MedDocket is a product of Zycurion Intelligence LLP. When we process medical records on behalf of a law firm, we act as a business associate under HIPAA. A Business Associate Agreement (BAA) is executed with your firm before any records are uploaded. If anything in this policy conflicts with your executed BAA, the BAA controls.
Account information: name, work email address, and firm name. Records: the medical records your firm uploads and the chronologies generated from them. Operational data: authentication events, access logs, IP addresses, and usage metadata required to secure the service and maintain audit trails. Billing information: invoicing details processed by our payment provider, which never receives record content. We do not use advertising trackers, and we do not sell data of any kind.
To generate your chronologies, to operate and secure the service, to bill for it, and to meet legal obligations. Nothing else. Your records are never used to train AI models: processing runs on Amazon Bedrock, which does not retain or use customer inputs or outputs for model training.
One infrastructure provider: Amazon Web Services, which provides hosting, storage, and AI processing (Amazon Bedrock) under a signed AWS Business Associate Addendum. Records are stored in the AWS us-east-1 region in the United States. No other third party receives record content.
MedDocket is operated by Zycurion Intelligence LLP from India. Our personnel may access records and operational data to deliver, support, and secure the service. All such access is authenticated, least-privilege, protected by multi-factor authentication, and captured in audit logs as described in Sections 5 and 6. Records themselves are stored and processed in the AWS us-east-1 region in the United States and are not transferred to storage outside the United States.
Every request is authenticated and scoped to your firm's account. Records are keyed to your firm's identifier, and access controls are enforced at the API layer so that credentials issued to one firm cannot be used to retrieve another firm's records. Administrative access requires separate credentials with multi-factor authentication, and all access to record data is captured in audit logs.
Records are encrypted at rest (AES-256) and in transit (TLS 1.2 or higher). Access follows least-privilege principles, administrative accounts require multi-factor authentication, and data-level access events are logged for audit.
Records are deleted within 30 days of your written request or account termination. Copies held in backups and point-in-time recovery expire within 60 days. Written certification of deletion is available on request.
We disclose data only when required by valid legal process. Unless legally prohibited from doing so, we will notify your firm before complying so you have the opportunity to object.
If we discover a breach of unsecured protected health information, affected firms are notified without unreasonable delay and within the timelines required by the HIPAA Breach Notification Rule and your BAA.
Updates are posted on this page with a revised date. We will give notice of material changes before they take effect.
Questions about this policy: support@med-docket.com
We aim to respond within one business day.