Mednor Mednor

Security & Compliance

How Mednor protects your laboratory and patient data.

HIPAA & BAA

We sign a Business Associate Agreement (BAA) with every covered entity. Protected Health Information is handled under strict use and disclosure controls, with breach notification commitments.

Encryption

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Backups are encrypted and access-controlled.

Access control & RBAC

Granular role-based access control, optional two-factor authentication, and full multi-tenant isolation keep each lab's data separate.

Audit logging

Every access to and change of clinical records is recorded in an immutable audit trail for accountability and investigations.

Data residency

Choose where your data is stored — US, EU, GCC, or Asia-Pacific — to meet local regulatory requirements.

GDPR & DPA

For customers in the EU, we provide a Data Processing Agreement covering lawful basis, data-subject rights, and cross-border transfer safeguards.

Availability & backups

Automated daily backups, monitored infrastructure, and a documented disaster-recovery process.

Need a signed BAA or DPA for your organization? Existing customers can sign directly from Settings → Compliance, or contact our team.

Mednor LIS © 2026