Your children's medical reports and documents online: why encryption isn't a detail
The whole family, in a single app.
The family organiser for iPhone, Android and the browser, end-to-end encrypted. Free for a family of two parents.
Almost every family has done these at least once: photographed a medical report and sent it by chat to the other parent, saved a child's ID card to a free cloud, emailed blood test results around. It's convenient, and it's normal. But health data and children's documents are among the most sensitive information a family has, and it's worth understanding where they end up.
Why health data is special
Under the GDPR, data concerning health is a special category of personal data, with stronger protection. Not for bureaucracy's sake: a medical report says things that can't be changed the way you change a password. A diagnosis, a treatment, an allergy stay true forever. And when they concern a child, they concern someone who had no choice.
Where files usually go
- In chat: the file travels, then stays in the phone's gallery, in automatic backups, sometimes forwarded to a group by mistake.
- In email: it stays in both inboxes, for years, often with no extra protection.
- In a generic cloud: it's protected by the account login, but the provider can technically access the files.
None of these is wrong in itself. The problem is that files multiply in different places, and nobody knows how many copies exist any more.
What "encrypted" really means
The word "encrypted" is used for very different things:
- Encrypted in transit: the file is protected while travelling, then readable on the server by whoever runs the service.
- Encrypted at rest: the file is encrypted on the provider's disks, but the provider holds the key.
- Client-side encrypted (or end-to-end): the file is encrypted on your device before it leaves, with a key the provider doesn't have. The servers only hold unreadable data.
Only the third guarantees that not even the people running the app can read your documents.
How it works in KidBox
In KidBox documents, notes, passwords, wallet, photos and videos and the chat are encrypted with a family key generated on your devices. Reports attached to visits in the health section are documents like any other, so encrypted the same way; health records are accessible only to family members. The servers see bytes, not content.
Two practical consequences worth knowing:
- Notifications don't show previews of encrypted content: the server can't read it to write them.
- The key is recovered by signing in: when you change phone your data is readable again, but the account needs strong protection.
Good habits, whatever tool you use
- One place for health documents, instead of scattered copies in chat and email
- Protect the account with a strong, unique password
- Share with those who need it: both parents yes, wider groups no
- Delete the copies sent by chat once the document is filed
In short
Health data and children's documents deserve more care than a photo in a chat. Understanding the difference between encryption in transit, at rest and client-side helps you choose where to keep them. The most useful rule stays simple: one place, well protected, shared with those who need it.
The tools this article talks about
Read next
The family health record: what to keep, how to organise it and when it really matters
A night in A&E, a new paediatrician, a specialist asking for tests from two years ago. What to keep about each family member's health, and how to find it in thirty seconds.
Family documents in order, once and for all
A three-level method — folders, records, wallet — to never search for a document again, and why encryption isn't a detail.
Sharing location as a family without it feeling like surveillance
Knowing your child got to school without calling, and without turning it into monitoring: rules, automatic alerts and time-limited sharing.