Resources
Policies and reports, available on request. Until our SOC 2 report is published, write to [email protected] and we'll walk you through our current controls.
FAQs
Common questions about how Medley protects health information.
Subprocessors
The vendors that help us run Medley. Every subprocessor that touches health information signs a Business Associate Agreement before any covered deployment.
Amazon Web Services (AWS)
Cloud infrastructure and encrypted storage for application data.
Twilio
Text messages and automated phone calls for reminders. Messages never include medication names.
Vercel
Hosting for our public website. No health information is stored or processed here.
First Databank (FDB)
Medication reference data: names, dosing, and plain-language descriptions.
Monitoring
A live view of the security controls we monitor continuously through Secureframe.
Compliance
Built to the HIPAA Security Rule from day one. A SOC 2 Type II examination is in progress, and the report will be published here when complete.
HIPAA
Built to the HIPAA Security Rule, with Business Associate Agreements executed with every vendor that touches health information.
SOC 2
SOC 2 Type II examination in progress. The report will be available here once complete — email [email protected] for interim details.