beyondmychart.com ๐Ÿ  Home

CARIN Code of Conduct โ€” Public Attestation

Last updated: July 30, 2026

PatientPower endorses and attests to the CARIN Alliance Trust Framework and Code of Conduct for consumer-facing health applications. This public attestation describes the binding commitments we make to every person who uses PatientPower to gather, view, and control their own health information, consistent with the CMS Interoperability & Patient Access rule (CMS-9115-F).

Why this exists: When you connect a health plan or health system to a consumer app, that data leaves the HIPAA-covered world and its protection depends on the app. The CARIN Code of Conduct is the industry standard by which apps publicly commit to protect it. This page is our commitment, made publicly so that you โ€” and regulators such as the FTC and state attorneys general โ€” can hold us to it.

Our commitments

PatientPower adheres to the following CARIN Code of Conduct principles:

PrincipleWhat we commit to
Consumer access & controlYou obtain your health data through the app you choose. You direct what is connected, viewed, and shared, and you can change your mind.
Meaningful, informed consentBefore any connected data is accessed, you authenticate at your provider or health plan and explicitly authorize the specific information. We do not collect connected data without your consent.
Use limited to what you authorizeWe use and disclose your information only for the purposes you authorize โ€” to consolidate and explain your records to you. No secondary use without your consent.
No sale of dataWe never sell your health information, and we do not use it for advertising or share it for third-party marketing.
Data minimizationWe access only the categories you approve and only what is needed to provide the Service.
TransparencyOur practices are described in plain language in our Privacy Policy & Disclosure and our ONC Model Privacy Notice.
Access, amendment & deletionYou may export your data, request correction, delete your account and information, and revoke access at any time โ€” both in PatientPower and at the connected source.
Security safeguardsWe protect your information with encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls, audit logging, and server-side token handling so credentials are never exposed to your browser.
Breach notificationWe work to notify affected users of a material breach as required by law.
Accountability & oversightWe designate a responsible officer (below) accountable for these commitments and support enforcement oversight by the FTC, state attorneys general, and other applicable authorities.
Best practices & lawWe adhere to applicable law and to industry best practices for privacy and security, and update this attestation as those standards evolve.

Connected data sources

PatientPower connects to health plans and health systems using standards-based, consent-driven interfaces (SMART on FHIR, OAuth 2.0, OpenID Connect). Connected sources โ€” including Kaiser Permanente's Patient Access API โ€” control their own data under their own privacy policies. We access only what you authorize from those sources, and we honor revocation performed at the source promptly and gracefully.

Designated accountable officer

Privacy Officer, PatientPower
Responsible for PatientPower's adherence to the CARIN Code of Conduct.
Contact: through beyondmychart.com.

Scope & changes

This attestation applies to the PatientPower Service at beyondmychart.com. Material changes will be reflected by the "Last updated" date above. This page is maintained as a publicly facing statement so that our commitments remain open to review and enforcement.

See also our Privacy Policy & Disclosure, ONC Model Privacy Notice, and Terms & Conditions.