Open app

Trust & data protection

Trust & data protection

How MedLineage handles personal data: the controls built into the software, the rights it supports, and the documents available for your DPO. MedLineage is processor-side software; your organization remains the controller.

Your data, your rights

  • Access: every external data output writes an audit row; the per-patient access history is available on request (Art. 15).
  • Erasure: hard delete across every patient-scoped table, verified by an automated completeness test (Art. 17).
  • Portability: byte-deterministic, machine-readable export with canonical JSON and a FHIR R4 bundle (Art. 20).
  • Consent: grant and withdrawal endpoints with an append-only event trail; withdrawal is as easy as granting (Art. 7).

Security by design

Pseudonymous HMAC-derived identifiers, per-purpose signing keys, tenant partition isolation, rate limiting, upload validation, and persistence surfaces that default off. The remaining gaps are listed with dates in the compliance matrix โ€” never hidden.

Sub-processors

Every third-party service that may receive personal data is enumerated in the sub-processor schedule, with role, data categories, and safeguard. The primary entry is the Anthropic API for language processing.

Documents for your DPO

Compliance matrix, DPIA support template, DPA template, technical and organisational measures, sub-processor schedule, incident-response runbook, retention policy โ€” available as a verifiable bundle on request.

This page describes what the software does. It does not claim a certification and is not legal advice; the controller remains responsible for their own obligations.