Home / Trust Center
Trust & Compliance

Medarch Trust Center

Security, privacy and compliance information for every product in the Medarch eCare family — EHR, care coordination, RCM and our AI agents. Request our certifications, security documentation and Business Associate Agreement from one place.

HIPAA Compliant
SOC 2 Type II
ISO 27001 Certified
Compliance documentation and security certification
Certifications & Frameworks

The standards we hold ourselves to

Medarch follows recognized security, privacy, and compliance standards across the eCare product family. Here’s what each framework means for our approach to protecting healthcare data and maintaining strong security practices.

HIPAA Compliant

HIPAA

HIPAA is the US law that governs how protected health information is stored, transmitted, and disclosed. Medarch builds its products to support HIPAA requirements and signs a Business Associate Agreement with the covered entities it serves.

HIPAA Assessment: Aegisra Assurance LLP on July 16 2026.

SOC 2 Type II Certified

SOC 2 Type II

SOC 2 Type II evaluates whether an organization’s security controls are suitably designed and operating effectively over a defined period. Medarch is pursuing SOC 2 Type II to strengthen and independently validate its security controls and operational practices.

ISO 27001 Certified

ISO/IEC 27001

ISO/IEC 27001 is an international standard for establishing and continually improving an information security management system (ISMS). Medarch is pursuing alignment with ISO/IEC 27001 to formalize its approach to identifying risks, managing controls, and continuously improving information security.

Security Practices

How we protect your data

Medarch follows established security and privacy practices across the eCare product family to help protect customer and patient data. These practices cover how we secure information, control access, monitor activity, and respond to potential security incidents.

Data Encryption

Protected health information is encrypted in transit and at rest across Medarch products. We use industry-standard encryption practices to help protect sensitive information as it moves between systems and while it is stored.

Access Controls

Access to production systems and customer data is limited based on role and business need. Medarch applies access control practices designed to follow the principle of least privilege and help ensure sensitive information is accessible only to authorized personnel.

Audit Logging

System and user activity is logged to support security monitoring, investigation, and accountability. Logs help Medarch track relevant activity across systems and investigate potential security events when needed.

Vulnerability Management

Medarch regularly assesses its products and infrastructure for potential security vulnerabilities and works to address identified issues. Our vulnerability management practices help us identify, prioritize, and remediate security risks.

Incident Response

Medarch maintains incident response practices to help identify, contain, investigate, and respond to potential security incidents. These practices support coordinated response, appropriate escalation, and post-incident review.

Employee Training

Employees with access to customer data receive security and privacy training appropriate to their responsibilities. Training helps reinforce secure handling of information, awareness of security risks, and our data protection practices.

HIPAA & BAA

Business Associate Agreements

When Medarch handles protected health information (PHI) on behalf of a covered entity, a Business Associate Agreement (BAA) helps establish the responsibilities and safeguards required under HIPAA.

Medarch works with healthcare practices, health systems, provider organizations, and other covered entities that require a BAA when using our products and services.

The BAA outlines the permitted use and disclosure of PHI, applicable safeguards, breach notification responsibilities, and other obligations related to protecting healthcare information.

To request a BAA or discuss your organization's requirements, contact our team.

Medarch: Empowering Providers By Simplifying Healthcare

One security and compliance programme covers the whole family — the same controls, the same policies, the same audits, across every product above.

Every product shown here is in scope for the current certifications — and flag any covered by a separate attestation.

Request Compliance Documents →
FAQ

Frequently Asked Questions

The questions security and procurement teams ask us most often during a review.

Medarch uses cloud infrastructure to host customer data and applies security practices designed to protect information stored within its environment. Specific hosting providers, data-center locations, regions, and data-residency details can be provided as part of a security review.

Yes. Medarch enters into Business Associate Agreements with covered entities when required under HIPAA. The BAA establishes the responsibilities of each party for protecting and handling protected health information.

Medarch is currently pursuing SOC 2 Type II. A SOC 2 Type II report will be made available to eligible customers or prospects once the assessment is completed and the report is available.

Medarch designs its AI-enabled features with privacy and security considerations for healthcare data. Specific details about AI providers, data processing, model training, de-identification, and data retention can be addressed during a security review.

Medarch works with third-party service providers that may support the delivery and operation of its products. Details about subprocessors and the services they provide can be shared as part of the security and procurement review process.

Medarch maintains processes for responding to potential security incidents and addressing applicable notification obligations. Specific contractual and notification requirements are addressed in the applicable agreements with customers.

Data retention and export practices depend on the applicable agreement and product. Medarch can provide customers with information about applicable retention periods, data export options, and data deletion procedures during the procurement or security review process.

Medarch engages independent third parties to test its products and infrastructure.

Get a Free Quote Book Free Demo