mednbotmednbot
Security & Compliance

Security you can verify. Privacy patients can trust.

MednBot is built for regulated healthcare environments from the ground up. This page is the single, authoritative source for our security architecture, privacy practices, sub-processors, and compliance roadmap.

Last updated July 2026 · Reviewed quarterly

HIPAA Program
Live

Administrative, physical, and technical safeguards in place. BAAs available.

Multi-State AI Compliance
52 jurisdictions

Jurisdiction-aware AI disclosures and consent enforcement across all 50 states, DC, and Puerto Rico. Counsel-reviewed language; versioned consent records.

SOC 2 Type II
Audit-ready

Controls implemented and audit evidence accumulating now — the Type II observation window is already running. Auditor engagement timed to cover a full window; Type I targeted H2 2026, Type II H1 2027.

Data Residency
United States

All customer data is stored and processed in U.S. AWS regions.

Encryption
AES-256 / TLS 1.2+

All data encrypted at rest and in transit. Keys managed via AWS KMS.

Multi-tenant Isolation
Enforced

Every query is scoped to a single customer tenant; cross-tenant access is denied by design.

Independent Pen Test
Scheduled

First external penetration test scheduled to complete H2 2026; annual cadence thereafter.

Compliance & Attestations

Anchored in HIPAA. Formalizing against SOC 2.

HIPAA

MednBot operates as a HIPAA Business Associate. We maintain administrative, physical, and technical safeguards consistent with 45 CFR Parts 160 and 164, including the Security Rule, Privacy Rule, and Breach Notification Rule. Business Associate Agreements are available to every customer at no charge.

SOC 2 (audit-ready, evidence accumulating)

We built our SOC 2 program in-house first: policies, control mappings to the Trust Services Criteria, and an evidence system that captures audit artifacts continuously in production. A Type II report requires a multi-month observation window that cannot be compressed — ours is already running, so engaging the independent auditor becomes a fast final step rather than the start of the clock. Type I attestation targeted H2 2026; Type II report following a full observation window, H1 2027.

State AI & Privacy Law (all 50 states + DC + PR)

MednBot ships a jurisdiction-aware compliance engine covering every U.S. state, DC, and Puerto Rico: the platform resolves the state whose law governs each patient interaction and applies that state's requirements — AI-disclosure statutes (e.g., California AB 3030, Texas TRAIGA, Utah, Illinois), all-party recording-consent rules, telehealth informed consent, and biometric-privacy notices — with counsel-reviewed language, strictest-state defaults for any unresolved jurisdiction, and versioned records of exactly which disclosure each patient saw and accepted. Statutes taking effect through 2027 are already tracked.

Roadmap

Our compliance roadmap includes annual independent penetration testing, SOC 2 Type II renewal, and HITRUST evaluation as enterprise demand warrants. Confirmed timelines are shared under NDA on request.

Data Protection

Encrypted, isolated, and recoverable.

Encryption at Rest

All customer data, including protected health information and uploaded media, is encrypted at rest with AES-256. Encryption keys are managed through AWS Key Management Service with audited key access.

Encryption in Transit

All connections between clients and MednBot, and between MednBot and its sub-processors, are protected using TLS 1.2 or higher with modern cipher suites. HTTP traffic is redirected to HTTPS at the application edge.

Backups & Recovery

The primary database is backed up automatically with point-in-time recovery enabled. Object storage is versioned. Recovery procedures are documented; recovery objectives are shared under NDA on request.

Retention & Deletion

Customer data is retained for the lifetime of the customer relationship and any contractually agreed retention window thereafter. On verified customer request, data is purged using documented procedures that traverse all related records in referentially safe order.

Sub-processors

Who we work with, and why.

MednBot engages the following third-party service providers to support delivery of the platform. Business Associate Agreements are in place where the sub-processor may process protected health information. The list is updated as relationships change.

Sub-processorPurposeData CategoryRegion
Amazon Web ServicesCloud infrastructure, object storage, transactional email, SMS/voice notifications, monitoringApplication data, PHIUnited States
NeonManaged PostgreSQL database hostingApplication data, PHIUnited States
StripePayment processing and subscription billingBilling data (no PHI)United States
xAILarge language model inference for clinical assistant featuresConversation content (may contain PHI)United States
D-IDGenerative video avatar renderingDoctor likeness, voice, prompt contentUnited States / Vendor-managed
Claim.MDInsurance eligibility, claim submission, ERA processingClaims data, PHIUnited States

Customers may subscribe to be notified of material changes to this list. To subscribe, contact compliance@mednbot.com.

Privacy

We process data for you, not on you.

MednBot processes personal information and protected health information on behalf of our customers, who are the data controllers. We do not sell personal information. We do not use protected health information to train third-party, general-purpose AI models. Customers remain responsible for issuing Notices of Privacy Practices to their patients consistent with HIPAA. See our Privacy Policy for how MednBot processes information across the platform.

Incident Response

Detect, contain, notify.

MednBot maintains a documented incident response program covering detection, containment, eradication, recovery, and post-incident review. In the event of a confirmed security incident affecting customer data, MednBot will notify affected customers without unreasonable delay and in accordance with applicable Business Associate Agreement obligations and the HIPAA Breach Notification Rule.

Report a suspected security issue at any time by emailing security@mednbot.com. We acknowledge credible reports within one business day.

Responsible Disclosure

Good-faith research is welcome.

If you believe you have discovered a vulnerability in any MednBot product, please report it to security@mednbot.com. Provide enough detail to reproduce the issue, and please do not access data that does not belong to you, degrade service for others, or disclose the issue publicly before we have had a reasonable opportunity to remediate. We credit researchers who request it once the report is resolved.

Need our full security package?

Enterprise buyers can request our security overview, sub-processor change log, sample Business Associate Agreement, HIPAA risk assessment summary, and current SOC 2 status memo. Materials are shared under a mutual NDA.