Our principles
- Your data is yours. We hold it, we do not own it, and you can take it out whenever you want.
- Minimum necessary. We collect what the service needs and no more. Where a full identifier is not required, we store a partial one.
- No secondary use. Patient data is not sold, not used for advertising, and not used to train machine learning models.
- Everything attributable. Clinical and financial changes record who made them, when and from where.
- Say what is true. We would rather tell you a certification is on the roadmap than imply we hold one.
Regulatory frameworks
Health data is regulated differently in every market. Medora is built around a common core of controls that maps onto the major frameworks, with region-specific arrangements available.
| Framework | Region | Our position |
|---|---|---|
| GDPR / UK GDPR | EU, UK | Processor obligations met via our DPA; SCCs for transfers |
| HIPAA | United States | BAA available on request; technical safeguards in place |
| DPDP Act 2023 | India | Data Fiduciary/Processor obligations addressed in the DPA |
| PIPEDA | Canada | Supported through the DPA and residency options |
| Privacy Act / APPs | Australia | Supported through the DPA and residency options |
GDPR and UK GDPR
For customers in the EU and UK, your hospital is the controller and Medora is the processor.
- Our Data Processing Agreement is drafted to meet Article 28 requirements and is available signed on request.
- Health data is special category data under Article 9. Establishing your lawful basis and Article 9 condition is your responsibility as controller; we support it with access controls and audit logging.
- Sub-processors are listed publicly with advance notice of changes and a right to object.
- Transfers outside the EEA/UK rely on Standard Contractual Clauses or an adequacy decision.
- We assist with data subject requests and DPIAs as set out in the DPA.
- Breach notification to you within [48] hours of awareness, so you can meet your own 72-hour regulator deadline.
HIPAA — United States
If you are a Covered Entity, we act as a Business Associate.
- A Business Associate Agreement is required before you place any PHI in the system. Request one before go-live — the DPA alone does not satisfy HIPAA.
- Technical safeguards: unique user identification, automatic logoff, encryption in transit and at rest, audit controls.
- Administrative safeguards: workforce confidentiality agreements, access management, security training, incident response.
- We will report breaches of unsecured PHI to you without unreasonable delay so you can meet your notification duties.
DPDP Act 2023 — India
- Your hospital is the Data Fiduciary; Medora acts as a Data Processor under contract.
- We process personal data only on your instructions, as set out in the DPA.
- Security safeguards, breach notification and deletion obligations are addressed in the DPA.
- Where a national identifier is captured, the system stores a partial identifier rather than the full number by default — an example of the minimum-necessary principle in practice.
- Data residency within India is available on request.
Other regions
We sell internationally and will work through local requirements with you before contract. If your regulator requires specific contractual terms, in-country hosting or a named local representative, raise it early — these are usually solvable, but not in the week before go-live.
Security controls
| Area | Control |
|---|---|
| Encryption | TLS in transit; encryption at rest for databases and backups |
| Authentication | Individual accounts; passwords stored using one-way hashing; session timeouts |
| Authorisation | Role-based permissions enforced server-side, not just hidden in the interface |
| Isolation | Logical separation per customer workspace; no pooled data |
| Audit | Clinical and financial changes logged with user, action, timestamp and origin |
| Backups | Daily encrypted backups; restores tested; point-in-time recovery |
| Change control | Peer review before release; staged deployment |
| Access management | Least privilege for our staff; support access on request only, time-limited and logged |
| Vendor management | Assessment before engaging any sub-processor handling customer data |
Data residency
By default your workspace is hosted in [PRIMARY REGION]. Residency in [LIST REGIONS] is available on request, usually at no extra cost. Backups stay in the same jurisdiction as the primary unless you agree otherwise in writing.
Certification status
We would rather be accurate than impressive.
| Item | Status | Notes |
|---|---|---|
| Data Processing Agreement | In place | Available signed on request |
| HIPAA Business Associate Agreement | Available | On request, for US customers |
| Encryption in transit and at rest | In place | — |
| Audit logging | In place | Clinical and financial records |
| Independent penetration test | [Roadmap — target DATE] | Summary shared with customers when complete |
| SOC 2 Type II | [Roadmap — target DATE] | Not yet held |
| ISO 27001 | [Roadmap — target DATE] | Not yet held |
If a certification is not listed as held, we do not hold it. Ask and we will tell you where we are.
Reporting a security problem
If you believe you have found a vulnerability, email [SECURITY EMAIL]. Please give us enough detail to reproduce it, and time to fix it before disclosing publicly. We will acknowledge within [2] working days and keep you updated.
We do not take legal action against researchers who act in good faith, avoid privacy violations and do not degrade the service.