Ponce Core Tech · Bimini

Bimini and your hospital

Published 17 September 2026 · Bimini is in limited, invitation-only beta, and the hospital connection described here is in development.

Bimini is a personal health application made by Ponce Core Tech, LLC. A member brings together their own wearable data, lab results, uploaded reports and, where they choose, records from their hospital, and Bimini organizes them into a clear summary the member can take to their own physician. Bimini is not a medical device. It does not diagnose, treat, or prescribe, and it is not medical advice.

This page explains how Bimini connects to a hospital's record system, in plain language for members first and in technical terms for hospital IT and compliance staff second.

If you are a member

You sign in to your hospital, not to us. When you connect a hospital in Bimini, the app opens your hospital's own sign-in page. You enter your patient-portal username and password there, on the hospital's page, the same way you would in a browser. Bimini never sees your password and never stores it.

What Bimini reads. Only what you authorize on the hospital's permission screen: your lab results and your clinical notes, such as imaging reports, echocardiogram reports and discharge summaries. Bimini reads; it never writes anything into your hospital record.

Where the work happens. Each document is processed on your own phone. Direct identifiers such as names, dates of birth, addresses, phone numbers and record numbers are found and removed on the device before any text is sent to Bimini's servers. What our servers hold is an identifier-reduced record under an account number, encrypted, in the configuration described in our Privacy Policy.

You can disconnect at any time. Disconnecting a hospital in the app deletes the hospital's access token from your phone. You can also revoke Bimini's access from your patient portal, and you can ask us to delete your Bimini account at any time.

Honest limitation. Not every hospital makes clinical notes available through the patient-access interface, and some make only the note's title and date available. Where that is the case, Bimini will tell you which notes it could not read rather than reporting success.

If you work in hospital IT, security, or compliance

Bimini is a patient-facing application that connects to a certified electronic health record's patient-access API using SMART on FHIR, at the patient's own request and under the patient's own login.

Developer
Ponce Core Tech, LLC
Application
Bimini (iOS, bundle identifier life.bimini.app)
Audience
Patients; standalone launch from the app
Authorization
OAuth 2.0 authorization code with PKCE (S256), public client. No client secret is held on the device. No refresh tokens are requested.
Redirect URI
bimini://hospital
FHIR version
R4 (US Core)
Resources requested
Patient (read); DocumentReference (read, search; clinical notes); Binary (read; clinical notes). Read only.
Data handling
Note bodies are processed on the patient's device. Direct identifiers are found and removed on the device before any text is transmitted. Access tokens are stored in the device keychain, scoped to one organization, and are never transmitted to Ponce Core Tech.
Server side
Amazon Web Services under a Business Associate Addendum; data encrypted at rest and in transit; per-account row-level access control. Details in the Privacy Policy.
Policies
Privacy Policy · Terms of Service
Contact
[email protected] for onboarding, security questions, or to report a concern

We are glad to complete your organization's application vetting process, provide a security description, and test against a non-production environment before any patient connects.

Contact

[email protected]

Ponce Core Tech, LLC