QuestConnect.app

Security

HIPAA-grade controlsOAuth 2.0 patient authorizationEncrypted at rest

Security Overview

QuestConnect is built for healthcare workflow use and uses layered controls to help protect sensitive information.

Access Control

  • Role-based access
  • Page visibility by role
  • Limited access to authorized staff
  • Administrative review of users and permissions

Dexcom Authorization Security

Dexcom data sharing is opt-in. Patients authenticate directly with Dexcom using Dexcom's OAuth 2.0 authorization flow before QuestConnect can request Dexcom data. QuestConnect does not collect Dexcom usernames or passwords, and the authorization can be revoked through Dexcom account permissions.

Token Handling

Dexcom tokens are stored server-side, encrypted at rest, and are not stored in the browser or on a mobile device. Dexcom token values are treated as credentials and are not included in public pages, user-facing messages, or application logs.

Encryption and Transport

  • HTTPS
  • Secure backend communication
  • Encryption in transit
  • Encryption at rest where configured
  • Dexcom API communication uses OAuth bearer token requests

Audit Logging

  • User activity logs
  • Access history
  • Change history
  • Security event tracking

Data Minimization

QuestConnect retrieves data needed for RPM workflow support. Dexcom data is used for retrospective review, glucose trend review, care coordination, documentation support, and billing readiness. It is not used for automated treatment decisions, insulin dosing recommendations, emergency monitoring, or immediate clinical action by patients or caregivers.

QuestConnect has applied for Dexcom production credentials. Until Dexcom separately approves production access to actual patient CGM data, QuestConnect's Dexcom developer access remains sandbox-only. Sandbox data is simulated CGM data and does not include actual patient data.

Dexcom API Compliance Reference

Dexcom describes the Dexcom API as calculating specified metrics from Dexcom CGM data and providing software developers with access to retrospective CGM data and CGM-derived metrics for use in software applications.

  • Product Name: Dexcom API
  • UDI / Device Identifier: 00386270000668
  • UDI / Production Identifier: Version 3.18.0.0
  • Date of Manufacture (DOM): 2026-04-23
  • Part Number (PN): 350-0019

Dexcom states that the Dexcom API is developed under Dexcom's quality management system. More information about independent verification of Dexcom's compliance controls is available through Dexcom's FDA Registration and Listing entry.

Record Retention and Logs

QuestConnect may retain security logs, access logs, and audit records to support compliance review, troubleshooting, and incident investigation. Retention periods may vary by record type and approved customer requirements.

Incident and Vulnerability Reporting

To report a security concern, contact support@questconnect.app.

Please use the subject line: Security Report.

No Unsafe Medical Use

QuestConnect is not an emergency monitoring system and does not provide insulin dosing recommendations or automated treatment decisions.