CareVault
Your health memory. Your rules.
CareVault is a patient-controlled memory and consent layer for AI health apps. Patients decide, field by field and app by app, what each AI app can see. Developers get one simple API to build on.
Built at the HealthLink Hackathon (October 2026) by Kevin Fong, Param Jain, Deren Erdem, and Arnav Wagh.
Inspiration
This hackathon inspired it. All around us, teams were using AI to improve healthcare: symptom checkers, trial matchers, imaging tools, health companions. Every one of them needed the same thing, which was the patient's health data.
There's no shared foundation for handing that data over safely. Each app asks for everything and stores it its own way. Once you've shared your data, you can't see what the app does with it, who it gets passed to or where it ends up.
The demand is there, but the trust is not:
| 230M+ | people ask ChatGPT health questions every week (OpenAI, Jan 2026) |
| 1 in 3 | US adults turned to AI for health info in the past year (KFF poll, Mar 2026) |
| 74% | of patients worry about health-data privacy (Wolters Kluwer, Sep 2026) |
| 61.6M | people's health data exposed in reported breaches in 2025 (HIPAA Journal / HHS OCR) |
So we built the missing layer. It's a memory for AI agents that the patient owns, with redaction and access controls built in, and an API that makes it easy for developers to build on.
The problem
Your health data is scattered across hospital EHRs, lab results, pharmacies, wearables, therapy notes and insurance claims. AI apps want all of it. Today the choice is all or nothing: every app you connect sees everything.
What it does
CareVault is one vault for your health memory. It sits between you and every AI app you use. For every field, separately for every app, you choose one of three settings:
| Setting | What the app receives | What it means |
|---|---|---|
| Share | The real value | Use this for what the app genuinely needs to do its job. |
| Redact | "[REDACTED]" |
The app knows the field exists but never sees its value. |
| Private | Nothing at all | The app can't tell the information exists. There's no field, no placeholder and no count. |
Reading, downloading and writing are separate permissions. An app can be allowed to read without being allowed to download or write back.
Example: same vault, different view
Alex's vault holds six fields. Here's how Alex has set them for an imaging app called Scan Review:
| Field | Value | Setting for Scan Review |
|---|---|---|
| Preferred name | Alex Morgan | Redact |
| Phone number | +1 202-555-0148 | Redact |
| Age | 34 | Share |
| Reported symptom | Intermittent cough for two weeks | Share |
| Private health note | Anxiety before appointments | Private |
| Appointment preference | Tue & Thu afternoons | Share |
Every request goes through a policy check. Here's what Scan Review actually gets back:
POST /api/v1/context
{
"policyVersion": 3,
"items": [
{ "field": "Preferred name", "value": "[REDACTED]" },
{ "field": "Phone number", "value": "[REDACTED]" },
{ "field": "Age", "value": "34" },
{ "field": "Reported symptom", "value": "Intermittent cough for two weeks" },
{ "field": "Appointment preference", "value": "Tue & Thu afternoons" }
]
}
The private health note doesn't appear in the response. There's no placeholder for it and no hidden count.
Working today
- ✅ Share / Redact / Private for every field, per app
- ✅ Separate read, download and write permissions
- ✅ Inherited protection, so data derived from a protected field keeps that protection
- ✅ Revocation at any time, plus a full access history
- ✅ Developer API and inspector
- ✅ Live AI chat that answers only from the memory you've permitted
- ✅ 29 automated tests passing
How it works
- The patient sets policy. Every field in the vault has a Share, Redact or Private setting for each connected app, plus read, download and write permissions.
- The app calls the Context API. The app requests context through
POST /api/v1/context. - A policy check runs on every request. CareVault applies the patient's current policy for that app before anything leaves the vault. Shared fields return their values, redacted fields return a placeholder and private fields are left out entirely. Each response carries the
policyVersionit was checked against. - Protection follows the data. Anything an app derives from a protected field inherits that field's protection.
- Every access leaves a receipt. Patients can see exactly what each app received and when. They can revoke access at any time.
How it's different
CareVault combines five things in one place:
- It works across many AI apps, not just one.
- It gives per-field Share / Redact / Private control.
- Protection follows derived data.
- Patients can see exactly what each app received.
- It's patient-owned and app-neutral.
Other options each cover only part of that list. These include consumer AI health assistants (ChatGPT Health, Copilot Health, Claude), patient portals and FHIR APIs (MyChart, SMART on FHIR apps) and phone health hubs (Apple Health Records). This comparison is based on public product descriptions as of October 2026.
Business model
Patients stay free, and apps pay for trusted access.
| Patients | Developers | Enterprise |
|---|---|---|
| Free | $0.25–$1 per connected patient / month in pilot | Annual license |
| Own the vault. Data is never sold and there are no ads. | Context API and consent receipts | White-label consent layer for care teams |
| Share / Redact / Private per field | Audit logs and access history | BAA / SOC 2 path for deployments |
| Revoke permissions any time | Tiered by volume and permissions | Admin controls and report review |
| See every app receipt | Health system licensing |
Go-to-market: We'll start with free pilots and prove safer consent and faster integration. Then we'll convert those apps into paid API customers.
What's next
Status: This is a hackathon prototype. Importing real records, encryption at rest and identity verification are all on the roadmap below. Real patient data waits on clinical and legal review.
Next 3 months: pilot
- Import real records via FHIR patient-access APIs
- Add encryption at rest and key management
- Build a review screen for reports written by apps
- Pilot with our 3 partner apps (imaging, trials and pharmacy)
12 months: production
- Real accounts with identity verification
- Caregiver and proxy access
- SOC 2 audit and BAAs for clinic deployments
- Public developer program
- Clinical and legal review before any real patient data
Our ask
- Pilot partners: imaging, trial matching, pharmacy or health-companion workflows
- Clinical and legal feedback: help us stress-test consent, derived data, audit logs and user safety
- Patient interviews: help us check whether users understand Share / Redact / Private
Team
- Param Jain
- Deren Erdem
- Arnav Wagh
- Kevin Fong
CareVault gives every patient one place to decide what every AI app can see, and gives developers a platform to build on.
Built With
- docling
- next.js
- node.js
- postgresql
- python
- pytorch
- react.js
- tesseract
- typescript
Log in or sign up for Devpost to join the conversation.