Data security

Patient records stay protected.

MediScan protects patient records with HIPAA-compliant safeguards, independent SOC 2 audits, encryption, and continuous security monitoring.

Physician reviewing records in a secure workspace

Security standards

Safeguards for sensitive medical information.

The workspace is designed to protect health information throughout record review. Independent audits and continuous monitoring support our security program.

HIPAA

Administrative, technical, and physical safeguards for protected health information. Incident response and breach notification follow HIPAA.

SOC 2

Independent SOC 2 audits assess our security and availability controls. These controls are part of our day-to-day operations.

Continuous monitoring

Vanta continuously monitors security controls to help our team identify issues and maintain compliance.

Encryption

Patient data is encrypted in transit and at rest, from upload through review and export.

Security practices

Protection built into daily operations.

Our security program covers account access, software development, monitoring, and the handling of patient records.

01

Access control

Multi-factor authentication protects accounts, and role-based permissions limit case access to authorized users.

02

Secure development

Security is designed in from planning, then tested with code review, static and dynamic analysis, and penetration testing before release.

03

Audit logging

Access to patient data is logged and reviewed to help identify and investigate unusual activity.

04

Backup and recovery

Regular backups and tested restoration keep records available if something fails. Contingency plans cover continuity after an incident.

05

Incident response

A written plan covers detection, escalation, and notification. If a breach of PHI is confirmed, we notify as HIPAA require.

06

Workforce training

Our employees are in the United States. They receive regular HIPAA and security training, and know their role in keeping records confidential.

07

Retention and disposal

Uploaded records and summaries stay for the life of an active account. When data is no longer needed, it is disposed of securely under HIPAA guidelines.

08

Vendors and hosting

Vendors who handle ePHI are reviewed and covered by BAAs. Hosting is physically secured. We carry cybersecurity insurance.

U.S. hosting

Stored, processed, and staffed in the United States.

Records are hosted on AWS in US-West. They are not sent to another country for processing. MediScan employees are in the United States. The cloud provider manages physical infrastructure security. Case access is limited to the users you authorize.

HIPAA CompliantSOC 2 Compliant

Business Associate Agreements

Business Associate Agreements for your organization.

We request a Business Associate Agreement when medical providers or businesses serving them use MediScan to handle protected health information under HIPAA.

The Privacy Policy explains how we handle personal and health information, including retention and cross-border transfers.

Continuous monitoring and independent audits.

We use Vanta to monitor security controls continuously and independent audits to assess our security program.

Questions about a BAA or a security review? Talk with the team.

Frequently asked questions

MediScan uses encryption in transit and at rest, role-based access, multi-factor authentication, and audit logging to protect patient records. Its security controls are independently audited for SOC 2 and monitored with Vanta. Access permissions help organizations limit sensitive case information to the people authorized to review it.

Yes. MediScan's workspace is built and operated to support HIPAA requirements, including access controls, encryption, audit logging, workforce training, and incident response. Business Associate Agreements are available for organizations handling protected health information. Organizations also need to manage their own authorized users and data-handling practices.

Yes. MediScan's security controls undergo independent SOC 2 audits and are monitored continuously with Vanta. These assessments are part of the company's security program. Organizations evaluating MediScan can contact the team to discuss the security information they need for their vendor review.

Yes. Business Associate Agreements are available for medical providers and businesses that use MediScan to handle protected health information. A BAA sets out the parties' responsibilities for that information. Contact the MediScan team to arrange the agreement as part of your organization's setup.

MediScan stores and processes medical records in the United States using AWS US-West. Records are not sent to another country for processing, and MediScan employees are based in the United States. These arrangements cover the hosting, processing, and staffing described in the company's security information.

Case access depends on the user's role and permissions in MediScan. Authorized team members can work from the shared case library, while guest physicians can be limited to assigned cases. Multi-factor authentication protects accounts, and role-based controls govern which information each user can access.

MediScan follows an incident response plan to investigate and contain security incidents. If protected health information is affected, notification is handled according to applicable HIPAA obligations and relevant agreements. Organizations can contact the team for security questions or to report a concern.

Uploaded records, summaries, and associated content are retained for the duration of an active MediScan account. Data that is no longer needed is disposed of securely under the company's data-handling policies. Contact the MediScan team to confirm retention and deletion requirements for your organization.

Review a case in a workspace built for PHI.