M Medora
How it works Modules Security Pricing
Sign in Book a demo ↗
Trust

Compliance

Last updated: [DATE]

Our principles Regulatory frameworks GDPR (EU / UK) HIPAA (United States) DPDP (India) Other regions Security controls Data residency Certification status Reporting a problem
Where responsibility sits. Compliance in healthcare software is shared. We are responsible for building and running a secure, well-governed platform. You remain responsible for how you use it — lawful basis, patient consent, staff access, and the clinical retention rules that apply where you practise. Neither of us can do the other's part.

Our principles

  • Your data is yours. We hold it, we do not own it, and you can take it out whenever you want.
  • Minimum necessary. We collect what the service needs and no more. Where a full identifier is not required, we store a partial one.
  • No secondary use. Patient data is not sold, not used for advertising, and not used to train machine learning models.
  • Everything attributable. Clinical and financial changes record who made them, when and from where.
  • Say what is true. We would rather tell you a certification is on the roadmap than imply we hold one.

Regulatory frameworks

Health data is regulated differently in every market. Medora is built around a common core of controls that maps onto the major frameworks, with region-specific arrangements available.

FrameworkRegionOur position
GDPR / UK GDPREU, UKProcessor obligations met via our DPA; SCCs for transfers
HIPAAUnited StatesBAA available on request; technical safeguards in place
DPDP Act 2023IndiaData Fiduciary/Processor obligations addressed in the DPA
PIPEDACanadaSupported through the DPA and residency options
Privacy Act / APPsAustraliaSupported through the DPA and residency options

GDPR and UK GDPR

For customers in the EU and UK, your hospital is the controller and Medora is the processor.

  • Our Data Processing Agreement is drafted to meet Article 28 requirements and is available signed on request.
  • Health data is special category data under Article 9. Establishing your lawful basis and Article 9 condition is your responsibility as controller; we support it with access controls and audit logging.
  • Sub-processors are listed publicly with advance notice of changes and a right to object.
  • Transfers outside the EEA/UK rely on Standard Contractual Clauses or an adequacy decision.
  • We assist with data subject requests and DPIAs as set out in the DPA.
  • Breach notification to you within [48] hours of awareness, so you can meet your own 72-hour regulator deadline.

HIPAA — United States

If you are a Covered Entity, we act as a Business Associate.

  • A Business Associate Agreement is required before you place any PHI in the system. Request one before go-live — the DPA alone does not satisfy HIPAA.
  • Technical safeguards: unique user identification, automatic logoff, encryption in transit and at rest, audit controls.
  • Administrative safeguards: workforce confidentiality agreements, access management, security training, incident response.
  • We will report breaches of unsecured PHI to you without unreasonable delay so you can meet your notification duties.
Be direct with us about US deployment. HIPAA changes what we must do and what we must sign. Tell us during the sales conversation, not after go-live.

DPDP Act 2023 — India

  • Your hospital is the Data Fiduciary; Medora acts as a Data Processor under contract.
  • We process personal data only on your instructions, as set out in the DPA.
  • Security safeguards, breach notification and deletion obligations are addressed in the DPA.
  • Where a national identifier is captured, the system stores a partial identifier rather than the full number by default — an example of the minimum-necessary principle in practice.
  • Data residency within India is available on request.

Other regions

We sell internationally and will work through local requirements with you before contract. If your regulator requires specific contractual terms, in-country hosting or a named local representative, raise it early — these are usually solvable, but not in the week before go-live.

Security controls

AreaControl
EncryptionTLS in transit; encryption at rest for databases and backups
AuthenticationIndividual accounts; passwords stored using one-way hashing; session timeouts
AuthorisationRole-based permissions enforced server-side, not just hidden in the interface
IsolationLogical separation per customer workspace; no pooled data
AuditClinical and financial changes logged with user, action, timestamp and origin
BackupsDaily encrypted backups; restores tested; point-in-time recovery
Change controlPeer review before release; staged deployment
Access managementLeast privilege for our staff; support access on request only, time-limited and logged
Vendor managementAssessment before engaging any sub-processor handling customer data

Data residency

By default your workspace is hosted in [PRIMARY REGION]. Residency in [LIST REGIONS] is available on request, usually at no extra cost. Backups stay in the same jurisdiction as the primary unless you agree otherwise in writing.

Certification status

We would rather be accurate than impressive.

ItemStatusNotes
Data Processing AgreementIn placeAvailable signed on request
HIPAA Business Associate AgreementAvailableOn request, for US customers
Encryption in transit and at restIn place—
Audit loggingIn placeClinical and financial records
Independent penetration test[Roadmap — target DATE]Summary shared with customers when complete
SOC 2 Type II[Roadmap — target DATE]Not yet held
ISO 27001[Roadmap — target DATE]Not yet held

If a certification is not listed as held, we do not hold it. Ask and we will tell you where we are.

Reporting a security problem

If you believe you have found a vulnerability, email [SECURITY EMAIL]. Please give us enough detail to reproduce it, and time to fix it before disclosing publicly. We will acknowledge within [2] working days and keep you updated.

We do not take legal action against researchers who act in good faith, avoid privacy violations and do not degrade the service.

Talk to us about your requirements

© 2026 Medora. All rights reserved. Designed, built and supported by TaskMinions