.
- No Unlawful Proxy Logging: Submitting proxy entries without documented patient consent or legal authority is strictly prohibited and subject to immediate account termination.
Legal & Governance Questions
Clear answers regarding patient identity, carer proxy boundaries, and data protection rules.