MedDocket
Sign In

Privacy Policy

Last updated: July 2026

1. Who we are and our role

MedDocket is a product of Zycurion Intelligence LLP. When we process medical records on behalf of a law firm, we act as a business associate under HIPAA. A Business Associate Agreement (BAA) is executed with your firm before any records are uploaded. If anything in this policy conflicts with your executed BAA, the BAA controls.

2. What we collect

Account information: name, work email address, and firm name. Records: the medical records your firm uploads and the chronologies generated from them. Operational data: authentication events, access logs, IP addresses, and usage metadata required to secure the service and maintain audit trails. Billing information: invoicing details processed by our payment provider, which never receives record content. We do not use advertising trackers, and we do not sell data of any kind.

3. How we use it

To generate your chronologies, to operate and secure the service, to bill for it, and to meet legal obligations. Nothing else. Your records are never used to train AI models: processing runs on Amazon Bedrock, which does not retain or use customer inputs or outputs for model training.

4. Who else processes your data

One infrastructure provider: Amazon Web Services, which provides hosting, storage, and AI processing (Amazon Bedrock) under a signed AWS Business Associate Addendum. Records are stored in the AWS us-east-1 region in the United States. No other third party receives record content.

4a. Where our team is located

MedDocket is operated by Zycurion Intelligence LLP from India. Our personnel may access records and operational data to deliver, support, and secure the service. All such access is authenticated, least-privilege, protected by multi-factor authentication, and captured in audit logs as described in Sections 5 and 6. Records themselves are stored and processed in the AWS us-east-1 region in the United States and are not transferred to storage outside the United States.

5. How firm data is isolated

Every request is authenticated and scoped to your firm's account. Records are keyed to your firm's identifier, and access controls are enforced at the API layer so that credentials issued to one firm cannot be used to retrieve another firm's records. Administrative access requires separate credentials with multi-factor authentication, and all access to record data is captured in audit logs.

6. Security

Records are encrypted at rest (AES-256) and in transit (TLS 1.2 or higher). Access follows least-privilege principles, administrative accounts require multi-factor authentication, and data-level access events are logged for audit.

7. Data retention and deletion

Records are deleted within 30 days of your written request or account termination. Copies held in backups and point-in-time recovery expire within 60 days. Written certification of deletion is available on request.

8. Legally required disclosures

We disclose data only when required by valid legal process. Unless legally prohibited from doing so, we will notify your firm before complying so you have the opportunity to object.

9. Breach notification

If we discover a breach of unsecured protected health information, affected firms are notified without unreasonable delay and within the timelines required by the HIPAA Breach Notification Rule and your BAA.

10. Changes to this policy

Updates are posted on this page with a revised date. We will give notice of material changes before they take effect.

11. Contact

Questions about this policy: support@med-docket.com
We aim to respond within one business day.

© 2026 MedDocket · Zycurion Intelligence LLP · All rights reserved · Privacy Policy · Terms of Service · Sign In