1. Current development status
ISS CareTrack is currently being developed as a documentation and reimbursement workflow platform for Texas Individualized Skills and Socialization providers. The public website and prototype application are intended for design review, workflow testing, demonstration, and continued development.
The current prototype environment should not be treated as a production clinical, billing, compliance, or official provider recordkeeping system.
2. Security design direction
ISS CareTrack is being designed with a security-conscious structure that supports controlled access, workflow accountability, documentation status tracking, and audit-friendly operational records.
3. Demo-data-only restriction
During the prototype stage, users must use test or demo data only. Users should not enter:
- Real patient or individual names
- Dates of birth or personal identifiers
- Medicaid, Medicare, insurance, or billing identifiers
- Diagnosis, service, clinical, or care plan details involving real individuals
- Incident notes involving real individuals
- Real staff-sensitive records beyond approved test accounts
- Any protected health information or confidential provider documentation
4. Login and account controls
Access to the prototype application may require login credentials. Users are responsible for maintaining the confidentiality of their username and password and should not share access with unauthorized persons.
Account activity may be logged for security, troubleshooting, workflow testing, and audit trail development. Unauthorized access, password sharing, account misuse, or attempts to bypass controls are not permitted.
5. Application access boundaries
ISS CareTrack uses role-focused dashboards and permission boundaries to help separate the work of staff, tenant admins, reviewers, billing users, and platform administrators.
Users should access only the areas, records, dashboards, and functions that they are authorized to use. Attempts to access restricted areas, manipulate URLs, bypass workflow rules, or modify unauthorized records are prohibited.
6. Website forms and email
Public website forms, including the demo request form, are for general business inquiries only. They should not be used to submit sensitive, confidential, regulated, or patient-related information.
Email communications should also avoid patient information, incident details, billing records, or official documentation unless appropriate production controls and agreements are in place.
7. SSL and secure transmission
The public website is currently available through HTTPS. The application subdomain should also use HTTPS before broader demos, real user testing, or any production use.
Until SSL is active for the application subdomain, the prototype application should remain limited to internal development and demo-data-only testing.
8. Planned production security expectations
Before ISS CareTrack is used in production with real healthcare documentation or patient-related information, the application environment should be reviewed and migrated to a HIPAA-conscious hosting arrangement with appropriate technical, administrative, and operational safeguards.
Planned or expected production controls may include:
- ✓HIPAA-conscious hosting arrangement with appropriate Business Associate Agreement review
- ✓HTTPS/SSL enforcement for the application subdomain
- ✓Centralized and protected database configuration
- ✓Role-based access control and least-privilege permissions
- ✓Secure password handling and account lifecycle controls
- ✓Activity logging and audit trail review
- ✓Encrypted backups and disaster recovery planning
- ✓Secure file upload/storage controls where applicable
- ✓Incident response and breach response procedures
- ✓Administrative policies for user access, onboarding, termination, and support sessions
9. No security guarantee during prototype stage
While ISS CareTrack is being designed with security and documentation integrity in mind, the prototype environment is provided for development and demonstration purposes only. No guarantee is made that the prototype environment is suitable for production healthcare use or for storing regulated healthcare information.
10. Reporting concerns
If you believe you have identified a security issue, unauthorized access, misdirected information, or a possible system weakness, please report it promptly.
Email: info@isscaretrack.com
Do not include patient information, passwords, database credentials, or sensitive screenshots in email unless a secure reporting method has been established.
11. Updates to this notice
This Security Notice may be updated as ISS CareTrack moves from prototype development toward production readiness, including changes related to hosting, SSL, access control, backup strategy, audit logging, and compliance documentation.
Effective date: July 1, 2026