Security & Trust Center

Security built for protected health information

MediCRM combines administrative and technical safeguards designed to support healthcare organizations that manage PHI.

HIPAA-Aligned Safeguards

PHI encrypted in transit & at rest

42 CFR Part 2 Controls

Substance-use privacy protections

BAA Available

Business Associate Agreement

Org-Level Isolation

Separation at the database layer

Access control

Role-based permissions aligned to clinical roles, multi-factor authentication, and break-glass emergency access for urgent situations — every action recorded.

  • Role-based access control (RBAC)
  • Multi-factor authentication (TOTP)
  • Break-glass emergency access
  • Session and token management

Auditability

Comprehensive audit trails capture record access and administrative activity to support operational review and accountability.

  • Record-access & admin audit logs
  • Searchable audit history
  • Configurable retention windows

Data protection

PHI is encrypted in transit and at rest, with organization-level data isolation separating one organization's records from another at the database layer.

  • Encryption in transit & at rest
  • Organization-level data isolation
  • Administrative anonymization of discharged records

Portability

  • HIPAA data export via structured JSON
  • Secure document vault with audit trails

This page describes product capabilities for informational purposes and is not legal advice. HIPAA compliance depends on your organization's complete program, policies, and Business Associate Agreement. No software alone makes an organization compliant.