Legal & Compliance

Everything you need to evaluate MediChatApp for HIPAA and enterprise procurement: BAA, Privacy, Terms, Subprocessors, Data Retention, and more.

MediChatApp Legal & Compliance

Core Documents

Standard terms and compliance materials for Covered Entities and Business Associates.

Business Associate Agreement (BAA)

HIPAA-compliant terms governing PHI when MediChatApp acts as a Business Associate.

View BAA
Privacy Policy

Explains what information we collect, how we use it, and your choices.

Read Privacy Policy
Terms of Service

Your agreement with MediChatApp for use of our products and services.

Read Terms
Security & Compliance

Our approach to HIPAA, SOC 2 Type II alignment, encryption, access control, and audit logging.

View Security Overview
Subprocessors

List of third parties that may process PHI/PII to deliver our services.

See Subprocessors
Notice of Privacy Practices (NPP)

How MediChatApp protects and uses health information when supporting healthcare organizations.

View NPP
Data Retention & Deletion

How long we retain data, and how deletion requests are handled.

Retention Policy
Data Processing Addendum (DPA)

Contractual GDPR/CCPA commitments when we act as a processor.

View DPA
Acceptable Use

Rules to keep messaging safe, compliant, and respectful for patients and staff.

Read AUP
Service Level (SLA)

Uptime targets, support response times, and maintenance windows.

View SLA
Responsible Disclosure

How to report a security issue to our team securely and responsibly.

Report a Vulnerability
SOC 2 Type II (Request)

Request controlled access to our latest audit report under NDA.

Request Access


Frequently Asked

Quick answers for compliance and procurement teams.

Will MediChatApp sign a BAA?

Yes. We countersign BAAs for Covered Entities as part of onboarding.

Do you encrypt PHI?

Yes—encryption in transit and at rest, with strong key management.

Can we review your subprocessors?

Yes. See the live list on our Subprocessors page; we provide notice before changes.

Do you provide audit logs?

Yes—immutable logs with time, actor, action, and context; export available.

Need a custom rider or security questionnaire?

We work with legal and security teams to finalize BAAs, DPAs, and enterprise terms.



💬 Ask a Question Schedule a meeting