Terms and Conditions

MyChart Care Record Connector · Effective September 10, 2026

This is a personal, family-operated tool. It is built and run by an individual, not a company, and it exists so that a parent can keep an organized copy of their own family's medical records. It is not a commercial product, and nothing about it is funded by advertising or by selling anyone's data.

1. Who operates this application

This application is operated by Ben Lewis, an individual and independent developer. There is no company, no staff, and no investors. The source code is available publicly so that anyone, including the health systems whose data it reads, can see exactly what it does.

2. What it does

The application connects to a patient portal (MyChart) using that portal's official, patient authorized API, and copies the patient's own health records into a private record kept by the patient's family. Its purpose is care coordination: keeping test results, reports and appointments organized and in one place, so they can be reviewed and shared with the care team.

The application is read only. It cannot write to, change, or delete anything in your medical record, and it cannot send messages to your care team on your behalf.

3. What data it accesses

Only what you approve during sign in, and only for the patient whose record you authorize. That includes:

The application does not collect data about anyone other than the patient whose record you authorize, and it does not combine your record with data from any other source.

4. Where data is stored and for how long

Data is stored in two places: on servers operated by Google Cloud in the United States, and locally on the family's own computer. Data in transit is protected with TLS. The credential used to reach the patient portal is encrypted at rest using Google Cloud Key Management Service, and is never written in readable form.

Data is kept indefinitely, because a medical history is only useful when it is complete. It is kept until the patient or their parent decides to delete it.

5. Deleting your data

You may have all stored data deleted at any time, for any reason, by asking. There is no retention period you have to wait out and no part of the record that is exempt.

Disconnecting the application from your patient portal revokes its access going forward, but it does not by itself erase the records already saved. That is deliberate: the care history is meant to outlive any one login credential, and an accidental disconnect should not destroy years of records. Deletion happens when you ask for it.

6. Who else can see your data

No one has routine access to your data except you and the family members operating this application. There is no staff, no partners, no affiliates, and no researchers.

There is one category you should understand clearly. This application is designed to make your records available to an AI assistant that you separately authorize, currently Claude, operated by Anthropic. When you ask that assistant a question about the records, the relevant records are sent to it so it can answer. That assistant is therefore an application that you authorize, and it processes your health data under its own provider's terms.

You approve each such application individually when you connect it. You are not notified separately every single time a record is read, and the application keeps only a partial record of access, in the form of ordinary server logs.

7. What is never done with your data

The data is used for one thing: providing the direct service described above to the family that operates the application.

8. You can get a copy of everything

You may request a complete copy of every record stored about you, in a readable format, at any time.

9. Legal status and HIPAA

This application is operated by an individual for personal family use. The operator is not a HIPAA covered entity and is not a business associate of any health system, and there is no business associate agreement in place with any health care organization.

Health information you retrieve through a patient access API leaves the protection of HIPAA once it reaches an application you chose. That is true of any patient facing application, not just this one, and it is worth understanding before you connect anything to your health record.

10. This is not medical advice

This application organizes and displays information. It is not a medical device, it does not diagnose, and nothing it produces is medical advice. It does not replace your doctors, your nurses, or your own judgment.

Any AI generated summary can be wrong, incomplete, or misleading. Always confirm against the original result in your patient portal and with your care team before acting on anything.

In an emergency, call your care team or your local emergency number. Do not rely on this application.

11. Availability

This is a personal project offered as is, with no warranty and no guarantee of availability, accuracy, or continued operation. It may stop working at any time, including because the health system changes or withdraws API access.

12. Changes to these terms

If these terms change materially, the change will be published at this address with a new effective date before it takes effect.

13. Contact

Questions, deletion requests, and requests for a copy of your data: ben.lewis@lewisconsultation.com.