Skip to content

Security & privacy

Your professional record is yours. Here, in plain language, is what we collect, what we don’t, and how we protect it.

Your record belongs to you

  • You can see everything in your record, including where each fact came from and when you confirmed it.
  • You can export your whole record at any time, with every original document.
  • You can delete your account and everything in it. We explain exactly when deletion completes.
  • We never sell physician data, and we don't share your record with anyone.

Sensitive details are your choice

  • Applications often ask for your date of birth and DEA number. You can keep them in MedIdentity so they're ready when you need them, or leave them out. It's your choice.
  • These details are encrypted separately from the rest of your record, hidden on screen until you choose to show them, and each time they're shown is recorded in your activity history.
  • They never appear in emails, and they're never sent to our logs, error reports or analytics.
  • If a document you upload contains one of them, it's saved only if you accept it.
  • We never store your Social Security number or driver's license number. When a document you add contains one, such as a license application, the number is blacked out on your own device before the document is uploaded, and you check it before it's saved.
  • That includes a photo of your driver's license, which you can keep for applications that ask for a copy of your ID.
  • If an organization needs an unredacted copy, you send it from your own files.
  • We never collect citizenship or immigration status.

How your record is protected

  • Two-step sign-in with an authenticator app is required for every account.
  • You're signed out after a period of inactivity, and asked to sign in again before exporting or deleting.
  • Your data is encrypted in transit and at rest.
  • Documents are kept in private storage. Each time you open one, we check it's yours and issue a link that expires within minutes.
  • Each physician's record is walled off at the database level, and we test that one account can never reach another's data.
  • You can see a history of sign-ins, uploads, downloads and changes to your record.

How we use AI

  • AI reads the documents you upload and suggests entries. It never adds anything to your record on its own.
  • Documents are processed on our servers, never in your browser, by an AI provider whose terms prohibit training on your data.
  • Our AI provider deletes what it processes within 30 days.
  • We record that AI was used and whether it succeeded, never the contents of your documents.

Malpractice history

  • Please don't include patient names or identifying details in malpractice documents or descriptions.
  • Malpractice documents and descriptions are never sent to our logs, error reports or analytics.

What we don't claim

  • There is no such thing as HIPAA certification, and we don't claim it.
  • No system is perfectly secure. If something goes wrong, we'll tell affected physicians promptly and plainly.