CareVault
CareVault is a privacy-first Flutter healthcare application designed around a simple principle: patients should have control over their own health information . The application allows patients to manage their health profiles and records, grant specific healthcare providers access to selected categories of information for a defined period, revoke access at any time, and review how their information has been accessed. CareVault supports three distinct roles - Patient, Provider, and Administrator . Patients manage their own records and consent decisions, providers can access only currently authorized information, and administrators handle user management, consent oversight, and formal data requests. The application emphasizes data minimization, granular consent, role-based authorization, auditable access, and Firestore-level security enforcement . From a compliance perspective, CareVault demonstrates GDPR-style privacy principles and HIPAA-relevant healthcare data protection and security practices , including patient-controlled consent, granular access control, auditability, data export, and controlled deletion workflows. CareVault is a portfolio and learning project and is not formally HIPAA- or GDPR-certified/compliant . It should not be used with real personal health information without additional legal, security, infrastructure, and regulatory assessment.





Challenges & solutions
The technical problems our team solved to ship a reliable, unified mobile experience.
A revoked consent should no longer authorize provider access.
The project operates without Cloud Functions or server-side triggers.
Audit events need to capture the actor, role, timestamp, action, and result without a dedicated server middleware layer.
Patients need a controlled way to obtain their information and request deletion without introducing unsafe immediate deletion.
Patients, providers, and administrators require completely different workflows and access levels.
Key features
What users get in the finished, shipped product.
Patient Health Profile & Records :
- Profile : Allows patients to manage their basic profile information and healthcare details.
- Records : Supports medical conditions, medications, lab results, and health metrics within the patient's authorized data scope.
Granular Consent Management :
- Provider : Patients can specify which healthcare provider can access their information.
- Purpose : Each consent defines the purpose of access and specific authorized data categories.
- Expiry : Supports time-limited consent with a defined expiry date and consent status.
Immediate Consent Revocation :
- Revocation : Patients can revoke provider access at any time.
- Authorization : Protected data requests re-evaluate consent status, preventing revoked or expired consent from authorizing new reads.
Consent History :
- Records : Retains consent decisions as historical records instead of silently removing them.
- Status : Clearly distinguishes between Active, Expired, and Revoked consents.
Provider Access Control :
- Authorization : Providers can only access patients with an applicable consent relationship.
- Categories : Access is restricted to the specific health-data categories authorized by the patient.
- Scope : Supports category-level access instead of unrestricted patient-record access.
Audit History :
- Tracking : Records successful access, denied access, error events, consent changes, and data-related actions.
- Review : Patients and administrators can review audit history for accountability and traceability.
Privacy Center & Data Rights :
- Export : Allows patients to export their information as a PDF document.
- History : Provides access to review access history and consent history.
- Deletion : Allows patients to submit an account-deletion request.
Administrative Dashboard :
- Management : Administrators can manage users, user roles, consent records, data requests, and account status.
- Oversight : Provides centralized oversight of privacy and data-management activities.
- Audit Logs : Allows administrators to review audit logs for data-access and privacy activities.
Firestore-Level Authorization :
- Security : Enforces authorization at the Firestore Security Rules layer rather than relying only on application UI or navigation.
- Verification : Security rules verify user identity, user role, account status, active consent, consent expiry, and authorized data category.
- Protection : Prevents restricted data from being accessed simply by bypassing the application interface.
Tech integrations
Third-party SDKs & libraries
9 core integrations powered
firebase_core
Core system integration
firebase_auth
Core system integration
cloud_firestore
Core system integration
get
Core system integration
go_router
Core system integration
intl
Core system integration
Core system integration
printing
Core system integration
cupertino_icons
Core system integration
Similar Projects We've Built

TrueGlow AI – AI-Powered Skincare App
TrueGlow AI is an advanced AI-powered skincare application designed to analyze skin conditions directly from a user’s photo and provide personalized skincare insights in seconds. Using intelligent image analysis, the app detects concerns such as acne, pigmentation, dryness, oiliness, pores, dark circles, and uneven skin tone, helping users build smarter and more effective skincare routines. […]

CareBot AI – AI-Powered Doctor Appointment Booking
CareBot AI is an intelligent conversational healthcare platform designed to simplify and automate doctor appointment booking through AI-driven chat interactions. Users can describe their symptoms in natural language, and the system instantly identifies the appropriate medical specialist, checks real-time appointment availability, and completes the booking process within a single conversational interface. The platform eliminates traditional […]

Ashmi Health
Ashmi Health is a digital healthcare and wellness platform designed to provide users with access to personalized health services, consultations, and wellness tracking tools. The platform integrates modern digital health practices with user-centric design to support preventive care, lifestyle management, and ongoing health monitoring. It appears to focus on delivering accessible healthcare solutions, potentially including […]

EatTrainTrack: Calorie Counter
EatTrainTrack is an AI-powered health and fitness tracking application designed to simplify nutrition logging, meal planning, and workout monitoring. The app enables users to track their daily food intake, calories, and physical activities using intelligent automation such as photo recognition, voice input, and AI-based analysis. It is built to support users aiming for weight loss, […]
Have a similar idea? Let's build it
together.
From concept to launch, we turn your vision into a world-class product.