Two regimes, one principle
HIPAA (in the US) and Japan's APPI (個人情報保護法) differ in the details, but they share a core idea: sensitive personal data needs consent, purpose limitation, least-privilege access, and a clear trail of who touched it.
Care data is among the most sensitive there is
Health symptoms, medication routines, mood, family circumstances — this is deeply personal information. Spreadsheets, chat apps, and paper notes were never designed to protect it.
What responsible handling looks like
- Consent and purpose limitation built into the data model, not bolted on
- Role-based access: who can see what, and why
- Audit logs for every view, edit, and approval
- Encryption in transit and at rest
- A clear path for deletion requests
The CareOS posture
CareOS is wellness-first and AI-drafts-only — a human approves every record before it is final or sent. It is designed around APPI/HIPAA-like principles even where they are not strictly required, because trust is the product.