Structural privacy

How privacy is built in by design, not by policy.

Most systems try to protect patient data by locking it down after they collect it. Arcametric starts a step earlier. It is built so a patient's name, or any free text, cannot be entered into it. There are no name fields. There is no free-text box. We never collect names, and the design makes it impossible to.

How that works

How that works, plainly.

Each record carries a code, not a name. If a clinic needs to know which of its own patients a record belongs to, it keeps that connection on its own side, never in Arcametric. A patient's name and free text cannot be entered into the platform, so we hold no name to trace back to an individual.

Your EHR keeps its job

Billing, scheduling, identity, and general charting stay in your existing system. Nothing migrates, nothing integrates. Your front desk never changes. Setup takes minutes, not months.

Arcametric makes it intelligent

Your team records treatment stages, safety events, and outcomes in the same fields every time, so you can report and review them. This is the work your EHR was never built to hold. An interaction reference sits alongside it; your clinical judgment stays in charge.

Identity stays in your clinic

Inside Arcametric, every patient is a record code. There is no field anywhere that can hold a name, so one cannot be entered or stored. The link between a patient's name and their record code lives entirely within your clinic's own systems. We cannot read it.

The architecture

Two sides, one arc of care.

Arcametric two-column privacy architecture On the left, your clinic holds patient identity, the name-to-code crosswalk, and your EHR. On the right, Arcametric holds the clinical records, treatment structure, and reports. Only de-identified records flow to Arcametric; patient identity never leaves the clinic. YOUR CLINIC Patient identity (names) Name-to-code crosswalk Your EHR (billing, scheduling) Clinical records Treatment structure + safety Outcomes reports de-identified reference

Your clinic

  • Patient identity (names)
  • Name-to-code crosswalk
  • Your EHR (billing, scheduling)
de-identified reference

Arcametric

  • Clinical records
  • Treatment structure + safety
  • Outcomes reports

Our support team works from a record code, never a name.

We can't see a name, because our system has no field that can hold one. To us, a patient is an ID like PT-4F9X2 attached to clinical data, and support works from that ID.

Your exports stay yours if you leave.

Your exports are yours. The crosswalk was always in your systems, so nothing about patient identity ever needs to come back from us.

Read this before citing it

What this is, and what it is not.

This is a description of how the platform is built, not a legal promise about every possible circumstance. What we claim is narrow, structural, and true: a patient's name, and any free text, cannot be entered into Arcametric, because there are no fields that would store them. There are no identities on our side to lose, leak, or hand over, because none were ever collected. That structural fact is also what lets contributors share de-identified data with each other in the first place.