Security & Compliance

Protecting Data. Protecting Trust.

Medicare EHR ships with healthcare-grade controls your organization can verify in the product: encryption, role-based access, MFA, audit logs, tenant isolation, consent tracking, and configurable database backups.

Security Overview
Laptop displaying Medicare EHR security dashboard beside a stethoscope

Your Data is Safe With Us.
Security Built for Healthcare.

Built for Healthcare Security

Safeguards Implemented in Medicare EHR

Each control below maps to production code — not marketing claims. Your administrators can configure MFA, SSO, backups, and review audit logs directly in the dashboard.

PHI Field Encryption

Sensitive patient and user identity fields are encrypted in transit and at rest with the latest encryption and technologies. Hashed lookup fields support search without storing plaintext identifiers.

Role-Based Access Control

Centralized AUTHZ presets gate every staff route and server action by role — reception, nursing, clinical, pharmacy, lab, finance, manager, and admin.

Multi-Factor Authentication

TOTP authenticator apps and one-time backup codes protect privileged accounts. MFA is required at login.

Audit & Activity Logs

Staff actions are recorded in UserLog with IP address, device context, and application version. Failed logins and lockouts are logged separately.

Backup & Restore

Tenant administrators configure automated database backups, retention policies, and restore workflows from their dashboard settings.

Account Threat Controls

Login throttling locks accounts after repeated failures with exponential backoff. Observability redacts sensitive data before Sentry export.

Regulatory Alignment

Designed for HIPAA-Aligned Operations

Medicare EHR is not a certifying body. We implement safeguards that help covered entities and business associates meet HIPAA and HITECH obligations. Third-party certification status varies by deployment and contract.

HIPAA Security Rule

Administrative, physical, and technical safeguards including access management, audit controls, integrity, and transmission security.

HITECH Act Readiness

Breach notification obligations for business associates are addressed in our BAA and supported by audit trails and incident logging.

Minimum Necessary Access

Role-scoped permissions limit each staff member to the modules and actions required for their job function.

Patient Consent Controls

Treatment, portal, telehealth, and data-sharing consents are captured with status, version, and audit history in the compliance hub.

Enterprise OIDC SSO

Per-tenant OpenID Connect single sign-on with optional domain allowlists, JIT provisioning, and configurable session limits.

Tenant Data Isolation

Multi-tenant architecture scopes clinical, billing, and operational data by organization ID on every query and server action.

Your Partner in Compliance

Compliance is shared between your organization and Medicare EHR. We provide technical safeguards, auditability, and documentation; your team defines policies, workforce training, and physical security for your sites.

Read the HIPAA Notice

Server actions validate payloads and enforce role checks before any PHI access

Patient Access API and FHIR integration clients use scoped tokens with audit logging

Password reset and email verification flows use time-limited tokens

Compliance administrators review consent registry and activity logs in-dashboard

Enterprise customers may request a Business Associate Agreement (BAA)

Security contact available for incident coordination and safeguard questions

Security Resources

View All Resources

Platform Security Overview

Review the safeguards above — encryption, RBAC, MFA, audit logs, backups, and SSO — fully implemented.

View safeguards

HIPAA Notice

Legal notice describing our role as a business associate, permitted uses of PHI, and breach notification obligations.

Read HIPAA Notice

Help & Support

Questions about access control, MFA enrollment, backups, or compliance workflows? Contact our team.

Get help

Security You Can Trust. So You Can Focus on Care.

See the safeguards in action — MFA, audit logs, consent tracking, and role-based access are available in your dashboard today.