# Security & Trust — Medrecords AI

> How Medrecords AI protects PHI: HIPAA controls, SOC 2 audit-ready documentation, encryption, PHI audit logging, and a never-train promise. BAA available.

Canonical page: https://medrecords.ai/security/

---
New — **Missing Records Detection:** flags every visit, provider, and date missing from the file. [See how →](https://medrecords.ai/product/missing-records-identification/)
Security & Trust · the procurement page

## Built for PHI from the ground up.

This page exists to be bookmarked and forwarded. Everything your security review, procurement team, or client audit needs: stated plainly, with nothing overstated.

HIPAA
 SOC 2 · audit-ready
 TLS 1.2+
 AES-256
 BAA / DPA available
 ISO 27701 · roadmap
"Audit-ready" means controls and evidence are documented for audit. We say "certified" only when a certificate exists.

PHI audit log


 LIVE
AES-256 · record encrypted
 verified
OCR extraction → page 14
 verified
Citation linked → source p.12
 verified
Access: case #2291 only
 verified
Export blocked — no BAA
 enforced

### Your records never train an AI model. Ever.

Not ours, not a vendor's, not "de-identified for research." Your files are processed to produce your outputs, and that is the end of their journey. This is contractual (it's in the BAA), not a settings toggle.

### 6 controls your reviewer will ask about.

Encryption
TLS 1.2+ in transit, AES-256 at rest — every file, every environment.

Case-level access control
HIPAA-minimal by default: people see only the cases assigned to them. Nothing else exists for them.

PHI audit logging
Every PHI access event is logged: who, what, when — and exportable for your own audits, appeals, and records requests.

Secure sessions
Token-validated sessions with strict expiry handling. No shared credentials, anywhere.

SOC 2 readiness
Controls documentation and evidence packages maintained audit-ready, available under NDA.

Human-guided AI
Every output cited, reviewable, and traceable to its source. AI does the reading; your experts make the calls.

### Deployment & integration

For carriers, TPAs, and public-sector programs deploying at scale.

Connect (API)
Secure REST API and CRM token exchange, no shared credentials — with outbound webhooks into your case-management and claims systems.

Usage & cost analytics
Per-feature, per-file metering — bill costs back to a case, a client program, or a desk.

Data lifecycle
Retention controls, de-identified export for sharing without exposing PHI, and deletion on request.

### Who touches your data, and what happens if something goes wrong.

Breach notification
Notice of any breach of unsecured PHI without unreasonable delay, and in no event later than 72 hours after we confirm it, as set out in the [DPA](https://medrecords.ai/dpa/) and the [BAA](https://medrecords.ai/hipaa/) .

Who can touch your records
4 vendors, all under BAA, zero-retention, no-training: AWS (US-hosted infrastructure), Anthropic, OpenAI, and OpenRouter (model inference and routing). Full detail: [Subprocessor List](https://medrecords.ai/subprocessors/) .

Data residency & retention
Customer Content is processed in the US only. At termination, PHI is returned within a 30-day export window, then destroyed (including backups) with a deletion certificate.
