Security and compliance claims as published on mediyn.com
Security and compliance claims as published on mediyn.com
Section titled “Security and compliance claims as published on mediyn.com”HIPAA / BAA
Section titled “HIPAA / BAA”Site path: /security
- Mediyn is described as HIPAA compliant.
- A Business Associate Agreement (BAA) is included on every plan — not gated behind an enterprise tier.
- The BAA is signed automatically at signup (per /privacy-first page).
- The footnote states: “HIPAA compliant · BAA included · SOC 2 Type II · 256-bit AES.”
On-Device PHI Redaction and De-identification
Section titled “On-Device PHI Redaction and De-identification”Site path: /security
- By default, Mediyn’s redaction engine runs on the device, finding names, dates, addresses, and other identifiers in the raw session and replacing them with tokens before anything is uploaded.
- What lands on the servers is described as a de-identified clinical note — structurally complete, but not re-identifiable.
- In the rare case on-device processing is not available, the app falls back to a secure encrypted upload that is deleted once notes are ready.
- Every document is labeled with where it was processed.
- The following data items are listed as staying on device: names & contacts, dates of birth, addresses, raw audio.
- The following items are listed as reaching the cloud: de-identified note, token placeholders, clinical structure, nothing re-identifiable.
- The site claims this represents “a fundamentally smaller attack surface than ‘upload everything, secure it later.’”
- Raw audio is stated to never leave the device.
Encryption
Section titled “Encryption”Site path: /security
- Data in transit is encrypted with TLS 1.3.
- Data at rest is encrypted with AES-256.
- Encryption keys are held in a hardware security module (HSM).
- The defense-in-depth panel labels these as five independent layers: on device, in transit, at rest, access, and audit.
- Each layer is described as independently encrypted, independently audited, and independently configurable.
Audit Trails
Section titled “Audit Trails”Site path: /security
- Every access, edit, and action is logged.
- The audit trail is described as tamper-evident and append-only (immutable).
- Retention period is seven years.
- The audit trail is exportable for audits and investigations.
- Items logged include: chart views, claim submissions, role changes, and system payment postings.
- The audit trail is described as covering every view, edit, and action.
MFA and Access Control
Section titled “MFA and Access Control”Site path: /security
- Multi-factor authentication (MFA) is required for all staff and can be required for every account.
- Access is role-based with least-privilege permissions.
- Periodic access recertification is performed on a quarterly basis.
- Trusted-device registration is supported; the panel example shows 2 registered devices.
- PHI is masked in the UI for non-clinical roles.
- PHI masking is described as server-side, not hidden with CSS (per /privacy-first page).
- Re-authentication is required to unmask sensitive fields, and every unmasking event is logged in the immutable audit trail.
Privacy Policy Controls and De-identification Configuration
Section titled “Privacy Policy Controls and De-identification Configuration”Site path: /security
- Redaction profile is configurable; the default/example shown is “Strict (names, dates, IDs).”
- PHI masking in the UI is configurable and is on for non-clinical roles.
- A consent ledger is maintained per consent type, with withdrawal supported.
- Data retention is configurable per policy.
Site path: /security
- Mediyn claims SOC 2 Type II certification.
- SOC 2 Type II is listed in the compliance panel alongside HIPAA and 256-bit AES.
No Surprises Act
Section titled “No Surprises Act”Site path: /security
- Mediyn claims No Surprises Act (Good Faith Estimate, GFE) support.
- The /privacy-first page adds: GFE generation, delivery, and acknowledgment are supported.
Data Use Commitments
Section titled “Data Use Commitments”Site path: /security
- Mediyn states it does not train models on identifiable (PHI) data.
- Mediyn states it does not sell or share client data.
- These commitments are described as being put in writing via the signed BAA.
- Users can export or delete their data at any time.
- The /privacy-first page adds: session recordings, transcripts, clinical notes, messages, and assessment responses are never used as training data — not for Mediyn’s own models, and not for third-party language model providers, who operate under zero-retention agreements.
Client Portal Security
Section titled “Client Portal Security”Site path: /security
- Client portal login uses passwordless magic links — no credentials to steal or phish.
- Biometric device authentication is used to confirm identity on trusted devices.
- Clients only see data scoped to their clinician-set permission level (role-scoped PHI masking).
- Secure in-app messaging is therapist-initiated, text only, with no file uploads.
- Assessments and worksheets are submitted through encrypted channels.
- Invoice access and payment are available without exposing clinical records.
- Every client portal action (view, submit, message) is logged in the immutable audit trail.
Device Loss and Data Access
Section titled “Device Loss and Data Access”Site path: /security
- Raw audio files exist only on the device and are encrypted at rest.
- If a device is lost, the token-mapping data linking de-identified transcripts to client identifiers is inaccessible without biometric or device passcode.
- Trusted devices can be remotely revoked from account settings.
- Mediyn’s access controls are designed so that support staff cannot access clinical content during normal operations.
Telehealth
Section titled “Telehealth”Site path: /security
- When a video session is conducted through Mediyn’s built-in telehealth, audio is processed through the same on-device transcription and PHI redaction pipeline.
- Video streams are encrypted in transit and at rest.
- Sessions are not recorded unless recording is explicitly enabled.
Data Retention After Cancellation
Section titled “Data Retention After Cancellation”Site path: /security
- After account closure, users have 90 days to retrieve clinical data.
- After 90 days, personal information is deleted.
- Clinical records are retained only as long as required by HIPAA and applicable state retention laws, described as typically 6–7 years.