Skip to main content

Security & trust

Built for clinical environments.

PrefCA keeps surgical preference data accurate and access tightly scoped. Here's how we approach security, privacy, and HIPAA-aware handling — described as practices, not certifications. For specifics on a Business Associate Agreement or your facility's requirements, reach out anytime.

  • HIPAA-aware by design

    Preference cards describe surgical setup — instruments, supplies, positioning — not patients. PrefCA is designed so cards don't require protected health information, keeping PHI out of the workflow.

  • Scoped, role-based access

    Surgeons own their cards and share them deliberately. Facilities and staff see only what they've been granted, scoped within organization boundaries — no cross-tenant visibility.

  • Encrypted in transit and at rest

    Traffic is served over TLS, and data is stored on managed, encrypted infrastructure with isolated tenancy per organization.

  • Auditable access trail

    Grants, adoptions, and version changes are recorded, so administrators can review who has access to what — and when it changed.

  • Data handling you control

    Photos and video are intended for room and tray context, not patients, and are served only to users with access to that card. You decide what goes on a card and who adopts it.

  • PHI safety boundaries

    Because cards aren't patient records, users should not enter patient identifiers into card fields, notes, or uploads. The product is shaped to make the no-PHI path the natural one.

Frequently asked questions

Who owns the data in a preference card?
The surgeon owns their official preference cards. Facilities adopt a card and work from the version they pinned; they don't take ownership of the surgeon's card. Each organization's data is scoped to that organization.
Does PrefCA store protected health information (PHI)?
Preference cards describe surgical setup — instruments, supplies, positioning, photos of the room and tray — not patients. PrefCA is designed so cards don't require patient identifiers. Users should not enter PHI into card fields, notes, or uploads.
How does facility adoption and access work?
A surgeon shares a card with a facility, which adopts a specific version. Facilities and their staff see only what they've been granted, within organization boundaries. Access can be granted and revoked, and changes are recorded.
Are photos and video safe to upload?
Photos and short video are intended for setup, instruments, and room context — not patients. They're stored on managed, access-controlled storage and served only to users with access to that card. Avoid capturing identifiable patients in any upload.
How is staff training and competency handled?
Each card can generate a competency quiz from its own content. Facilities assign it to staff and see pass rates against the exact version they adopted. Training results are scoped to the facility and its staff.
What does the AI review do with our content?
AI features help draft and review card content from the inputs you provide. They operate on card content (setup, instruments), and you stay in control — every suggestion is editable and nothing changes without your review.
What is PrefCA's HIPAA posture?
PrefCA is built with HIPAA-aware practices — scoped access, encryption in transit and at rest, and auditable access trails — and is designed to keep PHI out of preference cards. We describe these as practices rather than a formal certification; for specifics on a Business Associate Agreement or your facility's requirements, contact us.
How do we get help or report a concern?
Reach our team at support@prefca.com for product questions and security@prefca.com for security concerns. We'll route compliance and legal questions to the right people.

Ready when you are

Try PrefCA free for 30 days.

No credit card. Cancel anytime. Bring your first card in 10 minutes.