Security & Compliance

MediQueu handles patient data, so security is part of the product, not an add-on. HIPAA-ready infrastructure · GDPR compliant · BAA available on Scale plan.

Encryption everywhere

Data is encrypted in transit with TLS 1.2+ and at rest using AES-256 on managed infrastructure.

Role-based access

Patients, receptionists, doctors and admins each see only what their role and clinic allow — enforced at the database layer.

Audit trails

Sensitive actions are recorded with actor, timestamp and context so clinics can review who did what.

Tenant isolation

Every record is scoped to an organization. Cross-clinic reads and writes are blocked by row-level security policies.

Data rights

Export or delete your clinic's data on request. Retention windows are configurable per organization.

Compliance posture

HIPAA-ready infrastructure · GDPR compliant · BAA available on Scale plan.

Reporting a vulnerability

If you believe you've found a security issue, contact our team through the sales & support form with the subject "Security". We investigate every report and respond within two business days.

This page describes our security practices and is not legal advice. See our Privacy Policy and Terms of Service.