ISS CareTrack

Security Notice

This notice describes the current security posture, prototype limitations, and planned security direction for ISS CareTrack.

Prototype-stage security notice ISS CareTrack is currently in active development and should be used with demo data only. Do not enter real patient information, protected health information, official provider documentation, Medicaid identifiers, billing records, or incident details until production hosting and compliance controls are finalized.

1. Current development status

ISS CareTrack is currently being developed as a documentation and reimbursement workflow platform for Texas Individualized Skills and Socialization providers. The public website and prototype application are intended for design review, workflow testing, demonstration, and continued development.

The current prototype environment should not be treated as a production clinical, billing, compliance, or official provider recordkeeping system.

2. Security design direction

ISS CareTrack is being designed with a security-conscious structure that supports controlled access, workflow accountability, documentation status tracking, and audit-friendly operational records.

Role-based access Users are separated by role, including staff, tenant admin, reviewer roles, billing reviewer, and super admin.
Workflow status tracking Records can move through draft, submitted, returned, approved, rejected, closed, and billing-readiness stages.
Reviewer accountability Reviewer actions, attestations, notes, approvals, and correction decisions are designed to support clearer oversight.
Audit-friendly activity System activity and status changes are intended to support audit trail design and operational review.

3. Demo-data-only restriction

During the prototype stage, users must use test or demo data only. Users should not enter:

4. Login and account controls

Access to the prototype application may require login credentials. Users are responsible for maintaining the confidentiality of their username and password and should not share access with unauthorized persons.

Account activity may be logged for security, troubleshooting, workflow testing, and audit trail development. Unauthorized access, password sharing, account misuse, or attempts to bypass controls are not permitted.

5. Application access boundaries

ISS CareTrack uses role-focused dashboards and permission boundaries to help separate the work of staff, tenant admins, reviewers, billing users, and platform administrators.

Users should access only the areas, records, dashboards, and functions that they are authorized to use. Attempts to access restricted areas, manipulate URLs, bypass workflow rules, or modify unauthorized records are prohibited.

6. Website forms and email

Public website forms, including the demo request form, are for general business inquiries only. They should not be used to submit sensitive, confidential, regulated, or patient-related information.

Email communications should also avoid patient information, incident details, billing records, or official documentation unless appropriate production controls and agreements are in place.

7. SSL and secure transmission

The public website is currently available through HTTPS. The application subdomain should also use HTTPS before broader demos, real user testing, or any production use.

Until SSL is active for the application subdomain, the prototype application should remain limited to internal development and demo-data-only testing.

8. Planned production security expectations

Before ISS CareTrack is used in production with real healthcare documentation or patient-related information, the application environment should be reviewed and migrated to a HIPAA-conscious hosting arrangement with appropriate technical, administrative, and operational safeguards.

Planned or expected production controls may include:

9. No security guarantee during prototype stage

While ISS CareTrack is being designed with security and documentation integrity in mind, the prototype environment is provided for development and demonstration purposes only. No guarantee is made that the prototype environment is suitable for production healthcare use or for storing regulated healthcare information.

10. Reporting concerns

If you believe you have identified a security issue, unauthorized access, misdirected information, or a possible system weakness, please report it promptly.

Email: info@isscaretrack.com

Do not include patient information, passwords, database credentials, or sensitive screenshots in email unless a secure reporting method has been established.

11. Updates to this notice

This Security Notice may be updated as ISS CareTrack moves from prototype development toward production readiness, including changes related to hosting, SSL, access control, backup strategy, audit logging, and compliance documentation.

Effective date: July 1, 2026