MedOpinion
HomeAboutServicesDoctorsContact

HIPAA Notice: This platform handles Protected Health Information (PHI). By using this service, you acknowledge our Privacy Policy and HIPAA Authorization. All data is encrypted in transit and at rest.

HIPAA Compliance

MedOpinion's approach to healthcare data security and privacy.

Last Updated: September 1, 2026

Our Commitment to Healthcare Data Security

MedOpinion is designed with security and privacy controls appropriate for a platform that handles healthcare-related information. Because patients submit medical information and documents for second opinions, we treat the protection of that information as a core part of the product — not an afterthought.

Protected Health Information (PHI)

In the context of the Platform, Protected Health Information (PHI) means the health-related information patients submit in connection with their care — including case descriptions, diagnoses, medical documents, appointment details, and the opinions and recommendations doctors provide. PHI is visible only to the patient who submitted it, the doctor(s) assigned to the case, and authorized platform administrators.

Administrative Safeguards

  • User authentication is required to access the platform
  • Role-based access distinguishes patients, doctors, and administrators
  • Doctors are provisioned and managed through an administrative approval process
  • Access to medical cases is limited to the participating patient and doctor, and administrators as needed
  • Security procedures govern how PHI is handled within the platform

Technical Safeguards

  • All traffic to the platform is served over HTTPS/TLS
  • Users must authenticate with their credentials before accessing any case data
  • Authorization checks and role-based access controls enforce who can view or change each record
  • Access to medical cases is restricted at the data level, not only in the interface
  • Communication with video consultation and notification services uses authenticated, secure APIs
  • Access to cases is logged in an audit trail

Access Control

Doctors, patients, and administrators have different access permissions. Patients can see only their own cases and appointments. Doctors can see only the cases assigned to them. Administrators have operational access for platform management and support. Access permissions are enforced by the platform's data layer for every read and write.

Encryption

Encryption in transit: all data exchanged between your browser and the platform, and between the platform and its service providers, is encrypted using TLS.

Encryption at rest: data storage is handled by our underlying infrastructure provider, which applies industry-standard storage protections. We do not perform application-level encryption of stored records.

Audit and Monitoring

The platform maintains an audit log of significant events, including access to medical cases, changes to case records, file uploads, creation and joining of video consultation rooms, and the delivery status of notifications. Audit records are accessible to authorized administrators for security review.

Video Consultations

Video consultations are powered by Daily.co. Consultation rooms are created per-appointment with random, non-identifying room names, are private, and are accessed with short-lived, role-based access tokens issued only to the scheduled doctor and patient. Room names and links do not contain any personal or medical information.

Daily.co's participation in MedOpinion's compliance program is limited to the video service it provides; it does not by itself make the entire MedOpinion platform compliant with any regulation.

Email and SMS

Appointment notifications may be sent by email and SMS through the platform's configured providers. Notification messages are limited to appointment logistics (such as date, time, and joining instructions); SMS messages do not include medical information or case details. Email notifications may reference your case title so you can identify the appointment.

Business Associate Agreements

Where required, MedOpinion evaluates applicable service-provider contractual and data-protection requirements, including Business Associate Agreement requirements.

Incident Response

If a security incident affecting platform data occurs, we investigate promptly, take steps to contain and remediate the issue, and notify affected users and authorities as and to the extent required by applicable law.

User Responsibilities

Security is shared. Users must keep their login credentials confidential, use strong passwords, sign out on shared devices, and use the platform only for its intended purposes. If you suspect unauthorized access to your account, notify us immediately.

Important Statement

HIPAA is a legal and regulatory framework, and there is no general government-issued "HIPAA certification" that a platform can obtain. MedOpinion does not claim to be "HIPAA certified." Instead, we describe — accurately — the administrative and technical safeguards described on this page, and we continue to improve them over time.

MedOpinion

Trusted medical second opinions from world-class specialists. Get the clarity you need for important health decisions.

Quick Links

HomeAbout UsServicesOur DoctorsContact

Services

Medical Second Opinion

Remote Consultation

File Review

Specialist Matching

Contact

contact@med-opinion.net
+1 (800) 123-4567
123 Medical Center, New York, NY

© 2026 MedOpinion. All rights reserved.

Privacy PolicyTerms of ServiceHIPAA Compliance

Business Associate Agreement

HIPAA Business Associate Agreement (BAA)

This Business Associate Agreement ("BAA") is entered into between MedOpinion ("Business Associate") and you ("Covered Entity") pursuant to the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the HITECH Act.

Permitted Uses: Business Associate may use and disclose PHI only as necessary to provide the services described in the underlying service agreement, or as required by law.

Safeguards: Business Associate agrees to implement appropriate administrative, physical, and technical safeguards to prevent unauthorized use or disclosure of PHI.

Breach Notification: Business Associate agrees to notify Covered Entity of any breach of unsecured PHI within 60 days of discovery.

Data Retention: Upon termination, Business Associate agrees to destroy or return all PHI received from Covered Entity.

Audit Rights: Covered Entity has the right to audit Business Associate's compliance with the terms of this BAA upon reasonable notice.