Security and compliance

The member decides. Everything else follows from that.

My EHR Data handles protected health information on behalf of health insurance plans and their members. These are the commitments My EHR Data makes to both.

HIPAA

My EHR Data operates as a business associate to each health insurance plan it works with, under a business associate agreement signed before any data moves.

Consent-driven access

Nothing moves without the member's permission. The beneficiary can limit access to sensitive categories, such as sexual health and mental-health records, and those stay withheld from anyone the beneficiary has not authorized.

Standards

HL7 FHIR R4, the data standard CMS requires, for every record and API; SMART on FHIR for showing records inside the provider's EHR; and US Core profiles for the data itself.

One separate store per insurance plan

Each health insurance plan gets its own FHIR record store. No data is shared between plans and there is no shared pool.

Data ownership

The member owns the data. It lives with the insurance plan and the provider. My EHR Data licenses access to it and does not own member data.

Encryption

Data is encrypted in transit and at rest.

Audit logging

Every access to a beneficiary's record is logged: who, what, when and under which consent.

No sale of data

My EHR Data does not sell member data and does not use it for anything other than the service the member and the insurance plan have authorized.

Assurance

What My EHR Data can show today.

My EHR Data shows insurance plans the controls themselves. A SOC 2 assessment is planned. The current security overview and the business associate agreement are available as part of a pilot conversation.

Questions from an insurance plan's security or compliance team?

Send them to My EHR Data and a founder answers them directly.

Contact us