Security & Trust

Built to clear the procurement review.

HIPAA-compliant by design. Patient-controlled data with full audit trails. BAAs available for practices, health systems, and enterprise customers.

§ I — At a glance

What's true today.

We treat security disclosures the way we treat clinical summaries — clear about what's live, transparent about what's on the way. Additional attestations will be added as they're completed.

§

HIPAA-compliant by design

Security Rule and Privacy Rule controls implemented across all production systems.

BAA available on request

Standard BAA template ready for practices, health systems, and enterprise reviews.

Patient-controlled data

Patients own their records. Export anytime. We never train external models on PHI.

Full audit trails

Every read, write, share, and export is logged. Available to covered entities under BAA.

§ II — Data flow

From upload to summary, visualized.

PHI enters through patient- or caregiver-initiated upload, is encrypted in transit and at rest, structured by our AI layer in a HIPAA-compliant cloud, and surfaced only to people the account holder has explicitly shared with.

Step 01 / Intake

Patient or caregiver upload

Files arrive over TLS 1.3 from the patient or caregiver's device, into their private account. We don't pull from EHRs by default.

Step 02 / Storage

Encrypted at rest, AES-256

US-based HIPAA-compliant cloud infrastructure. Key management through provider KMS with documented rotation policies.

Step 03 / Structuring

AI parses & organizes

OCR, parsing, and structuring run inside the same secure environment. We never use customer PHI to train external models.

Step 04 / Access

Role-based, audit-logged

RBAC for patients, caregivers, clinicians, and practice admins. Every access event logged with user, timestamp, and IP.

§ III — Controls

The full list.

For the IT and security teams who need to see the granular controls before procurement gives a green light.

01 / Encryption

TLS 1.3 + AES-256

TLS 1.3 in transit, AES-256 at rest. Provider KMS for key management with documented rotation.

02 / Access

Role-based access

RBAC across patients, caregivers, clinicians, practice admins. Granular sharing permissions on every document.

03 / Audit

Comprehensive logging

Every read, write, share, and export logged with user, timestamp, and IP. HIPAA-retention periods enforced.

04 / Residency

US-based

All PHI processed and stored within United States infrastructure. No cross-border processing.

05 / Auth

MFA + SSO roadmap

Email + password with optional MFA today. SAML / OIDC SSO available for enterprise tier.

06 / Backup

Encrypted backups

Documented RPO/RTO targets. Detailed recovery procedures shared under NDA with covered entities.

07 / AI safety

Clarity, not diagnosis

MediClarity supports clinical decisions — it does not diagnose, treat, or prescribe. Aligned with FDA CDS guidance.

08 / Incident response

HIPAA breach notification

Documented procedures aligned with HIPAA breach notification rules. Covered entities notified per BAA terms.

§ IV — Transparency

Things we're not, today.

Honesty here matters more than a feature list. If any of these are blockers for your procurement, tell us — we'll be straight with you about timelines.

We don't pull data directly from EHRs today. Data enters MediClarity via patient-initiated upload and connected consumer devices. Direct FHIR / HIE connectivity is on the roadmap.

We don't write data back to EHRs today. Summaries are generated as outputs to read or paste, not pushed into external systems.

We don't currently hold third-party security attestations. Additional certifications will be added as they're completed — and we'll add them to the at-a-glance grid above with a real auditor-supplied target date, not a marketing guess.

We're not a replacement for clinical chart review. MediClarity supports the clinician's review. The clinician remains the decision-maker.

We'd rather under-promise on the security page than oversell what isn't yet attested. — MediClarity engineering
§ V — Procurement pack

What you can request under NDA.

For practices and enterprise reviews, we share the procurement pack via a single signed PDF + a private security-documentation page.

Document 01

Business Associate Agreement

Standard BAA template ready to send. Customized terms available for enterprise contracts under separate negotiation.

PDF · 12 pages · standard HHS template
Document 02

Security architecture overview

Data flow diagrams, infrastructure topology, encryption boundaries, and the subprocessor list. The thing your CISO will actually read.

PDF · 18 pages · technical detail
Document 03

Incident response policy

Detection, escalation, containment, notification, and post-incident review procedures aligned to HIPAA breach rules.

PDF · 9 pages · referenceable runbook
Document 04

Insurance & pen-test summary

Most recent penetration test summary (when available) and current cyber-liability coverage. Updated as scans complete.

PDF · 6 pages · auditor-readable
§ VI — Patient privacy

The patient owns the record.

If you're a patient or caregiver using MediClarity directly, your records belong to you. Always.

§

You decide what to upload

Records, devices, sharing — every input is controlled at the account level by the patient or their designated caregiver.

Export anytime

Full timeline and source documents available for export in standard formats at any time, including after cancellation.

Never sold or shared for ads

We don't sell your data. We don't share it with third parties for advertising. We don't use your records to train external models.

Delete on request

Documented deletion procedures aligned with HIPAA. You can request full account closure and removal at any time.

§ Next step

Need it in writing
for your IT team?

We share security documentation under NDA. Tell us who you are and what your procurement needs — we'll get you what you're looking for fast.

Request documentation
Or book a demo first →