Last updated: 31 July 2026 · Terms of Service (use rules — not data detail)
| Role | Role for privacy |
|---|---|
| User | Your records on the instance you use |
| Instance operator | Runs the server; responsible for that deployment’s security, access, backups, and any legal duties |
| YourPHR project / yourphr.org | Publishes software and this site; does not hold your health or Medicare data |
If someone else hosts your instance, ask them how they protect your data.
On an instance: health records you import (including Medicare claims-related data such as Coverage and ExplanationOfBenefit when you connect Medicare); documents you upload; account login data for the instance; provider/OAuth tokens used to fetch data you authorized.
Not by the project: maintainers and yourphr.org do not receive your health records, Medicare claims, or tokens.
This website: static pages only; no health data; no first-party analytics cookies. The host may log standard request metadata (e.g. IP).
You may import files yourself or connect a patient-access API (SMART on FHIR), including Medicare via CMS Blue Button.
When you connect Medicare (or another provider):
Shared with CMS: only what OAuth/API requires. Shared with the YourPHR project: nothing about your Medicare or clinical data.
How long: the instance may re-sync while the connection is authorized. Disconnect removes stored credentials for that source. Data already imported stays until you or the operator delete it.
Only to display and organize health information for users of that instance.
The stock software is not designed to sell data, use it for advertising/marketing, or train commercial AI on your records. Default product does not send Medicare data to third parties for their own use. If an operator adds export/share features, they must disclose that.
De-identified data: stock software does not package your data for sale/research as de-identified datasets. Even “anonymized” health data can sometimes re-identify people.
| Who | Role |
|---|---|
| CMS / your providers | You authorize; they supply data under their rules |
| Sign-in relay | OAuth code only (~60s); no health data, no tokens |
| Operator’s host / reverse proxy / SSO | Access control and hosting — operator must secure them |
| GitHub Pages | Serves yourphr.org only |
Dormant/closed accounts: data remains on the operator’s storage until removed. The project holds no enrollee databases.
Local storage, encryption at rest when enabled, no project copy of records, short-lived relay codes. Operators must also use HTTPS, access control, secure backups, and current software.
The instance operator handles breaches of data on their deployment and notifies people as required by law (including, where applicable, the FTC Health Breach Notification Rule for personal health records).
The project does not hold your instance data. If project-run infrastructure (e.g. the public relay or this site) is involved in an incident, we will communicate through appropriate public channels.
Open-source maintainer changes do not move your database. If a hosted operator is sold or changes data use, they must notify you when required; you should be able to disconnect sources and delete data.
We may update this policy; the date above will change. For a CMS-approved Blue Button production app, policy/notice changes may need CMS review before rollout.