LEGAL

Privacy

SimHealth is a hosted generator of synthetic FHIR R4 data for healthcare software developers and QA. It is not a clinical system and does not process real patient records (PHI).

What this site collects

The public pages are static HTML. Standard HTTPS request logs on Google Cloud Run may include IP address, user agent, and requested path for operations and abuse prevention.

Log in and sign up use Firebase Authentication on GCP project bs-freelance (email and password, or Google). Firebase stores the account email and authentication metadata. Google sign-in shares the Google account email with SimHealth. We do not use those accounts for clinical care. Do not use a password you reuse on systems that hold real patient data.

After sign-in, SimHealth stores a per-account profile and generator settings (display name, default seed, default count, last app panel) in Cloud Firestore database simhealth on the same project. That document is keyed by the Firebase uid and is readable and writable only by that signed-in user. We do not copy email into Firestore. We do not store API keys, destination URLs, or FHIR payloads there.

We do not use Google Analytics or Firebase Analytics. The Firebase web app is Authentication and Firestore for account settings. Product usage (generate, inspect, send) is recorded as first-party structured logs in Google Cloud Logging: request, tenant or workspace, artifact identifiers, scenario, and outcome. Logs do not include FHIR Bundle contents, API keys, bearer tokens, seeds, or destination URLs.

The API

The product API is an open sandbox. Workspaces and API keys, when issued, are tenant-scoped. Do not send production credentials or real patient data to SimHealth. Generated resources are labeled synthetic and are not diagnosis or evidence of care.

Contact

Questions: use the operator of interoperabilitypro.com / the SimHealth project owner. This notice covers the public site at simhealth.interoperabilitypro.com.

← Back to SimHealth