Structural privacy

See how privacy is built into the architecture.

Arcametric separates patient identity from the shared treatment record.

Entering a patient's name into Arcametric is structurally impossible. Arcametric helps you analyze your workflow, not your patients. Your patient's identity stays with you.

The architecture

Your clinic keeps identity. Arcametric helps you record your work.

Your clinic

Patient Identity

Name, date of birth, contact details

Identity remains here

EHR

Your existing identity-bearing clinical system

Local Crosswalk

The clinic maps identity to a De-Identified Patient Reference and keeps that link in its own systems.

Identity layer stays with the clinic
Privacy boundary
Only these cross De-Identified Patient Reference Structured clinical data Patient identity does not cross
Arcametric

De-Identified Patient Reference

No patient name required

Structured Clinical Record

Timing, interventions, observations, follow-up

Reports and Analytics

Governed clinical outputs from eligible structured data

De-identified record continues in Arcametric
Existing data

Patient identity doesn't need to travel with the dataset.

Prepare identity-bearing source information under your control before data enters Arcametric. Accepted records use de-identified references rather than making Arcametric the system that stores the patient's identity.

Source records move through local preparation, exclusion of identity fields, and validation before accepted de-identified records enter Arcametric.
  1. Source records

    Identity-bearing information stays under your control

  2. Local preparation

    Prepare the dataset before it enters Arcametric

  3. Excluded identity fields

    Names and other identity fields stay outside the hosted dataset

  4. Validation

    Check admission requirements against Arcametric structure

  5. Accepted records

    De-identified references enter the structured history

See how existing data works

How that works

You keep the names. We hold only a de-identified patient reference.

Each shared record uses a de-identified patient reference rather than a name. Your clinic keeps the link between that reference and the patient in its own systems. Arcametric stores the structured treatment record associated with that reference.

Your EHR keeps its job

Billing, scheduling, identity, and general charting stay in your existing system. Nothing migrates, nothing integrates. Your front desk never changes. Setup takes minutes, not months.

Arcametric structures the treatment record

Your team records treatment stages, safety events, and outcomes in the same fields every time, so you can report and review them. This is the work your EHR was never built to hold. An interaction reference sits alongside it; your clinical judgment stays in charge.

Identity stays in your clinic

No field in the shared system can hold a patient's name. Your clinic keeps the link between the patient's identity and the de-identified patient reference in its own systems.

Our support team works from a de-identified patient reference.

Support can work from the de-identified patient reference attached to the shared record. Patient identity remains in the clinic's own systems.

Your exports stay yours if you leave.

Your exports are yours. The crosswalk was always in your systems, so nothing about patient identity ever needs to come back from us.

Read this before citing it

See how this architecture helps protect you and your patients.

This page describes the platform's data boundary, not a legal conclusion. No field in the shared system can hold a patient's name. Identity stays in the clinic, and only de-identified patient references reach Arcametric. That architecture changes what Arcametric stores, but it does not replace legal, privacy, consent, security, or research review.

See it run beside your EHR.