MediMic.Ai
Security & compliance

Built to support HIPAA-regulated customers.

MediMic uses layered technical and operational safeguards to help protect sensitive healthcare conversations. Session content is protected before transmission, access is controlled, and a BAA is available for the parts of your compliance program that are our shared responsibility.

Session content protection

Sensitive session content is protected before transmission.

MediMic combines device-side protection, secure transport, controlled access, and protected storage. We share additional architecture and control details with qualified customers during a security or vendor review.

1
Session beginsProtection is established for the session
2
Content protected locallyProtection is applied before transmission
3
Secure transportData moves through authenticated connections
4
Protected storageStored session content remains protected
5
Authorized accessOnly authorized participants can access a session

Security details for vendor review

MediMic keeps public implementation detail intentionally high level. Customers and partners can request our security questionnaire, data-flow overview, and supporting control documentation during review.

Additional documentation available on request

Technical safeguards

Security controls mapped to the HIPAA Security Rule.

A concise overview for procurement and compliance teams. Detailed responses are available during vendor assessment.

SafeguardSecurity focusMediMic approach
Access controlAuthorized useVerified sign-in, role-based access, and session controls
Audit controlsAccountabilityAdministrative activity is recorded through operational controls
IntegrityData protectionProtected data includes controls to detect unexpected changes
AuthenticationIdentity assuranceEmail verification, one-time access controls, and account protections
Transmission securitySecure connectionsAuthenticated encrypted transport for service communications
Session contentConfidentialityContent is protected on the device and in storage

Full detail in the Help Center: How MediMic safeguards PHI →

Infrastructure

Hosted in the U.S., with layered protection throughout the service.

  • Hosted in the United States
  • Session content is protected before transmission and in storage
  • Authenticated secure connections
  • Access logging on administrative actions
  • Session transcript content is not written to application logs
Protectedsession content
Securetransport
Controlledaccess
Auditableoperations
Protection is applied throughout the session flow
Business Associate Agreement

A signed BAA, without the legal back-and-forth.

MediMic enters into a BAA with covered entities, defining our obligations and shared responsibilities. On paid plans it is available through your dashboard.

Standard BAAAvailable on paid plans
  • Defines shared responsibilities for protecting PHI
  • Available through the customer dashboard
  • Includes incident and subcontractor responsibilities
  • Enterprise review available on request
Security FAQ

Questions compliance teams ask.

Session content is protected on the device, transmitted through secure connections, and stored in protected form. Additional architecture and control details are available during vendor review.
Access is limited through verified accounts, session controls, and participant authorization. Administrative access is restricted and logged.
MediMic uses U.S.-based infrastructure. Session content and account metadata are handled under separate controls; ask your account team for current data-flow and subprocessor information.
No. Customer session content is not used to train models.
Contact us for a security questionnaire, vendor review materials, or our current security and privacy documentation.

Ready for a vendor assessment?

We provide a detailed security questionnaire response for procurement and compliance review.