Privacy Policy
Your Privacy. Our Responsibility.
Medicare EHR is committed to protecting personal information and Protected Health Information (PHI) across our multi-tenant EHR platform. This policy explains what we collect, how we use it, and the controls available to healthcare organizations and individuals.
Effective date: June 9, 2026
We Protect Your Data
Tenant-scoped storage, role-based access, MFA, and AES-256-GCM encryption for designated sensitive fields.
We Respect Your Privacy
Consent registry for treatment, portal, telehealth, and data sharing — with audit logging on changes.
We Are Transparent
Clear documentation of collection categories, subprocessors on request, and no sale of personal or health information.

Our Commitment
Our Commitment to Your Privacy
Medicare EHR follows privacy principles aligned with healthcare industry standards and the safeguards described in our HIPAA Notice.
Lawful & Fair Processing
We process information to deliver contracted EHR services and as required by applicable law.
Purpose Limitation
Data is used for clinical, operational, billing, and platform administration — not unrelated marketing.
Data Minimization
We collect fields needed for workflows — demographics, clinical records, and audit metadata scoped per tenant.
Secure Storage
Encrypted PHI mirrors, TLS in production, session management, and configurable backup retention.
Your Rights
Access, correction, and deletion requests are handled per legal obligations and customer agreements.
Healthcare Compliance
HIPAA-aligned safeguards for PHI when we act as a business associate to covered entities.
1. Information We Collect
We collect account, clinical, usage, payment, and support information necessary to operate the platform for each healthcare organization tenant.
When you register an organization, create staff accounts, use clinical workflows, or contact support, Medicare EHR collects information described below. Patient PHI is entered by authorized staff of the covered entity and stored in tenant-isolated databases.
Searchable hash fields (emailHash, phoneHash, ninHash) support lookup while encrypted mirrors (firstNameEnc, phoneEnc, etc.) protect designated sensitive values at rest.
Personal Information
Identity and contact details for staff and patients.
- • Staff: name, email, phone, role
- • Patients: demographics, address, NIN, preferred language
- • Organization: name, domain, branding settings
Health Information
Clinical and care-related records entered in the EHR.
- • Medical history, allergies, vitals
- • Encounters, orders, lab and imaging results
- • Medications, treatment plans, surgical cases
Usage Information
Activity needed for security, audit, and platform operations.
- • UserLog staff activity and login events
- • Security audit events (failed logins, lockouts)
- • Webhook event logs for integrations
Payment Information
Subscription and billing data for SaaS customers.
- • Checkout and order records via payment provider
- • Subscription status and revenue analytics for platform owners
- • Invoice references — card data handled by payment processor
Support Information
Communications when you contact our team.
- • Contact form submissions and email correspondence
- • Issue descriptions and troubleshooting context
- • Enterprise onboarding and BAA requests
We never sell personal information or PHI. Health records belong to the healthcare organization tenant; Medicare EHR processes PHI only to provide contracted services.
Your Trust Matters
Download the full policy for your compliance records, or contact us for a Business Associate Agreement and security documentation package.

Healthcare Trust
Privacy Built for Clinical Teams
From consent capture to encrypted patient fields and role-based chart access, Medicare EHR gives Sierra Leonean clinics and hospitals the controls they need to protect patient trust while delivering modern care.

