Operational Security
Our professional team at Medevio ensures a smooth and secure exchange of data across our platform. We leverage Amazon Web Services (AWS) cloud infrastructure, which adheres to the highest security standards, backed by SOC 2 Type 2 and HIPAA/HITECH certifications. Medevio continuously conducts internal and external audits and risk assessments to maintain constant control over data security.
Privacy
Patient and provider privacy is our absolute priority. Medevio does not share any information with third parties. Patients and providers are contacted only within the framework of the application and in line with the terms of use.
User Authentication
Every user undergoes multi-factor authentication, ensuring that only verified users can access Medevio features. Medevio implements standardised verification methods and maintains internal processes to identify any potential misuse of identity.
GDPR Compliance & Data Processing
Medevio complies with all requirements for processing, using, and storing personal data. Patients agree to data processing upon registration, while a Data Controller and Data Processor agreement is established with providers. When necessary, Medevio is prepared to demonstrate to relevant authorities that data handling complies with GDPR standards.
Encryption
Medevio employs the latest encryption standards in healthcare to secure all data on our platform. All communications and video transmissions are encrypted through DTLS/SRTP connections. Personal data is secured using 256-bit AES encryption, with all sensitive information further encrypted using AWS cloud services.
Network Security
Medevio uses detection mechanisms to monitor our applications and infrastructure, identifying any deviation from regular activity. Any irregularity triggers an immediate response, blocking any network breaches.
Login Monitoring & Activity Alerts
Our system identifies and flags suspicious logins and activities in the application, prioritising each alert for immediate resolution. Medevio staff have limited database access, and any interaction with internal databases is monitored and logged. Access is restricted strictly for application development purposes, with encrypted data ensuring no exposure to patient or provider information.
Physical Security
Medevio stores data on servers within the European Union, which comply with the highest security protocols. Access to these servers is controlled 24/7 and secured by fingerprint, key card, and password. These servers are trusted by banks, government organisations, and other sectors where data security is paramount.
Reporting Security Issues
We collaborate with security experts to stay at the forefront of security advancements, employing the latest technologies. If you discover a potential vulnerability, please report it to us at info@medevio.eu.
For more information on how we secure data in our application, feel free to contact us at info@medevio.eu.