Security & Compliance

Security that feels clear, disciplined, and ready for review.

We are built for healthcare from the ground up with the compliance certifications, encryption standards, and security infrastructure that growing specialty practices and health tech companies require.

HITRUST certified
HIPAA certified
SOC 2, Type II certified
Security snapshot

Built for healthcare from day one.

A quick overview of the certifications, encryption controls, and validation points most buyers want to confirm early.

Certification
HITRUST certified

Independent validation across HIPAA, SOC 2, NIST, ISO 27001, and more.

Compliance
HIPAA compliant

Healthcare workflows and patient data handling built to meet HIPAA requirements.

Audit
SOC 2 Type II certified

Controls tested continuously, not just reviewed at a single point in time.

Agreement
BAA included

Every Medsender account includes a signed Business Associate Agreement.

Encryption and access controls

256-bit SSL in transit, 2048-bit private key encryption at rest, role-based permissions, inactivity timeouts, and Microsoft SSO support.

Infrastructure and review access

US-based infrastructure plus Trust Center access for status, SOC reports, and additional HITRUST information.

Compliance certifications

HITRUST leads our security posture, supported by HIPAA compliance, SOC 2 Type II certification, and a signed BAA for healthcare teams with rigorous review requirements.

SOC 2 Type
Verified

SOC 2 Type II Certified

Independently audited and certified. Our security controls are tested continuously, not just at a point in time.

HIPAA badge
Verified

HIPAA Compliant

All data handling meets HIPAA Security Rule standards end to end.

BAA Included badge
Verified

BAA Included

Every Medsender account includes a signed Business Associate Agreement from day one — no additional cost.

Need deeper documentation for technical review?

View real-time status, SOC reports, and HITRUST information
How we protect your data

Security should feel visible, layered, and easy to validate.

Medsender's control stack is designed to read clearly for buyers — from encryption, to access, to infrastructure.

Technical buyer highlights
US-based infrastructure and Microsoft SSO support
SOC documentation available via request through the Trust Center
Additional HITRUST information available for deeper diligence

Encrypted in transit and at rest

Layer 01

256-bit SSL encryption for all data in transit. 2048-bit private key encryption for stored documents. Patient data is never transmitted or stored in an unencrypted state.

Access controls you control

Layer 02

Role-based user permissions, session timeouts on inactivity, centralized user management, and Microsoft SSO support. You decide who sees what.

Infrastructure you can trust

Layer 03

Built on Google Cloud with US-based servers, redundant systems, daily security assessments, DDoS protection, and 99.99% uptime. Firewall and intrusion detection built in.

Built for healthcare, not retrofitted for it

Most software companies add HIPAA compliance as an afterthought.

We built Medsender for healthcare from day one.

Vendor accountability
01

BAA enforced across every vendor and subprocessor we work with, not just with our direct customers.

Operational rigor
02

Privacy procedures, regular vulnerability testing, and security training built into our operations, not just our product.

Continuous monitoring
03

Continuous compliance monitoring through Vanta, one of the leading SOC 2 and HIPAA compliance platforms. Our controls are reviewed in real time, not annually.

Questions about security?

We are happy to provide documentation, answer security questionnaires, or walk your IT or compliance team through our controls.

Give technical stakeholders a fast path to answers instead of making them piece together proof from multiple sources.

Security review support

Everything buyers, IT teams, and compliance stakeholders need to move faster.

Audit documentation
SOC 2 Type II and SOC 2 Type I reports are available through our Trust Center via request access.
US-based hosting
Servers are located in the United States.
Microsoft SSO
Single Sign-On (SSO) is supported with Microsoft.
Questionnaire support
Security questionnaire support and guided walkthroughs are available for IT and compliance teams.
FAQ

Frequently Asked Questions

Answers to common questions about Medsender's security, compliance, and data protection practices.

Is Medsender HIPAA compliant?

Yes. Medsender is HIPAA compliant, and every account includes a signed Business Associate Agreement at no additional cost.

Is Medsender SOC 2 certified?

Yes. Medsender is SOC 2 Type II certified, meaning our controls are independently audited over time rather than reviewed only at a single point in time.

Does Medsender include a BAA?

Yes. Every Medsender account includes a signed Business Associate Agreement from day one, with no added fee.

Where can I see Medsender's compliance status?

You can review Medsender's real-time Trust Center at trust.medsender.com for status information, report access details, and additional compliance documentation.

What encryption does Medsender use?

Medsender uses 256-bit SSL encryption for data in transit and 2048-bit private key encryption for stored documents.

Where are your servers located?

Medsender's infrastructure is hosted in the United States.

Is Medsender HITRUST certified?

Yes. Medsender is HITRUST certified. HITRUST CSF brings together HIPAA, SOC 2, NIST, ISO 27001, and other standards into one unified framework validated by an independent assessor.