Trust / HIPAA

HIPAA-aligned by design.

Medi Prompt is built to support HIPAA compliance for covered entities and business associates operating in the United States, with signed BAAs and strong technical safeguards as defaults.

How we support HIPAA

  • Business Associate Agreement

    Signed BAA available for every covered entity engagement.

  • Access controls

    MFA, SSO/SAML, role-based permissions, and least-privilege service accounts.

  • Encryption everywhere

    AES-256 at rest, TLS 1.3 in transit, tenant-scoped keys.

  • Audit logging

    Comprehensive, tamper-evident logs across clinical and administrative actions.

Shared responsibility

HIPAA compliance is a shared model between Medi Prompt and each covered entity. We provide the technical safeguards and the BAA, you configure users, policies, and workflows in line with your compliance program.

This page describes controls we operate. HIPAA is a legal framework, not a certification - always review your organization's obligations with qualified counsel.

Requesting documentation

For BAAs, security questionnaires, and vendor risk packets, contact us and we'll route you to the right team.