Health data does not only leak in hospital headlines. It leaks on a Tuesday: an unlocked phone on the sofa, a prescription screenshot in the family chat, a camera roll that uploads itself to a shared household account.

The useful question is not “is the app secure?” It is: who, in practice, can open what is on your phone?

Five habits that beat a padlock icon

  1. Lock the device with biometrics or a passcode. Without that, the rest is theatre. Every health app inherits the phone’s protection, or the lack of it.
  2. Do not send a prescription screenshot to the group chat. Too many people, the history never expires, and the image lands in everyone else’s camera roll.
  3. Watch automatic photo backup. A report photographed with the camera often follows the family album into the cloud. The report stops being only yours.
  4. Run the airplane-mode test. If the history vanishes without a signal, it is not on the device. It is on someone’s server, and the basement clinic is exactly where you need it.
  5. Fill in the lock-screen medical ID with allergies and medications. That is the opposite of a lock: a minimum visible to whoever has to treat you if you cannot unlock the phone. Everything else stays locked.

None of this requires a particular app. These are habits. The app only matters when you decide where the history lives.

How FichaMed helps

Appointments, clinicians, and notes stay on your device. There is no FichaMed account for day-to-day use, and the company does not receive a copy of your clinical content to “keep in our cloud.”

In practice, that changes three things:

  • Who can read it. Without the phone unlocked (and without the extra app lock), FichaMed staff cannot open your history, because it never reached them.
  • Where the copy lives. The normal flow does not send your chart to company servers. If you turn on the phone’s own system backup, the copy lives in your platform account, under that platform’s rules, not ours.
  • When you lose the phone. Recovery follows the device: a backup you made, or whatever the system stored. There is no “forgot your password, we will read your data and send it back.”

App lock asks for the device biometrics or passcode again after FichaMed goes to the background. It covers the unlocked phone on the table, not the lost phone, that is still the system lock.

You can export an on-device backup and keep it wherever you want. On iPhone, you can also keep an automatic copy in your own iCloud account.

If the larger question is a vendor cloud versus a history that stays on the phone, the next piece is what actually changes.


This is a guide to privacy habits and how the app stores data, not legal advice. Device settings and platform-account settings matter too.