Medarch Trust Center
Security, privacy and compliance information for every product in the Medarch eCare family — EHR, care coordination, RCM and our AI agents. Request our certifications, security documentation and Business Associate Agreement from one place.
The standards we hold ourselves to
Medarch follows recognized security, privacy, and compliance standards across the eCare product family. Here’s what each framework means for our approach to protecting healthcare data and maintaining strong security practices.
HIPAA
HIPAA is the US law that governs how protected health information is stored, transmitted, and disclosed. Medarch builds its products to support HIPAA requirements and signs a Business Associate Agreement with the covered entities it serves.
HIPAA Assessment: Aegisra Assurance LLP on July 16 2026.
SOC 2 Type II
SOC 2 Type II evaluates whether an organization’s security controls are suitably designed and operating effectively over a defined period. Medarch is pursuing SOC 2 Type II to strengthen and independently validate its security controls and operational practices.
ISO/IEC 27001
ISO/IEC 27001 is an international standard for establishing and continually improving an information security management system (ISMS). Medarch is pursuing alignment with ISO/IEC 27001 to formalize its approach to identifying risks, managing controls, and continuously improving information security.
How we protect your data
Medarch follows established security and privacy practices across the eCare product family to help protect customer and patient data. These practices cover how we secure information, control access, monitor activity, and respond to potential security incidents.
Data Encryption
Protected health information is encrypted in transit and at rest across Medarch products. We use industry-standard encryption practices to help protect sensitive information as it moves between systems and while it is stored.
Access Controls
Access to production systems and customer data is limited based on role and business need. Medarch applies access control practices designed to follow the principle of least privilege and help ensure sensitive information is accessible only to authorized personnel.
Audit Logging
System and user activity is logged to support security monitoring, investigation, and accountability. Logs help Medarch track relevant activity across systems and investigate potential security events when needed.
Vulnerability Management
Medarch regularly assesses its products and infrastructure for potential security vulnerabilities and works to address identified issues. Our vulnerability management practices help us identify, prioritize, and remediate security risks.
Incident Response
Medarch maintains incident response practices to help identify, contain, investigate, and respond to potential security incidents. These practices support coordinated response, appropriate escalation, and post-incident review.
Employee Training
Employees with access to customer data receive security and privacy training appropriate to their responsibilities. Training helps reinforce secure handling of information, awareness of security risks, and our data protection practices.
Business Associate Agreements
When Medarch handles protected health information (PHI) on behalf of a covered entity, a Business Associate Agreement (BAA) helps establish the responsibilities and safeguards required under HIPAA.
Medarch works with healthcare practices, health systems, provider organizations, and other covered entities that require a BAA when using our products and services.
The BAA outlines the permitted use and disclosure of PHI, applicable safeguards, breach notification responsibilities, and other obligations related to protecting healthcare information.
To request a BAA or discuss your organization's requirements, contact our team.
Medarch: Empowering Providers By Simplifying Healthcare
One security and compliance programme covers the whole family — the same controls, the same policies, the same audits, across every product above.
Every product shown here is in scope for the current certifications — and flag any covered by a separate attestation.
Request Compliance Documents →Frequently Asked Questions
The questions security and procurement teams ask us most often during a review.
Medarch uses cloud infrastructure to host customer data and applies security practices designed to protect information stored within its environment. Specific hosting providers, data-center locations, regions, and data-residency details can be provided as part of a security review.
Yes. Medarch enters into Business Associate Agreements with covered entities when required under HIPAA. The BAA establishes the responsibilities of each party for protecting and handling protected health information.
Medarch is currently pursuing SOC 2 Type II. A SOC 2 Type II report will be made available to eligible customers or prospects once the assessment is completed and the report is available.
Medarch designs its AI-enabled features with privacy and security considerations for healthcare data. Specific details about AI providers, data processing, model training, de-identification, and data retention can be addressed during a security review.
Medarch works with third-party service providers that may support the delivery and operation of its products. Details about subprocessors and the services they provide can be shared as part of the security and procurement review process.
Medarch maintains processes for responding to potential security incidents and addressing applicable notification obligations. Specific contractual and notification requirements are addressed in the applicable agreements with customers.
Data retention and export practices depend on the applicable agreement and product. Medarch can provide customers with information about applicable retention periods, data export options, and data deletion procedures during the procurement or security review process.
Medarch engages independent third parties to test its products and infrastructure.