Privacy and data use · Updated July 28, 2026

Keep patient information out of RehearseCare.

See what the current pilot stores, where it is processed, and how to request an export or deletion.

Information you enter

Account holders enter their name, role, work email, practice or facility name, and facility type. Readiness setup can add facility-location details, oversight programs, services, and prior exercise information. During use, teams can create drill schedules, participant roles, observations, debrief findings, and corrective actions.

Patient information

Do not enter patient names, dates of birth, medical record numbers, contact details, diagnoses, or other patient identifiers. Use fictional details for every drill. A patient record is not needed to build a plan, run a rehearsal, or complete a report.

How RehearseCare uses information

The application uses entered information to create the facility workspace, calculate the readiness plan, schedule and run drills, and display the records and follow-up assigned inside that workspace.

Where information is stored and processed

RehearseCare uses Vercel to deliver the web application and Supabase for authentication and the managed database. The current Supabase project is hosted in the eastern United States. Information is encrypted in transit with HTTPS; the infrastructure providers manage encryption and access controls for their services. RehearseCare does not sell account or drill information.

Infrastructure providers: Vercel and Supabase.

Cookies and measurement

The application uses necessary cookies to keep account sessions secure and remember limited referral information such as a campaign or source. RehearseCare does not currently run third-party advertising trackers in the product.

Retention, export, and deletion

Records remain available while the facility account is active so the facility can use them as a training and quality-improvement history. Authorized users can print reports and export drill-history and attendance files. Self-service account deletion is not yet available. A facility can request access, correction, export, or deletion by email; we verify the request and confirm the scope and timing in writing before changing records. Limited copies may remain temporarily in infrastructure backups or where retention is required by an agreement or law.

HIPAA and Business Associate Agreements

The current pilot does not include a Business Associate Agreement. Do not enter protected health information. HHS explains that a cloud vendor that creates, receives, maintains, or transmits electronic PHI for a covered entity generally requires an appropriate Business Associate Agreement.

Read HHS cloud-computing guidance