← Back to Pivot Wellness
Documentation

Connecting your health records — and why it is safe

What you will see, what Pivot Wellness reads, and what it never sees.

What is Pivot Wellness?

Pivot Wellness is a personal health data management and wellness coaching platform. It helps users organize their health information from multiple sources into a unified, searchable system. Users can import nutrition data, fitness tracking, bloodwork results, and clinical medical records to get a comprehensive view of their health.

The platform includes AI-powered chat for exploring your health data, scheduled monitoring workflows, and wellness coaching tools.

How connecting works

Pivot Wellness connects to the health system you choose using SMART on FHIR, the standard US health systems use to let patients share their records with apps they pick. You choose your health system when you connect, Pivot Wellness talks to that organization directly, and you can connect more than one.

Connecting is one way records arrive. You can also add files, photos and imaging discs yourself, and every source is listed together in Manage my data.

The three steps you will meet

1 · Sign in at your health system
You sign in at your health system directly, with its patient login — not your Pivot Wellness one. Pivot Wellness never sees that password, and a reset goes through the organization.
2 · Allow access

Some organizations show a warning like this before you allow access:

This app is not provided by your healthcare organization.

They show it for every app they don’t run themselves. It is not a judgment about Pivot Wellness.

3 · Choose what to share, and for how long
Share everything you’re comfortable sharing, for as long as you’re offered. A complete picture is what lets Pivot Wellness see what a single result can’t. Some organizations never tell us which window you chose, so access can end without a warning we can give you — when it does, your source says so and Reconnect brings it back.

What arrives, and what happens to it

Everything your health system offers is brought in — documents, imaging reports and images, and records — and every document is read in full as it arrives, so chat and deep research can use it with a link back to where it came from. You can watch how far it has gotten:

  • Finding out
  • Bringing it in
  • Getting the words
  • Filing it
  • Done

If an organization won’t release something, or its connection doesn’t offer a kind of record, we list it and say why.

What we read
  • Documents: visit notes, letters and reports
  • Imaging reports, and images when they’re sent
  • Lab results and diagnostic reports
  • Vital signs (blood pressure, weight, heart rate, etc.)
  • Active and historical medications
  • Medical conditions and diagnoses
  • Encounter and visit history
What we never see
  • Your patient login password
  • Anything you do not grant
  • Records from a system you have not connected

You can stop syncing, or delete everything from a source, at any time from Manage my data › Your sources.

Data We Access

With your explicit permission, Pivot Wellness may read:

  • Lab results and diagnostic reports
  • Vital signs (blood pressure, weight, heart rate, etc.)
  • Active and historical medications
  • Medical conditions and diagnoses
  • Allergies and intolerances
  • Immunization records
  • Encounter and visit history
  • Clinical notes and documents
  • Imaging reports and images

We have read-only access. Pivot Wellness cannot modify, delete, or write any data to your medical record.

Security and Privacy

  • OAuth 2.0 with PKCE: We use the most secure form of authorization. Your credentials are never shared with us.
  • Encrypted transport, private storage: All imported health data travels over TLS 1.3, and the OAuth tokens that reach your medical record are encrypted at rest with server-managed keys. The imported records themselves are stored on our own hardware, protected by access controls and audit logging rather than row-level encryption — see Security for exactly what is and is not encrypted.
  • No data selling: We will never sell your health data to third parties.
  • Revocable access: You can stop syncing at any time from Pivot Wellness, or end access in your health system’s patient portal.
  • Data deletion: Delete a document, a study, or everything from a source, and Pivot Wellness stops showing and using it right away, then erases it. Copies in backups are removed as they age out — see Privacy.

Your Rights

Under the 21st Century Cures Act and the ONC Final Rule, you have the legal right to access your electronic health information through standardized APIs. Your healthcare provider is required to support this access. Pivot Wellness helps you exercise this right in a secure, user-friendly way.

Not Medical Advice

Pivot Wellness is a health data management tool, not a medical device. Any AI-generated analyses or summaries are for informational purposes only and do not constitute medical advice, diagnosis, or treatment recommendations. Always consult your healthcare provider for medical decisions.

Technical Details

  • FHIR Version: R4 (4.0.1)
  • USCDI Version: v3
  • Auth Protocol: SMART on FHIR (OAuth 2.0 + PKCE)
  • Client Type: Confidential, with JWT client assertion
  • Signing Algorithm: RS384

Contact

For questions about connecting your health records, please contact support@pivotwellness.com.

Related Documents

© 2026 Pivot Wellness. All rights reserved. Not medical advice.