Built to support HIPAA-regulated customers.
MediMic uses layered technical and operational safeguards to help protect sensitive healthcare conversations. Session content is protected before transmission, access is controlled, and a BAA is available for the parts of your compliance program that are our shared responsibility.
Sensitive session content is protected before transmission.
MediMic combines device-side protection, secure transport, controlled access, and protected storage. We share additional architecture and control details with qualified customers during a security or vendor review.
Security details for vendor review
MediMic keeps public implementation detail intentionally high level. Customers and partners can request our security questionnaire, data-flow overview, and supporting control documentation during review.
Additional documentation available on request
Security controls mapped to the HIPAA Security Rule.
A concise overview for procurement and compliance teams. Detailed responses are available during vendor assessment.
| Safeguard | Security focus | MediMic approach |
|---|---|---|
| Access control | Authorized use | Verified sign-in, role-based access, and session controls |
| Audit controls | Accountability | Administrative activity is recorded through operational controls |
| Integrity | Data protection | Protected data includes controls to detect unexpected changes |
| Authentication | Identity assurance | Email verification, one-time access controls, and account protections |
| Transmission security | Secure connections | Authenticated encrypted transport for service communications |
| Session content | Confidentiality | Content is protected on the device and in storage |
Full detail in the Help Center: How MediMic safeguards PHI →
Hosted in the U.S., with layered protection throughout the service.
- Hosted in the United States
- Session content is protected before transmission and in storage
- Authenticated secure connections
- Access logging on administrative actions
- Session transcript content is not written to application logs
A signed BAA, without the legal back-and-forth.
MediMic enters into a BAA with covered entities, defining our obligations and shared responsibilities. On paid plans it is available through your dashboard.
- Defines shared responsibilities for protecting PHI
- Available through the customer dashboard
- Includes incident and subcontractor responsibilities
- Enterprise review available on request
Questions compliance teams ask.
Ready for a vendor assessment?
We provide a detailed security questionnaire response for procurement and compliance review.