MedsVouch

Security and privacy

What is in place today, and what is not.

This page is the current state. Nothing here is a certification. When something changes, this page will change.

In place today

  • MedsVouch is a browser prototype.
  • In the prototype, records stay on the device where they were entered.
  • Nothing is sent to MedsVouch.
  • Demo names are fake.
  • This website holds no patient information.
  • The demo and pilot form stores only the fields listed on the privacy page.
  • The site is served over HTTPS with standard browser security headers.

Not in place today

  • No cloud backend.
  • No HIPAA-ready hosting.
  • No business associate agreement (BAA) offered yet.
  • No SOC 2 audit.
  • No EMR or pharmacy integrations.
  • No single sign-on.
  • No version that installs on a phone.
  • No remote wipe of a lost device.

The plan, before records leave the device

These are planned. None are in place yet.

  • A custody ledger on a HIPAA-ready cloud backend.
  • A BAA with each hospice, and with every vendor that touches the data.
  • HIPAA Security Rule safeguards: a risk assessment, encryption, access controls, audit logs, written policies, a named security officer, and a breach plan.
  • Minimum data: medicines, counts, times, nurse IDs, and a patient code the hospice assigns. No patient names or diagnoses.
  • A SOC 2 Type I report before the first multi-site pilot, and Type II after that.

During a pilot

A pilot uses the browser prototype, and the record stays on the device. Demo data is fake and labeled.