HashCare answers it with evidence instead of assurance. A record is fingerprinted — a 64-character SHA-256 hash that breaks if a single character changes. The fingerprint goes into a public registry with a timestamp, and the registry's whole root is countersigned into Bitcoin every day. The document itself never leaves your device. You do not have to trust us on any of that: the recipe for checking us — without an account, a node, or our permission — is published.
The accountability chain
Today’s actual registry root
reading /roots/latest.json…
Not an illustration. This is the live root of the public registry, read from /roots/latest.json as this page loaded — the SHA-256 of every fingerprint anchored to date, sorted and joined. Recompute it yourself →
Try to break it
Here is a single care event — a caregiver's visit note, sealed with a real SHA-256 hash the moment it was signed. Change one character and watch the fingerprint break. A family or a payer can run this same check and know, instantly, whether a record is the one the caregiver actually signed.
Sealed by the caregiver at sign-off. Edit any field below to simulate an after-the-fact change to the record.
This runs entirely in your browser using the Web Crypto API (SHA-256) — nothing is uploaded. In production, the sign-off hash is anchored in the public HashCare registry and countersigned into Bitcoin daily, so the comparison can be made by anyone, years later, against a record no one can quietly rewrite.
Two records. One question.
Edit either record below. Watch the fingerprint break in real time. This is exactly how a family, a payer, or an OIG auditor would verify a disputed care note.
In production, the signed hash is anchored in the public HashCare registry and countersigned into Bitcoin daily via OpenTimestamps. Any party — family, MCO, OIG — can run this comparison against the anchored fingerprint without asking anyone for permission.
How It Works
This is the whole mechanism. It is deliberately small, because a proof you cannot check yourself is just a claim with extra steps.
What Gets Anchored
A site about provenance does not get to be vague about its own. Below, every capability is labelled by whether it is actually anchoring records today. The counter is read live from the registry — it says what it says.
This is a small number, and we publish it rather than imply a larger one. The registry opened in July 2026 and everything in it is still ours. What changed on 2026-09-04 is that it stopped being a static list: the physician review loop now writes a receipt for every determination it issues, and those receipts land here automatically. They are synthetic pilot cases — no BAA is executed anywhere in this estate, so no real patient record has been near it — but the path from a signed determination to a publicly checkable fingerprint now runs end to end without anyone deciding to publish it. Verify the count against the raw list → · Read the errata →
Anyone can anchor any document right now — a manuscript, a dataset, a signed agreement, a photograph, a contract you do not want to show anyone. It is hashed in your browser, so we never see the content. No account, no payment, no permission. This is the part of HashCare that works today for a stranger who does not trust us at all.
Anchor a document →The Five Tests of a Real Review — licensed and matched, independent, engaged and measured, receipted, durable — published free for anyone to use or fork. The canonical text is itself anchored in this registry, so the standard cannot be quietly edited after the fact. Version 1.0, integrity-protected by its own content hash.
Read the standard →Every day, unattended, the registry root is stamped into Bitcoin via OpenTimestamps and the proof is committed publicly. Nothing here depends on this company continuing to exist: if HashCare disappears tomorrow, every proof issued before then remains checkable by anyone, forever, using open tools we do not control.
See the recipe →The design: when a physician reviews and attests to an AI-drafted note, LMN, or prior auth, the event is hashed at signing — approval, revision, or decline, each with its rationale. A signature proves who signed; the record of revisions and honest declines is what proves someone actually looked. Not just who signed, but how deeply. The review loop runs today at ClinicalSwipe; its attestations are not yet written into this registry.
ClinicalSwipe →The design: caregiver shift notes, care goal updates, and Letters of Medical Necessity hashed at issuance and again at sign-off, so the two-hash chain shows the document was not altered in between — family-owned and checkable by any authorised party without asking a platform's permission. Built as a pattern, not yet wired into these products.
co-op.care →The design: when an AI recommends a provider, a pathway, or a purchase, it is routing care. Anchoring the routing event — what was recommended, on what basis, by which model version — is what would make conflict-of-interest review possible at all. A platform cannot audit its own routing; a receipt can. This one matters most and exists least.
SurgeonValue →SolvingHealth Ecosystem
HashCare is the receipt layer for the SolvingHealth products below. Each one has a real accountability problem this is meant to close — and each is described here by the problem, not by an integration that is not finished. The counter above is the honest measure of how far that has got.
The physician review loop: an AI drafts, a named and specialty-matched physician signs or declines. Live and running. The attestation-anchoring rail is designed and not yet wired.
clinicalswipe.comA QR-accessible emergency profile for a caregiver or paramedic to read at the door. Where a stranger has to trust a record on sight, a fingerprint is the natural fit.
comfortcard.orgWorker-owned care with family-owned records. The families, not the platform, should be able to prove what a shift note said — which is the whole argument for a receipt they can check without us.
co-op.careSurgeon-side encounter and billing work, where a claim signed under a physician’s own NPI is the thing that has to hold up later. The strongest case for anchoring at ingestion, and the next one to build.
surgeonvalue.comThe licensed reviewers whose signatures anchor here. NPI-verified, specialty-matched, paid per review — join the network that signs what AI drafts.
altru.care/physiciansThe physician-governed harness for engineering teams, exposed as narrow MCP tools rather than open-ended access. Synthetic and test data only — no BAA is in place, so no protected health information goes through it.
harnesshealth.ai/developersShow the chain
If your product anchors its records to HashCare, say so. Paste the snippet below anywhere HTML renders — no JavaScript, no dependencies, one link back to the audit layer.
<a href="https://hashcare.com" target="_blank" rel="noopener"
style="display:inline-flex;align-items:center;gap:7px;padding:7px 13px;
background:#131f38;border:1px solid rgba(13,115,119,0.5);
border-radius:8px;font-family:Arial,Helvetica,sans-serif;
font-size:12px;font-weight:700;color:#14a4a9;text-decoration:none;">
<svg width="13" height="13" viewBox="0 0 22 22" fill="none" aria-hidden="true">
<path d="M11 2L3 6v6c0 4.8 3.2 9.3 8 10.4C16.8 21.3 19 16.8 19 12V6l-8-4z"
stroke="currentColor" stroke-width="1.75" stroke-linejoin="round"/>
<path d="M7.5 11.3l2.4 2.4 4.6-4.8" stroke="currentColor" stroke-width="1.75"
stroke-linecap="round" stroke-linejoin="round"/>
</svg>
Verified by HashCare
</a>
A manuscript before you send it. A dataset before you publish. A signed agreement, a photograph, a clinical protocol, a disclosure you may one day need to date. It is hashed in your browser, so the document never leaves your device and we never see it — and the timestamp holds even if this company does not.
Anchor a documentNot a clinical signature, not a copyright registration, not legal advice. It proves a document with that exact fingerprint existed at that time — nothing more, and nothing less.
Building something that needs receipts for physician review? The rail is being built in the open. Leave an address and you will hear when it is real — not before.
No spam, no drip sequence, no cohort urgency.