(But it does. So we became that lawyer.)
Every institution that has ever treated you holds fragments of your medical history. Under GDPR Article 15 and HIPAA, you have the legal right to access all of it. We enforce that right.
The problem
Each one has different forms, different processes, and zero incentive to make it easy for you. Most people give up after the first phone call.
How it works
Without acta.bio
Google how to request medical records
Fill out 15 different forms
Wait 6-8 weeks per institution
Half of them don't respond
Give up (96% do)
With acta.bio
Sign one authorization
We send legal demands to every institution
They comply within 30 days
All your data, one vault check_circle
Your vault
End-to-end encrypted, zero-knowledge architecture. Your data is stored so that even we cannot read it.
We literally cannot see your data
It's your data. Take it wherever.
We never share it.
City General Hospital
GenomicsLab Inc.
BlueCrest Insurance
7
Sources
143
Records
100%
Retrieved
The marketplace
Pharmaceutical companies spend billions trying to find people like you. With acta.bio, they come to you — on your terms, at your price. You decide what to share, with whom, and for how long.
Research offer
$340Cardiovascular Outcomes Study
Read-only access · 12 months
Research offer
$1,200Genomic Biomarkers for Drug Response
One-time snapshot
Accepted
$580Longitudinal Diabetes Prevention Trial
Read-only access · 24 months
The obvious question
Fair question. Short answer: you don't have to. We use end-to-end encryption, which means we physically cannot access your data. Not "we promise we won't." We architecturally can't. The encryption keys live on your device, not on our servers.
Encrypted architecture
Your data is encrypted before it leaves your device. We store ciphertext. If someone broke into our servers, they'd get gibberish.
Legal fiduciary
We act as your legal representative. That means we have a legal duty to act in YOUR interest, not ours. If we screw you over, you can sue us. That's by design.
We make money only when you do
We take a cut of marketplace transactions. If you never sell access to your data, we earn nothing from it. Our incentive is always aligned with yours.
GDPR Art. 15 & 20 · EU-US Data Privacy Framework · Your data never sold without consent