Skip to main content
Medera operates under a HIPAA-grade, 42 CFR Part 2-aware controls program. Every request runs through a tenant-scoped runtime with Row-Level Security, encrypted PHI encryption, and Merkle-tree audit integrity.

HIPAA

Access control, audit, integrity, transmission security.

42 CFR Part 2

SUD data with explicit consent + re-disclosure.

BAA / DPA

Business Associate Agreement + Data Processing Addendum.

Sub-processors

Current sub-processor list.

Security Controls

Encryption, audit, RLS, access control.

Data Residency

US, EU, customer-VPC options.

Certifications and posture