Medical record retrieval built for legal teamsTalk with MedRex →
Sensitive data deserves disciplined handling

Security designed into the record workflow.

MedRex is presented as a secure legal-record platform. Final production claims should match your implemented controls, contracts, audit results, and certifications.

Core controls

Build trust with specific, verifiable safeguards.

This site uses security language that is appropriate for a platform handling PHI while avoiding certifications or audit claims that have not been supplied.

✓
EncryptionUse encryption in transit and at rest for PHI and other sensitive client data.
✓
Access controlApply role-based access, least-privilege principles, and documented user provisioning.
✓
Audit loggingRecord important user activity, request events, and administrative actions.
✓
Vendor governanceUse appropriate agreements and diligence for subprocessors that touch protected information.

Security page content blocks

Privacy & HIPAA programDescribe policies, workforce training, BAAs, permitted use, minimum necessary access, and privacy governance.
InfrastructureIdentify approved cloud environment, data residency, encryption, backup, monitoring, and disaster recovery.
Application controlsAuthentication, role-based permissions, session management, secure development, and vulnerability management.
Operational controlsBackground checks where applicable, workforce training, least privilege, secure devices, and incident handling.
Enterprise diligence

Make compliance documentation easy to request.

▣

Security packet

Provide a controlled diligence packet containing policies, architecture details, insurance, and audit documentation appropriate to the client.

⚿

Business associate agreements

Support a clear BAA process where legally required by the relationship and use of protected health information.

⎘

Data handling overview

Explain storage, transfer, retention, deletion, access logging, and subprocessors in plain language.

Need a security review?

Use the contact form to request a diligence discussion or security documentation.

Contact security →