HIPAA Compliance
MedOpinion's approach to healthcare data security and privacy.
Last Updated: September 1, 2026
Our Commitment to Healthcare Data Security
MedOpinion is designed with security and privacy controls appropriate for a platform that handles healthcare-related information. Because patients submit medical information and documents for second opinions, we treat the protection of that information as a core part of the product — not an afterthought.
Protected Health Information (PHI)
In the context of the Platform, Protected Health Information (PHI) means the health-related information patients submit in connection with their care — including case descriptions, diagnoses, medical documents, appointment details, and the opinions and recommendations doctors provide. PHI is visible only to the patient who submitted it, the doctor(s) assigned to the case, and authorized platform administrators.
Administrative Safeguards
- User authentication is required to access the platform
- Role-based access distinguishes patients, doctors, and administrators
- Doctors are provisioned and managed through an administrative approval process
- Access to medical cases is limited to the participating patient and doctor, and administrators as needed
- Security procedures govern how PHI is handled within the platform
Technical Safeguards
- All traffic to the platform is served over HTTPS/TLS
- Users must authenticate with their credentials before accessing any case data
- Authorization checks and role-based access controls enforce who can view or change each record
- Access to medical cases is restricted at the data level, not only in the interface
- Communication with video consultation and notification services uses authenticated, secure APIs
- Access to cases is logged in an audit trail
Access Control
Doctors, patients, and administrators have different access permissions. Patients can see only their own cases and appointments. Doctors can see only the cases assigned to them. Administrators have operational access for platform management and support. Access permissions are enforced by the platform's data layer for every read and write.
Encryption
Encryption in transit: all data exchanged between your browser and the platform, and between the platform and its service providers, is encrypted using TLS.
Encryption at rest: data storage is handled by our underlying infrastructure provider, which applies industry-standard storage protections. We do not perform application-level encryption of stored records.
Audit and Monitoring
The platform maintains an audit log of significant events, including access to medical cases, changes to case records, file uploads, creation and joining of video consultation rooms, and the delivery status of notifications. Audit records are accessible to authorized administrators for security review.
Video Consultations
Video consultations are powered by Daily.co. Consultation rooms are created per-appointment with random, non-identifying room names, are private, and are accessed with short-lived, role-based access tokens issued only to the scheduled doctor and patient. Room names and links do not contain any personal or medical information.
Daily.co's participation in MedOpinion's compliance program is limited to the video service it provides; it does not by itself make the entire MedOpinion platform compliant with any regulation.
Email and SMS
Appointment notifications may be sent by email and SMS through the platform's configured providers. Notification messages are limited to appointment logistics (such as date, time, and joining instructions); SMS messages do not include medical information or case details. Email notifications may reference your case title so you can identify the appointment.
Business Associate Agreements
Where required, MedOpinion evaluates applicable service-provider contractual and data-protection requirements, including Business Associate Agreement requirements.
Incident Response
If a security incident affecting platform data occurs, we investigate promptly, take steps to contain and remediate the issue, and notify affected users and authorities as and to the extent required by applicable law.
User Responsibilities
Security is shared. Users must keep their login credentials confidential, use strong passwords, sign out on shared devices, and use the platform only for its intended purposes. If you suspect unauthorized access to your account, notify us immediately.
Important Statement
HIPAA is a legal and regulatory framework, and there is no general government-issued "HIPAA certification" that a platform can obtain. MedOpinion does not claim to be "HIPAA certified." Instead, we describe — accurately — the administrative and technical safeguards described on this page, and we continue to improve them over time.