Legal

Privacy Policy

Effective date: July 23, 2026

HIPAASOC 2 Type II (in progress)BAA available

Medera, Inc. (“Medera,” “we,” “us,” or “our”) is committed to protecting the privacy, confidentiality and security of all personal information and Protected Health Information (“PHI”) entrusted to us. This Policy describes the categories of information we collect, the purposes for which we process it, the safeguards we maintain, and the rights you may exercise with respect to your data.

Scope & applicability

This Policy applies to all users of Medera’s AI-powered behavioral health platform, including healthcare providers, their authorized staff, covered entities, business associates, and patients whose information is processed through our Services. It covers all data collected and processed through our platform, websites, APIs, mobile applications and related services (collectively, the “Services”), including:

  • All web-based and API interactions with our clinical AI platform
  • Data transmitted through integrations with Electronic Health Record (EHR) systems
  • Information collected via customer support, sales and onboarding
  • Data processed by our subprocessors and third-party service providers
  • Aggregated and de-identified datasets derived from PHI for model improvement
Where Medera processes PHI on behalf of a Covered Entity, the terms of the applicable Business Associate Agreement (“BAA”) control to the extent of any conflict with this Policy.

Information we collect

Healthcare provider information

  • Professional credentials, NPI numbers and licensing information
  • Contact information (name, email, phone, practice address)
  • Organization affiliation, role and department
  • Authentication credentials and multi-factor authentication tokens
  • Usage data, platform interactions and feature adoption metrics

Protected Health Information (PHI)

  • Clinical notes, assessments and behavioral health evaluations
  • Treatment plans, progress notes and care coordination records
  • Diagnostic information (DSM-5, ICD-10/11 codes)
  • Voice recordings and transcriptions, with explicit, revocable consent
  • Patient demographics and insurance identifiers

Technical & operational information

  • IP addresses, device identifiers and browser data
  • Browser type, operating system and screen resolution
  • Session logs, timestamps and API call metadata
  • Performance metrics, error logs and system telemetry
  • Coarse geolocation derived from IP address only

Business & billing information

  • Organization name, billing address and tax identification numbers
  • Payment method details, processed and stored by PCI DSS-compliant payment processors; Medera does not store raw payment card data
  • Subscription tier, usage volumes and invoice history

How we use information

Service delivery & clinical support

To deliver AI-powered clinical insights, generate evidence-based treatment recommendations, facilitate behavioral health assessments and support clinical decision-making workflows. PHI is processed solely to provide the contracted Services as described in the applicable BAA.

Platform operations & improvement

To maintain, monitor and improve the reliability, performance and security of our platform. Where we use data for model training or algorithmic improvement, we use only de-identified datasets that meet the HIPAA Safe Harbor or Expert Determination standard under 45 CFR § 164.514.

Compliance, audit & safety

To meet regulatory obligations under HIPAA, state privacy laws and other applicable statutes; to conduct internal and third-party audits; and to detect, prevent and respond to fraud, abuse, security incidents and threats to patient safety.

Communications & support

To respond to support requests, deliver service notifications, provide onboarding materials and communicate material changes to our Services or policies. We do not use PHI for marketing purposes under any circumstances.

Data protection & security

Medera maintains a comprehensive, enterprise-grade security program designed to protect the confidentiality, integrity and availability of all data processed through our platform. Our controls are being independently evaluated through a SOC 2 Type II audit currently in progress, alongside continuous third-party penetration testing.

  • Encryption at rest. AES-256-GCM for all data at rest, with HSM-backed key management and automated 90-day key rotation.
  • Encryption in transit. TLS 1.3 enforced on all endpoints, with certificate pinning for mobile clients and forward secrecy enabled.
  • Access controls. Role-based access control with least privilege, MFA for all users, and just-in-time provisioning for administrative functions.
  • Network security. Zero-trust architecture with micro-segmentation, WAF, DDoS protection and intrusion detection and prevention.
  • PHI tokenization. PHI is tokenized at the application layer before storage; de-identification pipelines meet HIPAA Safe Harbor standards.
  • Vulnerability management. Continuous automated scanning, annual third-party penetration testing and a responsible disclosure program, with critical vulnerabilities remediated in under 24 hours.

Audit trail

  • All PHI access, creation, modification and deletion events are logged
  • Audit logs are retained for a minimum of six (6) years per HIPAA requirements
  • Logs include user identity, timestamp, action performed, data elements accessed and source IP address

Incident response

  • Documented Incident Response Plan tested via tabletop exercises at least twice annually
  • Dedicated Security Operations Center with 24/7/365 monitoring
  • Mean time to detect target of under 15 minutes for critical incidents
  • Forensic investigation capabilities maintained in-house and via contracted specialists

HIPAA compliance

Medera operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). We execute HIPAA-compliant BAAs with all Covered Entities before receiving PHI. Our program includes:

  • Administrative safeguards. Designated Privacy and Security Officers; mandatory workforce HIPAA training at hire and annually; a formal sanctions policy; a documented risk analysis and risk management program updated at least annually; background checks for personnel with PHI access; and contingency planning including backup, disaster recovery and emergency mode operation.
  • Physical safeguards. Data hosted in SOC 2 Type II-certified cloud infrastructure with physical access controls; workstation security including full-disk encryption and automatic screen lock; and NIST SP 800-88 media disposal procedures.
  • Technical safeguards. Unique user identification with audit controls on all PHI access; automatic session termination; break-the-glass emergency access with post-access review; encryption exceeding the HIPAA addressable specification; and integrity controls to detect unauthorized alteration of PHI.
  • Minimum necessary. The platform limits PHI exposure to only the data elements required for each specific authorized purpose.

SOC 2 Type II audit

Medera has a SOC 2 Type II audit in progress, conducted by an independent, AICPA-accredited auditing firm, scoped to the Security, Availability, Confidentiality and Privacy Trust Services Criteria. A SOC 2 Type II audit evaluates the operational effectiveness of controls over a continuous observation period. The report will be made available to enterprise customers upon completion; for current status, contact hi@medera.info.

Information sharing & subprocessors

Medera does not sell, rent or trade your personal information or PHI under any circumstances. We share information only:

  • With your explicit, documented consent or at the direction of the Covered Entity
  • To comply with applicable laws, legal process or enforceable governmental requests
  • With subprocessors bound by written agreements no less protective than this Policy and applicable BAAs
  • In connection with a merger, acquisition or sale of assets, with prior written notice to affected Covered Entities
  • To protect the rights, safety or property of Medera, our users or the public, as permitted by law
  • For de-identified research purposes where data meets the HIPAA Safe Harbor or Expert Determination standard

Subprocessor management

  • Security assessment and compliance review before engagement
  • Written subprocessor agreements with HIPAA flow-down provisions
  • Annual reassessment of security posture and compliance standing
  • Right to audit subprocessors upon reasonable notice
  • Thirty (30) days advance written notice to Covered Entities before engaging a new subprocessor that will process their PHI, with the right to object

Current subprocessor categories include our cloud infrastructure provider (SOC 2 Type II, HIPAA-eligible), payment processor (PCI DSS Level 1), transactional email provider (BAA in place), application performance monitoring (de-identified telemetry only) and customer support platform (with PHI access controls and BAA). A complete list is available upon request.

Breach notification

In the event of a breach of unsecured PHI, Medera will comply with HIPAA breach notification requirements and all applicable state breach notification laws:

  • Written notification to the affected Covered Entity without unreasonable delay and no later than thirty (30) calendar days after discovery, identifying affected individuals, the type of PHI involved, the dates of breach and discovery, and our investigation, mitigation and prevention steps
  • Breaches affecting 500 or more individuals reported to the HHS Secretary and prominent media within sixty (60) days; smaller breaches logged and reported annually
  • State Attorney General notifications as required by applicable state law
  • Immediate containment and forensic investigation, with a root cause analysis and corrective action plan documented within fourteen (14) days
  • Credit monitoring and identity protection offered to affected individuals where warranted

Data retention & deletion

  • Active service period. PHI and personal data are retained for the duration of the active service agreement with the Covered Entity.
  • Post-termination. Upon contract termination, PHI is returned or securely destroyed within thirty (30) calendar days per the BAA, with a certificate of destruction available upon request.
  • Audit logs. Access and security event records are retained for a minimum of six (6) years to satisfy HIPAA requirements.
  • Legal holds. Data subject to litigation hold or regulatory investigation is retained until the hold is released.

Secure deletion follows NIST SP 800-88-compliant sanitization; for encrypted data, cryptographic erasure is employed as an equivalent method.

Data residency & transfers

All PHI and primary personal data are processed and stored within the United States. Medera does not transfer PHI outside the United States without the prior written consent of the applicable Covered Entity.

  • Primary infrastructure in U.S.-based, HIPAA-eligible, SOC 2 Type II-certified data centers
  • Redundant failover within U.S. geographic regions for disaster recovery
  • Where international transfer is authorized: Standard Contractual Clauses, Binding Corporate Rules or other recognized mechanisms
  • Supplemental technical measures (encryption, pseudonymization) on all cross-border transfers
  • Transfer Impact Assessments for any new international data flow

Your rights

Depending on your jurisdiction and the nature of the data, you may have the rights below. To exercise any right, contact hi@medera.info. We respond to all verified requests within thirty (30) calendar days, or the shorter timeline required by applicable law.

  • Access. Request a copy of the personal data or PHI we hold about you, including categories, purposes and recipients.
  • Correction. Request amendment of inaccurate or incomplete data, subject to clinical record-keeping requirements.
  • Deletion. Request deletion, subject to legal retention obligations, litigation holds and HIPAA record-keeping requirements.
  • Portability. Receive your data in a structured, machine-readable format (for example JSON or CSV).
  • Restriction and objection. Request that we restrict processing, or object to processing based on legitimate interests.
  • Withdraw consent. Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
  • Non-discrimination. Exercise any of these rights without discriminatory treatment in service quality, level or pricing.

U.S. state privacy laws

California residents have additional rights under the CCPA as amended by the CPRA, including the right to know, delete, opt out of sales and sharing, and limit use of sensitive personal information. Medera does not sell personal information. We also comply with privacy laws in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA) and other states with comprehensive privacy legislation, and we maintain a mapping of state-specific breach notification requirements.

International compliance (GDPR)

Where the EU GDPR or UK GDPR applies, Medera acts as a Data Processor on behalf of the Data Controller (typically the healthcare organization). Our commitments include Data Processing Agreements incorporating Standard Contractual Clauses; Data Protection Impact Assessments for high-risk processing; Article 30 records of processing; an EU/EEA representative where required; 72-hour breach notification to supervisory authorities and notification to Data Controllers without undue delay; and support for data subject rights including access, portability and erasure.

AI & machine learning disclosures

  • Model training data. AI models are trained exclusively on de-identified datasets meeting HIPAA Safe Harbor or Expert Determination standards. No identifiable PHI is used in training, fine-tuning or evaluation, and training data undergoes bias assessment and fairness auditing.
  • Automated decision-making. Medera’s AI generates recommendations as decision-support only. No automated decisions with legal or similarly significant effects are made without human clinician review and approval; providers retain full authority over all clinical decisions.
  • Explainability & audit. Outputs include confidence scores and supporting evidence references. Performance is monitored continuously for accuracy, bias and drift; board-certified clinicians review outputs under our Clinical Oversight Program; model cards and algorithmic impact assessments are available to enterprise customers upon request.

Cookies & tracking

Medera uses strictly necessary cookies to operate the platform and optional analytics cookies to improve service quality. We do not use advertising or cross-site tracking cookies.

  • Strictly necessary. Session management, authentication, security tokens and load balancing; these cannot be disabled.
  • Functional. User preferences, language settings and interface customization.
  • Analytics. Aggregated, de-identified usage analytics; no PHI is included in analytics data.

You may manage cookie preferences through your browser settings or our consent banner; disabling optional cookies will not affect core platform functionality.

Children's privacy

Medera’s Services are designed for licensed healthcare providers and authorized clinical staff. We do not knowingly collect personal information directly from children under 13 (or the applicable age of consent). Where PHI of minors is processed through our platform, it is collected and managed by the treating healthcare provider in accordance with applicable law, including parental consent requirements. If we become aware of information collected from a child without appropriate authorization, we will promptly delete it.

Text messaging & mobile information

This section applies to the Medera Health Care-Team Notifications text messaging program (effective July 23, 2026) and supplements the rest of this Policy. For the program, we collect your name, contact details (including mobile phone number) and health-coverage information you choose to share with your care team, such as a photo of your insurance card submitted through our secure verification link. We use this information solely to provide your care services: verifying insurance coverage, coordinating appointments and communicating with you about your care.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, excluding vendors and aggregators acting solely on our behalf to deliver messages.

Insurance card photos travel via single-use, time-limited secure links with encrypted transmission, and this information is retained only as long as needed to provide your care and as required by law. You may opt out of text messages at any time by replying STOP, or reply HELP for help. You may request access, correction or deletion by contacting your care team at (681) 432-3260 or hi@medera.info. See also our SMS program page and the SMS Terms & Conditions within our Terms of Service.

Changes to this Policy

We may update this Policy to reflect changes in our practices, technologies or legal requirements. Material changes will be communicated to Covered Entities and registered users via email at least thirty (30) calendar days before the effective date; non-material changes may be posted directly on this page. Continued use of the Services after the effective date of a revised Policy constitutes acceptance of the updated terms.

Contact & Data Protection Officer

For questions, concerns or requests related to this Policy or our data protection practices, contact our Privacy & Compliance Team or Data Protection Officer at hi@medera.info.

Questions about this document?

Our privacy and legal team responds to verified requests within thirty days, and usually much sooner.