Source-backed · private by design

Redacted files stay in your browser. Live health and medicine context comes from NLM and FDA sources; price and coverage context comes from CMS, Medicaid.gov, and official carrier tools.

Methodology & safety

Trust is built from
visible boundaries.

Care Navigator AI is designed to be useful without pretending to know more than its sources—or more than an educational tool can safely know.

01

What the product does

It searches live National Library of Medicine sources for common and rare conditions, finds medicine names and other candidate terms in a redacted document on the visitor's device, retrieves official FDA/DailyMed label sections for a confirmed medicine, queries Cigna's official public directory, routes other carrier searches through plan-aware official directories, retrieves CMS and Medicaid cost benchmarks, compares user-verified pharmacy quotes, and builds a source-linked 30-day conversation planner.

02

What it does not do

It does not diagnose, prescribe, choose treatment, calculate or personalize a dose, interpret a lab for an individual, determine whether medicines are safe together for a specific person, tell someone to start or stop medicine, rank insurance plans, predict eligibility, or replace professional care. Label text is education, not an individualized instruction.

03

Source-selection policy

Consumer health search starts with NLM MedlinePlus and broadens to NLM MedGen for recognized disease concepts, including many rare conditions. PubMed supplies recent indexed reviews and guidelines as links, without turning article titles into medical advice. Confirmed medicines use openFDA label data and a direct DailyMed label. NIH GARD, ClinicalTrials.gov, and the nonprofit NORD directory are clearly labeled follow-up resources. Cost context uses CMS Medicare Part D and Medicaid NADAC data. Carrier results use official public or plan-aware directories. Displayed data URLs must use HTTPS and match a source-specific allowlist.

04

Safety before intelligence

A deterministic safety layer runs before any optional AI path. It flags clear emergency, crisis, and poisoning language and blocks direct answers to diagnosis, prescribing, dose, interaction, treatment-selection, and plan-ranking requests. Keyword detection is not comprehensive.

05

Privacy and data flow

Document extraction, OCR, and quote comparison run in browser memory and clear on refresh. The app has no account, health database, cookies, analytics, advertising, or session replay. Generic search terms, confirmed medication names, and ZIP codes reach site API routes and may appear in request URLs, platform logs, or short public-response caches; those generic inputs reach the named official services. The image or document itself is not sent. The interface tells visitors not to include personal information.

06

Local document boundary

The public file control accepts PDF, DOCX, common text formats, and PNG/JPG/WebP/GIF/BMP images up to 15 MiB, with no more than 12 PDF pages. Text extraction and English OCR happen in the browser. Photos are checked in four orientations, and the most readable result is parsed for bounded medication fields. Only a medicine name confirmed on screen is used for an official-label lookup; the file is never uploaded or stored. Visitors must compare the result with the original. Encrypted, unreadable, oversized, and unsupported files fail closed.

07

Known limitations and failure modes

No database contains every disease or guarantees perfect accuracy. Rare-disease names, synonyms, and evidence change; MedGen and GARD can be incomplete, and a PubMed record is not a clinical recommendation. Official services can fail or return stale, duplicate, or mismatched records. OCR can misread text, and an FDA label may not list every person-specific risk or interaction. A provider listing cannot prove current network status, and no universal public endpoint gives a person's exact pharmacy price. The interface exposes retrieval time, uncertainty, source links, and verification steps.

08

Future production requirements

A health-record product would need reviewed hosting, identity and access controls, consent, retention rules, privacy and compliance analysis, incident response, clinical governance, content review, abuse protection, monitoring, and clear accountability. Care Navigator does not claim HIPAA compliance and deliberately keeps document processing on-device.

Simplified public-product data flow
Generic queryDeterministic safety rulesAllowlisted official sourceValidated display · source + retrieval time