Transparency, accountability, and rigorous compliance with healthcare regulations. All policies are reviewed quarterly and updated as regulations evolve.
Last updated: February 1, 2026
By accessing or using the CUBE OneCare platform operated by CUBE Collective LLC, you agree to be bound by these Terms of Service. If you are using the Service on behalf of an organization, you represent that you have authority to bind that organization to these Terms.
CUBE OneCare is a cloud-based healthcare management platform providing patient portal, provider portal, administrative dashboard, FHIR R4 APIs, CUBE Assist AI, telemedicine, and clinical workflow tools. The Service processes, transmits, and stores Protected Health Information (PHI) as defined by HIPAA.
The Service is available to healthcare organizations, covered entities, business associates, and their authorized personnel. Users must be at least 18 years of age. Patient portal users may be minors with guardian authorization.
You are responsible for maintaining the confidentiality of your account credentials. You must immediately notify us of any unauthorized access. Multi-factor authentication (MFA) is mandatory for all accounts with access to PHI.
You may use the Service solely for lawful healthcare purposes including patient management, clinical workflows, administrative operations, and interoperability functions in compliance with applicable healthcare regulations.
You may not: (a) reverse-engineer or decompile the Service; (b) use it to process data unrelated to healthcare; (c) attempt to circumvent security controls; (d) share credentials or PHI with unauthorized parties; (e) use automated systems to scrape data outside approved API usage.
Starter and Professional plans target 99.9% monthly uptime. For Enterprise plans, the SLA and any service credits are agreed in the enterprise agreement. Scheduled maintenance windows are communicated 72 hours in advance.
The Service, including all software, algorithms, and designs, is the intellectual property of CUBE Collective LLC. Customer data remains the property of the customer at all times.
Either party may terminate with 30 days written notice. Upon termination, we provide 90 days to export your data in the platform's standard export formats. After the export period, PHI is deleted from active systems under our data-retention policy. The FHIR R4 API is experimental and is not offered for production clinical export.
To the maximum extent permitted by law, CUBE Collective LLC's total liability shall not exceed fees paid in the 12 months preceding the claim. We are not liable for clinical decisions made using the platform.
Last updated: February 1, 2026
We collect: (a) Account information (name, email, organization, role); (b) Clinical data entered by authorized users (PHI governed separately by HIPAA); (c) Usage analytics (anonymized interaction patterns); (d) Technical data (IP address, browser type); (e) Communication records (support tickets, contact form submissions).
Account information is used for authentication and account management. Clinical data is processed solely for Service delivery under HIPAA. Usage analytics improve the Service. We never sell personal information or PHI and do not use PHI for marketing or training AI models.
We share data only with: (a) Sub-processors necessary for Service delivery — each sub-processor's current DPA/BAA status is available on request and is not assumed for every vendor; (b) As required by law; (c) With explicit consent for integrations you configure. A current sub-processor list is available upon request.
PHI is retained per HIPAA minimum necessary requirements and customer-configured retention policies. Account data is retained for the service relationship plus 7 years. Usage analytics older than 24 months are automatically anonymized.
Data is encrypted at rest by the hosting platform and in transit (TLS 1.3). Field-level encryption with AES-256-GCM is applied to selected, high-sensitivity PHI fields. Access is controlled by RBAC with mandatory MFA. PHI access is logged in an insert-only audit log.
You have the right to: (a) Access your personal data; (b) Request correction; (c) Request deletion (subject to retention requirements); (d) Export your data in the platform's standard export formats; (e) Withdraw consent for non-essential processing; (f) Lodge a complaint with supervisory authorities.
The public website is not directed at children under 13. The patient portal supports minor patients through guardian-authorized access with appropriate consent mechanisms as required by HIPAA and state law.
Last updated: February 1, 2026
How medical information about you may be used and disclosed and how you can get access to this information. CUBE Collective LLC functions as a Business Associate and, for certain direct patient interactions, may function in a Covered Entity capacity.
We may use and disclose your PHI for treatment purposes — sharing your medical record with a healthcare provider treating you through the platform, delivering lab results, or facilitating prescription management.
We may use and disclose your PHI for payment activities including eligibility verification (EDI 270/271), claims submission (EDI 837), and remittance processing (EDI 835).
We may use PHI for operations including quality assessment, care coordination, provider credentialing, and platform security audits.
Right to inspect and copy your PHI (§164.524); Right to request amendment (§164.526); Right to an accounting of disclosures (§164.528); Right to request restrictions (§164.522); Right to a paper copy of this notice.
In the event of a breach of unsecured PHI, we will notify affected individuals within 60 days per 45 CFR §164.404, notify HHS per §164.408, and if 500+ individuals are affected, notify prominent media per §164.406.
Privacy Officer: the secure privacy contact form. You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.
Last updated: February 1, 2026
When PHI is involved, CUBE Collective LLC signs a Business Associate Agreement (BAA) with the customer as HIPAA requires; terms and timing are agreed in the contract. No plan includes a customer BAA and none is signed automatically.
Where a BAA is signed, it covers all PHI processed, stored, or transmitted through CUBE OneCare, including: patient records, clinical notes, lab results, prescriptions, billing data, imaging reports, appointment records, and telemedicine session recordings.
Our BAA obligations flow down to sub-processors that access PHI. Each sub-processor's own agreement status is recorded in the sub-processor annex; CUBE has signed a BAA with Stedi (clearinghouse), and the remaining sub-processor BAAs, including hosting, are pending; they will be published in the CUBE control panel when available, and until then OneCare does not process real PHI.
To request a BAA, contact us through the secure compliance contact form or the Contact page. Signed agreements are made available to the customer once executed.
Last updated: February 1, 2026
This DPA applies to the processing of personal data of data subjects in the EEA, UK, and Switzerland. CUBE Collective LLC acts as a Data Processor on behalf of the Controller (customer organization).
We process personal data under: (a) Performance of contract (Article 6(1)(b)); (b) Legitimate interests (Article 6(1)(f)) for security; (c) Legal obligation (Article 6(1)(c)); (d) Consent (Article 6(1)(a)) where explicitly provided.
CUBE services and customer data are hosted in the United States; EU data residency is not offered today. Where a transfer outside the EEA is required, the applicable safeguard is agreed and executed in the contract; no SCC instrument is in place today and no EU data-residency option is offered.
No standalone DPIA is maintained for high-risk processing activities today.
Our DPO can be contacted through the secure privacy contact form for GDPR-related inquiries, data subject requests, or concerns about our processing activities.
Last updated: February 1, 2026
CUBE OneCare is a product of CUBE Collective LLC, a limited liability company organized under the laws of the State of Wyoming, USA. Our registered office is located at 30 N Gould St. Ste. R, Sheridan, WY 82801, USA.
These terms are governed by the laws of the State of Wyoming, without regard to conflict of law provisions. Disputes shall be resolved in state or federal courts in Wyoming, unless otherwise required by applicable consumer protection laws.
CUBE Collective LLC is not a healthcare provider, health plan, or healthcare clearinghouse under HIPAA. We function as a Business Associate providing technology services to Covered Entities. Our platform is a software tool and does not render medical advice, diagnosis, or treatment.
CUBE Collective LLC may engage authorized agents and distribution partners in jurisdictions outside the United States. Such representatives act under binding agreements requiring compliance with applicable data protection and healthcare regulations.
Last updated: February 1, 2026
Testimonials, reviews, ratings, case studies, and customer quotes displayed on CUBE OneCare materials may be: (a) anonymized; (b) aggregated from multiple sources; (c) illustrative composites representing typical experiences; or (d) fictionalized for demonstrative marketing purposes. Names, titles, and statistics may not correspond to real individuals or entities.
All performance metrics and outcomes cited in marketing materials represent targets, estimates, or results observed under specific conditions. Individual results may vary. Past performance does not guarantee future results.
CUBE Assist AI, HealthScore, AI Plan Recommender, Lab AI, Risk Scoring, and all other AI-powered features are decision-support tools only. They do not constitute medical advice, clinical diagnosis, or treatment recommendations.
Marketing materials may contain forward-looking statements regarding planned features, integrations, certifications, or market expansion. Such statements reflect current expectations and are subject to change.
Last updated: February 1, 2026
CUBE Collective LLC is a Wyoming-based entity providing cloud-based healthcare technology services worldwide. While our corporate headquarters and legal jurisdiction are in the United States, CUBE OneCare is designed to serve healthcare organizations in multiple countries.
For international customers, CUBE Collective LLC may engage local authorized agents or implementation partners to provide localized support and onboarding. All agents operate under binding agreements requiring compliance with data protection and healthcare regulations.
The platform is designed to support compliance with HIPAA (US), GDPR (EU), LGPD (Brazil), and other applicable frameworks. Customers are responsible for determining regulatory applicability and configuring the platform accordingly.
Customer support is provided through CUBE Collective LLC staff and authorized support partners. First-tier support may be handled by trained representatives. Escalated and PHI-related support is handled exclusively by CUBE Collective LLC personnel bound by BAAs.
Last updated: February 1, 2026
Protected Health Information (PHI) includes any individually identifiable health information created, received, maintained, or transmitted through CUBE OneCare including patient demographics, clinical records, lab results, prescriptions, appointment data, billing records, and telemedicine recordings.
Access to PHI is governed by the HIPAA Minimum Necessary standard. Role-based access controls (RBAC) ensure users access only the PHI required for their authorized functions. All PHI access is logged.
Selected PHI fields are encrypted at the application layer using AES-256-GCM and in transit using TLS 1.3. Field-level encryption (FLE) is applied to high-sensitivity elements. Encryption keys are held in the hosting platform's secret store; there is no customer-managed KMS rotation schedule today.
Upon contract termination, customers have 90 days to export their data in the platform's standard export formats. After the export period, PHI is deleted from active systems under our retention policy. The FHIR R4 API is experimental and is not offered for production clinical export.
Incidents are reviewed and handled by the engineering team; no 24/7 SOC service and no contractual detection or containment times are offered today. A breach of unsecured PHI is notified to affected individuals without unreasonable delay and no later than 60 days, per 45 CFR §164.404.
Last updated: February 1, 2026
CUBE Collective LLC maintains a risk-assessed inventory of all sub-processors that access, process, or store customer data. Each sub-processor undergoes security assessment prior to engagement and annually thereafter. Sub-processors with access to PHI are required to execute BAAs.
Incidents are reviewed and handled by the engineering team; no 24/7 SOC service and no contractual detection or containment times are offered today. A breach of unsecured PHI is notified to affected individuals without unreasonable delay and no later than 60 days, per 45 CFR §164.404.
Sub-processors are evaluated against: (a) SOC 2 Type II or equivalent certification; (b) Data residency and transfer mechanisms; (c) Encryption standards; (d) Incident response capabilities; (e) Business continuity plans; (f) Applicable regulatory requirements.
CUBE Collective LLC monitors concentration risk across its sub-processor portfolio. Critical services have designated fallback providers. Infrastructure runs in a single United States region today; no multi-region deployment is offered.
Last updated: February 1, 2026
By default, customer data and PHI are stored in US-based cloud regions. CUBE maps hosting controls and subprocessor evidence to SOC 2, ISO 27001, and HITRUST CSF requirements; formal certification status is tracked in the Trust Center.
EU-hosted deployment is not currently offered. All CUBE services run in a United States region, and customer data and PHI are stored there. If EU data residency is a requirement, raise it before contracting; we will tell you plainly that it is not available today.
CUBE services and customer data are hosted in the United States; EU data residency is not offered today. Where a transfer outside the US is required, the applicable safeguard (for example Standard Contractual Clauses) is agreed and executed in the contract before the transfer; no SCC instrument and no transfer-impact assessment is in place today.
Last updated: February 1, 2026
CUBE OneCare is a cloud-based SaaS platform accessible via modern web browsers and mobile devices. The Service requires an active internet connection. Offline functionality is limited to cached data viewing in the patient portal PWA.
The platform is not designed for: (a) Life-critical or real-time patient monitoring; (b) Direct emergency dispatch or 911 integration; (c) PACS image hosting or DICOM viewer; (d) Pharmacy dispensing system management; (e) Regulatory submissions to FDA or EMA.
Starter/Professional plans: 99.9% monthly uptime target. Enterprise plans: the SLA and any service credits are agreed in the enterprise agreement. Scheduled maintenance windows communicated 72 hours in advance. Real-time status available on the platform status page.
Supports the two most recent major versions of Chrome, Firefox, Safari, and Edge. Mobile: iOS 15+ and Android 12+. Internet Explorer not supported. Minimum bandwidth: 5 Mbps for telemedicine, 1 Mbps for all other features.
Last updated: February 1, 2026
CUBE Collective LLC is committed to ensuring digital accessibility for people with disabilities. The CUBE OneCare platform is designed to support conformance with WCAG 2.1 Level AA and Section 508 of the Rehabilitation Act.
The platform includes: (a) Semantic HTML with proper heading hierarchy; (b) ARIA landmarks, labels, and live regions; (c) Keyboard-navigable interfaces with visible focus indicators; (d) Skip-to-content links; (e) Color contrast ratios meeting WCAG AA; (f) Screen reader compatibility with NVDA, VoiceOver, and JAWS.
We conduct regular accessibility audits using automated tools (axe-core, Lighthouse) and manual testing. All new features undergo accessibility review before release. Our engineering team receives ongoing accessibility training.
If you encounter accessibility barriers, contact the accessibility contact form. We aim to respond within 5 business days and resolve identified barriers within 30 days where feasible.
Last updated: February 1, 2026
CUBE OneCare includes AI-powered features under CUBE Assist AI: appointment scheduling suggestions, symptom triage, clinical documentation assistance, automated coding suggestions, population health risk stratification, and patient message triage. These features use machine learning to assist — not replace — clinical decision-making.
CUBE Assist AI is an informational tool only. It does not provide medical diagnoses, treatment recommendations, or clinical orders. All AI outputs are clearly labeled as AI-generated and require clinician review before any clinical action is taken.
CUBE Assist AI models are trained on de-identified, publicly available medical literature and clinical guidelines. We do not train AI models on customer PHI. Customer data is processed by AI features only during active use sessions and is not retained for model training.
All AI features include: (a) Per-engine kill-switches; (b) Risk-tier classification with human-in-the-loop required for High and Critical tiers; (c) Complete audit trails; (d) Configurable confidence thresholds below which AI outputs are suppressed.
Last updated: February 1, 2026
The information provided through CUBE OneCare, including content generated by CUBE Assist AI, is for informational and administrative purposes only. It is not intended to substitute for professional medical advice, diagnosis, or treatment. Always seek the advice of your physician or other qualified health provider.
Use of the CUBE OneCare platform does not create a doctor-patient relationship between CUBE Collective LLC and any user. The platform facilitates connections between patients and their healthcare providers but does not itself provide medical care.
The CUBE OneCare platform is not designed for medical emergencies. If you are experiencing a medical emergency, call 911 (or your local emergency number) immediately. Do not rely on the platform's messaging or AI features for urgent medical needs.
Clinical decision support features are designed to supplement — not replace — the clinical judgment of licensed healthcare professionals. Healthcare providers remain solely responsible for all clinical decisions regarding patient care.
Last updated: February 1, 2026
CUBE OneCare's current sub-processors, their purpose, the data they touch and where they operate are listed in full in the sub-processor annex, which is the authoritative record. Large healthcare institutions requiring a dedicated, compliance-hardened deployment may choose CUBE's white-label option, scoped and contracted separately.
Business Associate Agreements are required with every sub-processor that may process PHI. Sub-processors that do not handle PHI operate under standard data processing agreements with appropriate security requirements.
Customers are notified at least 30 days in advance of any new sub-processor being added. Customers may object within the 30-day notice period; if unresolved, the customer may terminate their agreement.
All PHI is processed and stored within the geographic region specified in the customer's agreement. US customers: data in Fly.io's United States region. EU customers: data in a Fly.io European region, confirmed per engagement. Cross-region transfer occurs only with explicit consent and appropriate safeguards.
Last updated: February 1, 2026
This Acceptable Use Policy governs the use of the CUBE OneCare platform and all related services. It supplements the Terms of Service and applies to all users including administrators, clinicians, staff, and patients.
Users may not: (a) Upload malicious code; (b) Attempt unauthorized access to systems or data; (c) Harass, threaten, or defame others; (d) Share PHI in violation of HIPAA; (e) Use the platform for non-healthcare purposes; (f) Conduct penetration testing without written authorization; (g) Resell the Service without a partner agreement; (h) Use bots or scrapers outside approved API access.
Violations may result in: (a) Warning and corrective action request; (b) Temporary suspension; (c) Permanent termination; (d) Reporting to law enforcement where required. CUBE Collective LLC may investigate suspected violations and take action without prior notice where necessary.
Suspected AUP violations should be reported to the secure security contact form. For security vulnerabilities, use subject line 'Security Vulnerability Report'. We acknowledge all reports within 24 hours.
For legal inquiries, compliance questions, or policy clarifications, contact our team.