Skip to main content

Security

Security Built for Clinical Data

A public summary of MedEazy security posture for hospital IT, privacy, and clinical governance reviewers. This page does not publish credentials, internal endpoints, or protected runbook steps.

Tenant Isolation

Organization and facility boundaries enforced server-side on every query, job, cache, and export.

Role-Based Access

Granular permissions with deny-by-default clinical features and privileged MFA requirements.

Immutable Audit

Sensitive administrative and clinical actions recorded in an append-only security ledger.

Integration Boundaries

Scoped credentials, circuit breakers, and provenance for external clinical systems.

Multi-Tenant Isolation by Design

Every tenant-owned record carries a tenant identifier. Facility-owned records carry tenant and facility context. Cross-tenant access requires explicit platform privileges and is fully audited.

  • Tenant scope established from authenticated membership — never from client-supplied IDs alone
  • Automated tests target cross-tenant leakage for supported API and UI paths
  • Tenant branding cannot weaken contrast, focus, or mandatory safety indicators

Authentication and Session Controls

Separate clinician and administrator entry points with session management appropriate for healthcare environments.

  • Multi-factor authentication for privileged and administrator workflows
  • Invitation-based onboarding; open registration disabled by default
  • Re-authentication for sensitive administrative and clinical-final actions

Audit and Accountability

Governance teams need to reconstruct who did what, when, and under which role — especially for overrides and publication events.

  • Append-only security audit ledger for defined sensitive events
  • Override reasons, user, role, timestamp, and encounter context preserved
  • Support and impersonation workflows designed for approval, banner, time limit, and audit

Data Handling and Availability

High-level commitments for production deployments. Specific contractual and jurisdictional terms are agreed per hospital pilot.

  • TLS in transit and encryption at rest for production architectures
  • Protected data redaction from application logs and error traces where feasible
  • Service status communication via external status pages — not internal runbooks

Clinical Safety Controls

Security and clinical safety intersect where alerts can influence care. MedEazy treats high-risk capabilities as gated, versioned, and auditable.

  • Clinical features deny-by-default with tenant authorization and kill switches
  • AI retrieval constrained to approved sources; deterministic checks remain authoritative
  • Degraded and unavailable states must be clinically approved per workflow

Architecture

Logical Boundaries for Hospital Reviewers

A high-level view of how users, application policy, and tenant-scoped data relate. Detailed diagrams are shared during vendor assessment.

Simplified logical architecture for reviewer discussions. Production topology and endpoints are shared under NDA during vendor assessment.

Users & Hospital Systems

  • Clinicians & pharmacists
  • Administrators
  • EHR / FHIR / HL7 sources

MedEazy Application Boundary

  • Authenticated API & UI
  • Tenant context middleware
  • Policy-based authorization

Governed Data & Operations

  • Tenant-scoped clinical data
  • Audit & security ledger
  • Queues, cache, and exports

MedEazy does not claim HIPAA, GDPR, SOC 2, ISO 27001, or medical-device certification on this public page until independently established for your deployment context.

Security Reviewer FAQ

Where is data stored?
Data residency and hosting are defined per pilot agreement and applicable law. Contact us for the current deployment model.
Do you publish penetration test results publicly?
No. Summary assurance materials are available to authorized reviewers under appropriate confidentiality terms.
How do we report a security concern?
Use the contact form for product security questions. Do not include patient information, credentials, or vulnerability exploit details in public channels.
Are demo credentials published?
No. Public pages and production deployments must not display shared demo passwords.

Request Security Review Materials

Hospital IT and governance teams can contact us for pilot-scope security questionnaires and architecture discussions.