Skip to main content

Legal

Data Processing and Security Summary

data processing and security summary

A public-facing summary of how MedEazy processes information and protects hospital data. Detailed security questionnaires, subprocessors, and architecture diagrams are available under NDA during vendor assessment.

Draft legal content for MedEazy. Independent legal review and sign-off required before production reliance (APR-043).

Document Purpose

document purpose

This summary supports initial due diligence. It does not replace a signed Data Processing Agreement (DPA), Business Associate Agreement where applicable, or security schedule attached to your contract.

Roles and Scope

roles and scope

For clinical workspace data, the Customer typically acts as data fiduciary/controller and MedEazy acts as processor/service provider processing data only on documented instructions, subject to the agreement.

Processing scope includes user accounts, configuration, clinical inputs and outputs, audit logs, support tickets, and integration payloads necessary to deliver authorized features.

Tenant Isolation

tenant isolation

Every tenant-owned record carries a tenant identifier. Facility context is enforced server-side. Cross-tenant access requires explicit platform privileges and is audited. Automated tests target cross-tenant leakage for supported paths.

Security Controls (Summary)

security controls (summary)

Production architectures are designed to include:

  • TLS encryption in transit and encryption at rest for stored data.
  • Role-based access control with deny-by-default clinical features.
  • Multi-factor authentication for privileged and administrator workflows.
  • Invitation-based onboarding; open registration disabled by default.
  • Append-only security audit ledger for defined sensitive events.
  • Protected data redaction from application logs and error traces where feasible.
  • Scoped integration credentials with rotation and circuit breaker patterns.

Subprocessors and Hosting

subprocessors and hosting

We use infrastructure and service providers for hosting, email, monitoring, and security operations under written agreements requiring confidentiality and appropriate security measures. Current subprocessor and region details are shared with customers under contract.

Retention, Export, and Deletion

retention, export, and deletion

Retention schedules, legal hold, export formats, and tenant offboarding procedures are configured per agreement. Customers may request export windows and certified deletion timelines as defined in the DPA.

Incident Response

incident response

We maintain incident response procedures for security and availability events. Customers are notified of confirmed breaches affecting their data according to contractual timelines and applicable law. Public status pages communicate availability; detailed runbooks are not published.

Certifications and Assurance

certifications and assurance

MedEazy does not claim HIPAA, GDPR compliance, SOC 2, ISO 27001, or medical-device certification on this public page unless independently established and approved for your deployment context. Summary assurance materials may be shared with authorized reviewers under confidentiality terms.

Contact for Security Review

contact for security review

Hospital IT and privacy teams may request questionnaires and architecture discussions through the Contact page with topic “Security review.” Do not include patient data, credentials, or exploit details in public channels.