Why We Build Certain Features Slowly — And Why That's a Good Thing

Families have asked: "When is voice logging coming? When will AI-powered summaries be ready?" The honest answer is: when we can do it right. Here's what that actually means — and why it matters for your child.

The data safety question we ask before every AI feature

Any time audio or text is processed using AI, a question must be answered before a single line of code is written: where does that data go, who can access it, and for how long? The wrong answer to any of those questions puts your family's privacy at risk. Many AI vendors process data on third-party servers, retain it for model training, and are not eligible for HIPAA Business Associate Agreements.

What HIPAA compliance actually means

Saying "we comply with HIPAA" is easy. Genuine compliance means data is encrypted at rest and in transit (not just one), access to health data is logged and auditable, data minimization is practiced, and Business Associate Agreements are in place with every vendor that touches protected health information. SPM Health Tech has a BAA with Google Cloud (Firebase).

Who built PANDAS Tracker

PANDAS Tracker was built by Kenneth Vignali — a PANDAS parent and cybersecurity professional with an M.S. in Cybersecurity and a Juris Master in National Security, Cybersecurity & Privacy Law, who founded his own cybersecurity advisory firm before building this app. The security architecture reflects that background, not just aspirational language.

Frequently Asked Questions

Why does PANDAS Tracker build new features slowly?
Every feature that touches sensitive pediatric health data must be architected with privacy, encryption, and access control in place before release. Moving fast with features means moving fast with risk to families.
Is PANDAS Tracker HIPAA compliant?
PANDAS Tracker follows HIPAA-aligned security practices including AES-256 encryption, TLS 1.3, Firebase Security Rules, audit logging, and a BAA with Google Cloud (Firebase).
Can PANDAS Tracker employees see my child's health records?
No. Firebase Security Rules enforce that only authenticated members of your family plan can read or write your child's health records. SPM Health Tech employees cannot access your family's records without an explicit, documented, auditable support request from the account holder.