Privacy & Security
Managing sensitive data requires navigating a strict and complex regulatory landscape. At CareEvolution®, we clear this operational friction by anchoring our entire infrastructure to the most rigorous federal compliance baselines. This foundational security gives researchers and builders the total confidence required to innovate, while ensuring patients retain complete privacy and control over their personal health journey.
Regulatory standards
NIST SP 800-53 Rev. 5
Our core system architecture maps directly to federal privacy and security controls. Compliance is continuously verified through independent assessments by a certified Third-Party Assessment Organization (3PAO).
HITRUST e1 Certification
The Orchestrate data engine and Discover ecosystem (including MyDataHelps™) hold active HITRUST e1 certifications, standardizing data protection controls across global health regulations.
HIPAA Compliance
We safeguard Protected Health Information (PHI) under the same strict security baselines required by enterprise EHR systems and major hospital networks.
FDA 21 CFR Part 11
Our platform enforces the necessary technical controls for electronic records, audit trails, and signatures, taking backend compliance friction out of digital clinical trials.
NIH Authorization to Operate (ATO)
Formally authorized by the National Institutes of Health to securely ingest and manage large-scale digital phenotypes for national research initiatives.
Digital Medicine Society (DiMe) Seal
MyDataHelps carries independent validation confirming the highest standards of evidence, usability, privacy, and safety.
Global Privacy
We uphold strict international privacy mandates, including GDPR and Data Privacy Framework (DPF) standards, to ensure compliant global operations.
CARIN Code of Conduct
We adhere to consumer-directed privacy principles to ensure absolute transparency and user control over personal health information.
Privacy policies
We maintain absolute transparency regarding how data is managed, shared, and protected across our ecosystem. Review our specific privacy policies to see how we safeguard data and keep individuals in control of their information:
Applies to study participants volunteering health data and individuals managing records through our consumer applications.
Applies to clinical research teams, PIs, and coordinators configuring and managing trials through our no-code builder.
Applies to developers, architects, and data scientists utilizing our data ingestion and standardization tools.
Applies specifically to user interactions and data privacy across our primary website.
Security research program
We minimize systemic risk by collaborating with independent security experts to identify vulnerabilities, welcoming proactive testing conducted strictly under our established disclosure guidelines.