Security & Compliance

Security at DocsMD™

Technical, administrative, and physical safeguards used to protect patient and practice data processed by our autonomous operations engine.

EFFECTIVE MARCH 27, 2026 · LAST UPDATED MARCH 27, 2026

DocsMD™ takes the security of patient and practice data seriously. This page describes the technical, administrative, and physical safeguards we use to protect information processed by our autonomous operations engine.

Data Encryption

Access Controls

Application Security

Infrastructure Security

HIPAA Safeguards

As a HIPAA Business Associate, DocsMD implements the safeguards required by the HIPAA Security Rule (45 C.F.R. §§ 164.302–164.318):

CategoryExamples of Safeguards
AdministrativeSecurity policies, workforce training, access management, incident response plan, risk assessments
PhysicalSubprocessor data centers with controlled physical access; no on-premises PHI storage
TechnicalAccess controls, audit logs, integrity controls, transmission security (encryption)

Subprocessor Security

All subprocessors handling Protected Health Information have executed Business Associate Agreements and maintain their own security certifications:

Incident Response

DocsMD maintains a documented incident response procedure. In the event of a security incident or breach affecting PHI:

  1. The incident is investigated and contained as quickly as possible
  2. The affected Practice is notified without unreasonable delay (and within 60 days for breaches under HIPAA)
  3. Affected individuals are notified by the Practice in accordance with HIPAA Breach Notification Rule
  4. HHS Office for Civil Rights is notified as required
  5. A post-incident review is conducted and corrective actions implemented

Telephone Consumer Protection Act (TCPA) Compliance

All outbound SMS messages comply with the TCPA, 47 U.S.C. § 227, through:

Data Retention & Deletion

Vulnerability Disclosure

We welcome reports from security researchers. If you believe you have discovered a security vulnerability, please contact us at hello@docsmd.com with details. We will respond within 5 business days and work with you to verify and remediate the issue. We commit not to pursue legal action against good-faith researchers who follow responsible disclosure practices.

Contact

DocsMD™ Security
Email: hello@docsmd.com