Compliance · HIPAA

How MedIQ maps to the HIPAA Security Rule.

This page is a plain-English summary intended for prospective customers and their security reviewers. It is not legal advice. Customers remain responsible for their own compliance posture.

AreaSafeguardHow MedIQ addresses it
AdministrativeSecurity Management ProcessDocumented risk analysis, written policies, sanction policy, periodic information system activity review.
AdministrativeWorkforce Security & TrainingBackground checks, role-based access, annual HIPAA training, signed acceptable-use policy.
AdministrativeInformation Access ManagementLeast-privilege roles enforced in app and database; access reviews quarterly.
AdministrativeContingency PlanDocumented backup, DR, and emergency-mode operation plans; tested restore drills.
AdministrativeBusiness Associate ContractsStandard BAA with every covered-entity customer; signed BAAs with all PHI-touching sub-processors.
PhysicalFacility Access ControlsPHI lives only in HIPAA-eligible cloud regions with physical controls audited by the provider (SOC 2).
PhysicalWorkstation & Device SecurityWorkforce devices managed via MDM, full-disk encryption, screen lock, and remote wipe.
TechnicalAccess ControlUnique user IDs, mandatory MFA, automatic logoff, role-based authorization, server-side checks on every mutation.
TechnicalAudit ControlsAppend-only audit log of access and changes; per-tenant scoping; queryable for breach investigations.
TechnicalIntegrityDatabase constraints + application validation + AES-256-GCM auth tags on encrypted secrets.
TechnicalTransmission SecurityTLS 1.2+ enforced end-to-end; HSTS; modern cipher suites only.
BreachNotificationDocumented incident response with 60-day breach notification window; customer-facing comms templates ready.
Minimum necessary, by default

PHI never leaves your tenant in plaintext.

AI prompts are de-identified before transmission. We log the input hash, model version, and outcome — never the patient name, MRN, or note body.

Sub-processors

A short, audited list.

We publish our sub-processor list under NDA. Today it includes our cloud provider, our managed Postgres provider, and your chosen LLM provider (you bring the key).

Reviewing us for your security team?

We can share the security overview, BAA, sub-processor list, and SOC 2 progress under NDA.