CareBand × Regis Healthcare — Patent Positioning & Technology Alignment Review

Export full PDF

B — Regis Evidence Base

Privacy, Consent & Information Sharing

Regis' current privacy policy is one of the most important public evidence sources in this review. It articulates, as an organisational obligation, the exact decisions the CareBand architecture is designed to make at the moment information is requested.

Publicly stated privacy responsibilities

Regis' privacy policy states that Regis seeks to: Privacy and governance source

  • protect personal and health information
  • ensure use and disclosure occurs only for legally permitted purposes
  • regulate access, correction and deletion
  • maintain confidentiality through storage and security
  • control access through access and identity-management systems
  • protect information when using service providers
  • control where information is stored and who has access
  • use privacy-by-default settings where possible
  • manage consent withdrawal

Direct CareBand relevance

Regis privacy responsibilityCareBand patent-positioning relevance
Legally permitted use and disclosurePurpose and authority-based policy evaluation
Access and identity managementVerification of requesting user and role
Health information protectionAttribute-level minimum disclosure
Service-provider accessRelationship and organisation-aware access
Family and supporter updatesRelationship-specific disclosure
ConsentDynamic, purpose-bound and time-bound permissions
Withdrawal of consentRevocation and invalidation of access
De-identificationSelective suppression and pseudonymisation
Overseas storage and service providersRegion and jurisdiction-aware policy
Emergency disclosureEmergency-purpose policy override
High-risk technologiesPolicy-gated biometric, location or device data
Data breach riskReduced exposure through minimum necessary release

Key message

Regis already describes the legal and operational obligation. CareBand potentially provides a protected technical method for enforcing that obligation at the moment information is requested.
The privacy policy describes obligations and intentions. It does not describe the technical mechanism by which disclosure decisions are computed or recorded. Technical implementation not publicly disclosed.

Sources referenced on this page