MedDocket is a product of Zycurion Intelligence LLP. When we process medical records on behalf of a law firm, we act as a business associate under HIPAA. A Business Associate Agreement (BAA) is executed with your firm before any records are uploaded. If anything in this policy conflicts with your executed BAA, the BAA controls.
Account information: name, work email address, and firm name. Records: the medical records your firm uploads and the chronologies generated from them. Operational data: authentication events, access logs, IP addresses, and usage metadata required to secure the service and maintain audit trails. Billing information: invoicing details processed by our payment provider, which never receives record content. We do not use advertising trackers, and we do not sell data of any kind.
To generate your chronologies, to operate and secure the service, to bill for it, and to meet legal obligations. Nothing else. Your records are never used to train AI models: processing runs on Amazon Bedrock, which does not retain or use customer inputs or outputs for model training.
One infrastructure provider: Amazon Web Services, which provides hosting, storage, and AI processing (Amazon Bedrock) under a signed AWS Business Associate Addendum. Records are stored in the AWS us-east-1 region in the United States. No other third party receives record content.
MedDocket is operated by Zycurion Intelligence LLP from India. Our personnel may access records and operational data to deliver, support, and secure the service. All such access is authenticated, least-privilege, and captured in audit logs as described in Sections 5 and 6; interactive sign-in to the AWS account that holds records requires multi-factor authentication. Records themselves are stored and processed in the AWS us-east-1 region in the United States and are not transferred to storage outside the United States.
Every request is authenticated and scoped to your firm's account. Records are keyed to your firm's identifier, and access controls are enforced at the API layer so that credentials issued to one firm cannot be used to retrieve another firm's records. Administrative access to the underlying infrastructure uses credentials that are separate from any firm login and is not reachable through the firm dashboard. Storage-layer access to the record store is captured in an infrastructure audit trail, described in Section 6.
Records are encrypted at rest (AES-256) and in transit (TLS 1.2 or higher). Access follows least-privilege principles. Interactive sign-in to the AWS account that hosts the service requires multi-factor authentication. The internal tool used to provision firm accounts neither creates nor reads records; it is reachable only over TLS and is gated by a high-entropy shared secret held in AWS Secrets Manager, not by multi-factor authentication. Firm user accounts support optional authenticator-app two-factor authentication, which each user can enable from the dashboard. An infrastructure audit trail (AWS CloudTrail) records administrative actions on our AWS account, together with read and write operations against the record store and document storage. Those entries identify the service component that performed each operation; they do not yet attribute an individual user to each view of a specific chronology. Per-user access logging is on our roadmap, and we do not represent it here as an existing control.
Records are deleted within 30 days of your written request or account termination. Copies held in backups and point-in-time recovery expire within 60 days. Written certification of deletion is available on request.
We disclose data only when required by valid legal process. Unless legally prohibited from doing so, we will notify your firm before complying so you have the opportunity to object.
If we discover a breach of unsecured protected health information, affected firms are notified without unreasonable delay and within the timelines required by the HIPAA Breach Notification Rule and your BAA.
Updates are posted on this page with a revised date. We will give notice of material changes before they take effect.
Questions about this policy: support@med-docket.com
We aim to respond within one business day.