Security and trust

Patient data is handled as if it were our own

Healthcare organizations deserve direct answers about how their data is protected. This is how Meridian approaches it.

Data protection

Encrypted, separated and logged

Data is encrypted in transit and at rest. Access is granted by role, and every access is recorded in a log your team can review. Each customer’s data is kept separate from every other organization’s.

Compliance

Audited and contractually accountable

Meridian is independently audited against SOC 2 Type II. We sign a Business Associate Agreement with every customer and design our infrastructure around the HIPAA Security Rule safeguards. Our incident response and notification procedures are documented and shared with customers during onboarding.

Responsible AI

Validated, monitored, supervised

Models are validated before release and monitored in production for drift and performance. They never take autonomous clinical action, and every suggestion can be traced to the data behind it.

Our commitments

What you can expect

Your data is never sold and never used for advertising. Full audit trails are available for compliance review whenever you need them, and if something ever goes wrong you will hear it from us first, with the details.

Need our security documentation?

We share detailed materials with your compliance team on request.

Get started