Trust · United States

HIPAA: programme in progress.

MedAppz is hosted in the United States, and that is not HIPAA compliance. A covered entity may only share protected health information with a vendor that signs a business associate agreement (BAA), and every vendor behind that one needs a BAA too. None of ours are signed yet. This page says what the product already does, what is still open, and what you would need to do.

Status as of 24 September 2026MedAppz United States
An illustration of a clinic team reviewing a shared, secured workspace

Where we stand, as of 24 September 2026

This covers HIPAA (the US Health Insurance Portability and Accountability Act). MedAppz does not claim compliance with it or any certification under it. This is a programme in progress, and this table is where it stands. Records are stored on one server: Boston, United States · Hostinger VPS. It is a US location, but a US server is not a HIPAA-covered arrangement without a BAA.

ItemStatusNote
Business associate agreement from MedAppz to youNot startedWe will not offer one until the vendors below have signed theirs.
BAA with our host (Hostinger)In progressWe have asked whether Hostinger signs a BAA for this VPS. Unconfirmed. If it does not, US patient data moves to a host that does.
BAAs with AI and speech-to-text vendorsNot startedNone signed. You can switch AI and transcription off for your organisation today.
BAAs with SMS, email and WhatsApp providersNot startedNone signed. Our SMS provider today is an Indian gateway, and US text messaging is not set up.
Written HIPAA risk analysisNot startedNot yet done or published.
Breach notification workflow for HIPAA timelinesNot startedThe breach register tracks Indian notice deadlines (CERT-In and the Data Protection Board). HIPAA’s are not built in yet.
Audit trail, emergency access, access reviews, backupsIn placeListed below, each with the module that does it.
Encryption at rest for the database and backupsIn progressBackup encryption is built but not yet switched on. Backups are not yet held off-site.
HIPAAGuard (a HIPAA workflow app)In progressIn development; see its catalog page.

In place in the product today

Each of these runs in the product now. The line under each one names the part of the law it relates to. That is a pointer for your own review, not a claim that the clause is met.

An audit trail that cannot be editedRecord opens, searches and exports are written once: who, when, from where, under which permission. The log is append-only by database trigger and hash-chained day by day; the chain is re-verified nightly.Audit schema and AuditLens · Audit controls — §164.312(b)
One clinic cannot read another’s rowsRow-level security on every tenant table, bound to the transaction. The account the application runs as cannot switch it off.Database row-level security · Access control — §164.312(a)(1)
Emergency access that expires and is reviewedBreak-glass access needs a written reason, lasts at most four hours (a database constraint), and lands on a review queue.BreakGlass · Emergency access procedure — §164.312(a)(2)(ii)
Consent records, by notice versionMessages are gated on the consent notice the patient accepted, by version, at the moment of sending. Withdrawal cancels what is queued.ConsentVault and the consent service
Access reviews with two-person revocationThe Security Centre runs dated access-review campaigns over privileged grants (full patient data, money, platform, emergency access). A challenge raises a two-person approval; a campaign cannot close with unread items.Security Centre · Information system activity review — §164.308(a)(1)(ii)(D)
Strong sign-in and short sessionsArgon2id password hashing, lockout after five failures, optional or organisation-required app-based two-factor, 15-minute access tokens with rotating refresh tokens, and a five-minute idle-out on shared devices.Identity · Person or entity authentication, automatic logoff — §164.312(d), (a)(2)(iii)
Encryption in transit, and sealed credentialsTLS on every connection, with certificates renewed automatically. Keys and passwords a clinic gives us are sealed with AES-256-GCM, bound to the organisation, and never shown back.TLS and the secrets envelope · Transmission security — §164.312(e)(1)
Nightly verified backups, with a rehearsed restoreThe database and files are dumped every night and each dump is checked before the run counts as a success. A full restore was rehearsed on 3 September 2026.ops/backup.sh · Data backup plan — §164.308(a)(7)(ii)(A)
Exports are whitelisted and recordedOnly listed views can be exported, each needs its permission, and each export is recorded with its row count and data classes.Exports
AI you can switch off, or send redactedOne setting per organisation: off, redacted (the default) or full. Redacted strips the name, date of birth, hospital number, phone and email before the request leaves our server. A named person accepts every draft.AI governance

What you would need to do

  • Do not put real patient data into MedAppz until a BAA is signed between you and us, and ours with our vendors are in place. The demo clinic has invented data for trying the product.
  • Do your own risk analysis. HIPAA puts it on the covered entity, whoever the vendor is.
  • Turn AI and transcription off, or keep them on redacted, until the AI vendors have signed BAAs.
  • Require two-factor sign-in for everybody in your organisation (it is one setting).
  • Keep your own policies: workforce training, sanctions, device and media controls. Software cannot do these for you.
This page describes our product. It is not legal advice; take your own advice on how the law applies to your practice.

Sub-processors and where they are

Every outside service the product can send data to, where it processes it, and whether an agreement is signed. The list is generated from the register the product itself reads, the same one the Trust Centre shows.

ServiceLocationAgreement
HostingerThe rented server the database, the application and the uploaded files run onOne rented regionNone signed yet
S3-compatible object storageWhere uploaded files and documents live when object storage is switched onThe bucket region the deployment configuredNone signed yet
AnthropicAI drafting and answeringUnited StatesNone signed yet
OpenAIAI drafting and answeringUnited StatesNone signed yet
Google (Gemini)AI drafting and answeringUnited StatesNone signed yet
NVIDIA NIMAI drafting and answeringUnited StatesNone signed yet
The configured speech-to-text serviceTurning a consultation recording into a transcriptWherever SPEECH_API_BASE_URL points — api.openai.com (United States) unless changedNone signed yet
The clinic’s own Jitsi serverCarrying the live audio and video of a video visitWherever the clinic hosts itNone signed yet
ResendSending emailUnited States / European UnionNone signed yet
MSG91Sending SMSIndiaNone signed yet
Meta (WhatsApp Business)Sending WhatsApp messages through the official APIMeta’s global networkNone signed yet
The clinic’s paired WhatsApp numberSending WhatsApp messages from the clinic’s own handset sessionMeta’s global network, through the clinic’s own numberNone signed yet
Google (Firebase Cloud Messaging)Delivering push notifications to a phoneGoogle’s global networkNone signed yet
RazorpayTaking a payment online, and holding a standing UPI Autopay or e-mandate authorisationIndiaNone signed yet
PhonePeTaking a payment onlineIndiaNone signed yet
StripeTaking a payment onlineUnited StatesNone signed yet
Pine LabsTaking a card payment on the counter terminalIndiaNone signed yet
Google SheetsReceiving a scheduled exportGoogle’s global networkNone signed yet
Google Business Profile and MetaReading reviews and publishing the clinic’s repliesGoogle and Meta’s global networksNone signed yet
The clinic’s own mail serverThe mailbox MedAppz proxies rather than copiesWherever the clinic’s mail is hostedNone signed yet
The hospital’s own GST Suvidha ProviderRegistering the hospital’s own patient invoices with the Invoice Registration PortalIndiaNone signed yet
The clinic’s own Tally serverReceiving the accounting export, and answering which vouchers it tookWherever the clinic runs TallyNone signed yet
A database the clinic bringsA destination the clinic asked the product to write toWherever the clinic hosts itNone signed yet

Send us your HIPAA questions

Your security questionnaire is longer than this page. Leave a number and we will answer it line by line, including where the answer is “not yet”.

We use your name, phone number and clinic name for one thing: to answer this enquiry about MedAppz. It is stored on our own server, in the single region our trust centre names, and it is not sold or passed to anyone else.

Email us

You can withdraw either at any time: write to hello@medappz.com, or tell whoever calls you, and we will delete what you gave us.