Home / Trust Center
Trust & Compliance

Medarch Trust Center

Security, privacy and compliance information for every product in the Medarch eCare family — EHR, care coordination, RCM and our AI agents. Request our certifications, security documentation and Business Associate Agreement from one place.

HIPAA Compliant
SOC 2 Type II
ISO 27001 Certified
Healthcare providers using Medarch
Certifications & Frameworks

The standards we hold ourselves to

Medarch operates one security and compliance programme across the whole eCare product family. These are the frameworks that programme is built on, in plain English.

HIPAA Compliant

HIPAA

HIPAA is the US law that governs how protected health information is stored, transmitted and disclosed. Medarch builds and operates its products to meet the HIPAA Security and Privacy Rules, and signs a Business Associate Agreement with the covered entities it serves. [COMPLIANCE: confirm] the exact attestation wording, the date of the most recent HIPAA risk assessment, and whether a third party performed it.

[COMPLIANCE: confirm] current status
SOC 2 Type II Certified

SOC 2 Type II

A SOC 2 Type II report is an independent auditor's opinion on whether a company's security controls actually operated as described over a period of months — not just on a single day. It is the report most security reviewers ask for first. [COMPLIANCE: confirm] the audit period, which Trust Services Criteria are in scope, the audit firm, and the release process.

[COMPLIANCE: confirm] current status
ISO 27001 Certified

ISO/IEC 27001

ISO/IEC 27001 is the international standard for running an information security management system — a documented, audited way of identifying risk and managing controls over time. Certification is issued by an accredited body and re-checked on a fixed cycle. [COMPLIANCE: confirm] the certificate number, the scope statement, the certification body, and the issue and expiry dates.

[COMPLIANCE: confirm] current status

This list reflects the badges already published across medarch.com. [COMPLIANCE: confirm] the final certification list before launch — nothing has been added or removed here.

Security Practices

How we protect your data

The day-to-day controls behind the certifications. Full detail, including our current policies and control descriptions, is available on request.

Data Encryption

Protected health information is encrypted in transit and at rest across Medarch products. [COMPLIANCE: confirm] the cipher suites and TLS versions in use, the encryption standard applied at rest, and how encryption keys are managed and rotated.

Access Controls

Access to production systems and customer data is restricted to the people who need it for their role. [COMPLIANCE: confirm] the authentication requirements for staff, whether MFA is mandatory, the least-privilege model applied, and the access review cadence.

Audit Logging

System and user activity is logged so that access to patient records can be reconstructed and reviewed. [COMPLIANCE: confirm] which events are captured, how long logs are retained, whether logs are tamper-evident, and what audit reporting customers can access themselves.

Vulnerability Management

Medarch scans its products and infrastructure for known vulnerabilities and tracks remediation to closure. [COMPLIANCE: confirm] the scanning cadence, the penetration testing schedule and testing firm, and the remediation SLAs by severity.

Incident Response

Medarch maintains a documented incident response plan covering detection, containment, customer notification and post-incident review. [COMPLIANCE: confirm] the notification timeline committed to in customer agreements, the escalation path, and how often the plan is tested.

Employee Training

Everyone at Medarch who can reach customer data completes security and HIPAA privacy training. [COMPLIANCE: confirm] the training frequency, whether background checks are performed at hire, and how completion is tracked and evidenced for auditors.

HIPAA & BAA

Business Associate Agreements

When Medarch handles protected health information on behalf of a covered entity, HIPAA requires a Business Associate Agreement between us. Medarch signs a BAA with the practices, health systems and provider organisations it serves, and with business associates who route PHI through our products.

The BAA sets out how we may use and disclose PHI, the safeguards we are obliged to maintain, our breach notification duties, and what happens to your data when the agreement ends. [COMPLIANCE: confirm] the current BAA template version, who is authorised to countersign, and the expected turnaround time.

To request a BAA, or to have your own paper reviewed, submit a request through the Trust Center and our security team will route it to the right person.

Medarch: Empowering Providers By Simplifying Healthcare

One security and compliance programme covers the whole family — the same controls, the same policies, the same audits, across every product above.

[COMPLIANCE: confirm] that every product shown here is in scope for the current certifications — and flag any covered by a separate attestation.

Request Compliance Documents →
FAQ

Frequently Asked Questions

The questions security and procurement teams ask us most often during a review.

Medarch hosts customer data in US-based cloud data centres. [COMPLIANCE: confirm] the hosting provider, the specific regions in use, and whether any data or backups are replicated outside the United States.

Yes. Medarch enters into a Business Associate Agreement with covered entities and with business associates who route protected health information through our products. [COMPLIANCE: confirm] the current BAA template version, who countersigns it, and the expected turnaround time.

SOC 2 reports are released through the Medarch Trust Center at trust.medarch.com. [COMPLIANCE: confirm] whether an NDA is required before release, which report periods are currently available, and who approves each request.

Medarch's AI features are built to operate on protected health information under the same controls as the rest of the platform. [COMPLIANCE: confirm] which model providers are used, whether customer PHI is ever used to train models, what de-identification is applied, and how long AI inputs and outputs are retained.

Medarch maintains a current list of subprocessors that may process customer data. [COMPLIANCE: confirm] where the subprocessor list is published, how customers are notified of changes, and the notice period before a new subprocessor is engaged.

Medarch notifies affected customers of a confirmed security incident involving their data. [COMPLIANCE: confirm] the contractual notification window, the escalation path, and how notification obligations under the HIPAA Breach Notification Rule are met.

Customer data is retained for the life of the agreement, and export is available on termination. [COMPLIANCE: confirm] the retention period after termination, the export formats offered, and the timeline for secure deletion.

Medarch engages independent third parties to test its products and infrastructure. [COMPLIANCE: confirm] the testing cadence, the testing firm, the scope covered, and whether a summary report can be shared with customers.

Need our compliance documentation for your review?

Certifications, security documentation and BAA requests — all in one place.

Request Compliance Documents
HIPAA Compliant SOC 2 Type II Certified ISO 27001 Certified