Skip to content

Security and compliance claims as published on mediyn.com

Security and compliance claims as published on mediyn.com

Section titled “Security and compliance claims as published on mediyn.com”

Site path: /security

  • Mediyn is described as HIPAA compliant.
  • A Business Associate Agreement (BAA) is included on every plan — not gated behind an enterprise tier.
  • The BAA is signed automatically at signup (per /privacy-first page).
  • The footnote states: “HIPAA compliant · BAA included · SOC 2 Type II · 256-bit AES.”

On-Device PHI Redaction and De-identification

Section titled “On-Device PHI Redaction and De-identification”

Site path: /security

  • By default, Mediyn’s redaction engine runs on the device, finding names, dates, addresses, and other identifiers in the raw session and replacing them with tokens before anything is uploaded.
  • What lands on the servers is described as a de-identified clinical note — structurally complete, but not re-identifiable.
  • In the rare case on-device processing is not available, the app falls back to a secure encrypted upload that is deleted once notes are ready.
  • Every document is labeled with where it was processed.
  • The following data items are listed as staying on device: names & contacts, dates of birth, addresses, raw audio.
  • The following items are listed as reaching the cloud: de-identified note, token placeholders, clinical structure, nothing re-identifiable.
  • The site claims this represents “a fundamentally smaller attack surface than ‘upload everything, secure it later.’”
  • Raw audio is stated to never leave the device.

Site path: /security

  • Data in transit is encrypted with TLS 1.3.
  • Data at rest is encrypted with AES-256.
  • Encryption keys are held in a hardware security module (HSM).
  • The defense-in-depth panel labels these as five independent layers: on device, in transit, at rest, access, and audit.
  • Each layer is described as independently encrypted, independently audited, and independently configurable.

Site path: /security

  • Every access, edit, and action is logged.
  • The audit trail is described as tamper-evident and append-only (immutable).
  • Retention period is seven years.
  • The audit trail is exportable for audits and investigations.
  • Items logged include: chart views, claim submissions, role changes, and system payment postings.
  • The audit trail is described as covering every view, edit, and action.

Site path: /security

  • Multi-factor authentication (MFA) is required for all staff and can be required for every account.
  • Access is role-based with least-privilege permissions.
  • Periodic access recertification is performed on a quarterly basis.
  • Trusted-device registration is supported; the panel example shows 2 registered devices.
  • PHI is masked in the UI for non-clinical roles.
  • PHI masking is described as server-side, not hidden with CSS (per /privacy-first page).
  • Re-authentication is required to unmask sensitive fields, and every unmasking event is logged in the immutable audit trail.

Privacy Policy Controls and De-identification Configuration

Section titled “Privacy Policy Controls and De-identification Configuration”

Site path: /security

  • Redaction profile is configurable; the default/example shown is “Strict (names, dates, IDs).”
  • PHI masking in the UI is configurable and is on for non-clinical roles.
  • A consent ledger is maintained per consent type, with withdrawal supported.
  • Data retention is configurable per policy.

Site path: /security

  • Mediyn claims SOC 2 Type II certification.
  • SOC 2 Type II is listed in the compliance panel alongside HIPAA and 256-bit AES.

Site path: /security

  • Mediyn claims No Surprises Act (Good Faith Estimate, GFE) support.
  • The /privacy-first page adds: GFE generation, delivery, and acknowledgment are supported.

Site path: /security

  • Mediyn states it does not train models on identifiable (PHI) data.
  • Mediyn states it does not sell or share client data.
  • These commitments are described as being put in writing via the signed BAA.
  • Users can export or delete their data at any time.
  • The /privacy-first page adds: session recordings, transcripts, clinical notes, messages, and assessment responses are never used as training data — not for Mediyn’s own models, and not for third-party language model providers, who operate under zero-retention agreements.

Site path: /security

  • Client portal login uses passwordless magic links — no credentials to steal or phish.
  • Biometric device authentication is used to confirm identity on trusted devices.
  • Clients only see data scoped to their clinician-set permission level (role-scoped PHI masking).
  • Secure in-app messaging is therapist-initiated, text only, with no file uploads.
  • Assessments and worksheets are submitted through encrypted channels.
  • Invoice access and payment are available without exposing clinical records.
  • Every client portal action (view, submit, message) is logged in the immutable audit trail.

Site path: /security

  • Raw audio files exist only on the device and are encrypted at rest.
  • If a device is lost, the token-mapping data linking de-identified transcripts to client identifiers is inaccessible without biometric or device passcode.
  • Trusted devices can be remotely revoked from account settings.
  • Mediyn’s access controls are designed so that support staff cannot access clinical content during normal operations.

Site path: /security

  • When a video session is conducted through Mediyn’s built-in telehealth, audio is processed through the same on-device transcription and PHI redaction pipeline.
  • Video streams are encrypted in transit and at rest.
  • Sessions are not recorded unless recording is explicitly enabled.

Site path: /security

  • After account closure, users have 90 days to retrieve clinical data.
  • After 90 days, personal information is deleted.
  • Clinical records are retained only as long as required by HIPAA and applicable state retention laws, described as typically 6–7 years.