Account Security
Version: 0.1.1 | Last Updated: 2026-01-07
Overview
CareForMeds protects your health information with bank-level security and HIPAA compliance. This guide explains how to keep your account secure.
Your Privacy is Protected
CareForMeds is HIPAA-compliant, meaning:
- Your health data is encrypted in transit and at rest
- Access is strictly controlled and logged
- We never sell or share your data with advertisers
- Only you and your authorized caregivers can see your information
Password Best Practices
Creating a Strong Password
Your password should be:
- At least 12 characters long
- Mix of character types: uppercase, lowercase, numbers, symbols
- Not based on personal information: No birthdays, names, addresses
- Unique to CareForMeds: Don't reuse passwords from other sites
Good examples:
Sunrise#Coffee2024!My3DogsLoveTreats@HomeBlueSky_rainy_Day99
Bad examples:
password123(too common)John1965(personal info)qwerty(keyboard pattern)
Changing Your Password
- Click your name in the top right corner
- Select Profile or Settings
- Click Change Password
- Enter your current password
- Enter and confirm your new password
- Click Save
Two-Factor Authentication (2FA)
2FA adds an extra layer of security by requiring a code from your phone in addition to your password.
Setting Up 2FA
- Go to Settings > Security
- Click Enable Two-Factor Authentication
- Choose your method:
- Authenticator App (recommended): Google Authenticator, Authy, etc.
- SMS: Text message codes
- Follow the setup instructions
- Save your recovery codes in a safe place
Using 2FA
After setup, when you log in:
- Enter your username and password
- Enter the 6-digit code from your authenticator app or SMS
- You're logged in
Recovery Codes
When you enable 2FA, you receive recovery codes. These let you log in if you lose access to your phone.
- Store them safely (printed, password manager, secure note)
- Each code works once then expires
- Generate new codes if you run out or suspect they're compromised
Session Management
Automatic Timeout
For your safety, CareForMeds automatically logs you out after a period of inactivity. This protects your data if you forget to log out on a shared computer.
- Default timeout: 30 minutes
- You can adjust this in Settings > Security
Active Sessions
View and manage devices logged into your account:
- Go to Settings > Security > Active Sessions
- See all devices currently logged in
- Click Log Out next to any session you don't recognize
- Click Log Out All Other Sessions to secure your account
Login Notifications
Get alerted when someone logs into your account:
- Go to Settings > Security
- Enable Login Notifications
- Choose notification method (email, push, or both)
You'll be notified of:
- New device logins
- Logins from new locations
- Failed login attempts
Password Reset
If You Forgot Your Password
- Click Forgot Password on the login page
- Enter your email address
- Check your email for a reset link
- Click the link and create a new password
- Log in with your new password
Note: Reset links expire after 1 hour for security.
If Your Account is Compromised
- Change your password immediately
- Enable 2FA if not already enabled
- Review active sessions and log out unknown devices
- Check your email for unauthorized changes
- Contact support if you need help
Caregiver Access
When you authorize a caregiver:
- They can view your medications and adherence
- They cannot change your password or security settings
- You can revoke access at any time
- All their access is logged
Managing Caregiver Access
- Go to Settings > Caregivers or Family Access
- View currently authorized caregivers
- Click Remove to revoke access
- Click Add Caregiver to authorize someone new
Data Export
You can download all your data:
- Go to Settings > Privacy > Export Data
- Select what to export (medications, doses, all data)
- Click Export
- Download the file when ready
Account Deletion
To permanently delete your account:
- Go to Settings > Privacy > Delete Account
- Read the warning carefully
- Enter your password to confirm
- Click Delete My Account
Warning: This permanently deletes all your data and cannot be undone.
Security Tips
- Don't share your password with anyone
- Use a password manager to store complex passwords
- Log out on shared computers when done
- Keep your email secure (it's used for password resets)
- Review caregiver access periodically
- Report suspicious activity to support immediately
See Also
- Push Notifications - Configure alerts
- PWA Installation - Install the app securely