Security & Trust

Last verified: 14 May 2026 · Updated when controls change

MediCare HIS stores hospital operational data and patient health information on behalf of healthcare providers. The security practices below describe what we run today, how we verify it, and how to report a problem. We publish this so customers, auditors and security researchers can hold us to it.

On this page

  1. 1. Transport security
  2. 2. Edge defense
  3. 3. Identity & access
  4. 4. Data protection
  5. 5. Continuous monitoring
  6. 6. Enterprise governance & compliance posture
  7. 7. Independent verification
  8. 8. Vulnerability disclosure
  9. 9. Recent updates

1. Transport security

Every byte that crosses the public internet is encrypted. We hold an external A+ grade from Qualys SSL Labs on every endpoint, and an A+ (10/10) from Mozilla Observatory on our HTTP security headers.

2. Edge defense

All traffic flows through Cloudflare's global edge network before reaching our origin. The origin itself is locked to Cloudflare-only via an authenticated-pulls shared secret — direct attempts to bypass the edge and hit our servers are rejected at the network layer.

3. Identity & access

Multi-factor authentication is enforced for every privileged role, not just available. We support both authenticator apps (TOTP) and modern phishing-resistant passkeys, and we can enforce passkey-only sign-in for the most sensitive accounts.

4. Data protection

Patient and operational data is encrypted in transit and at rest, with an additional client-side encryption layer on off-host backups so backup data is never legible to anyone but us — including our backup provider.

5. Continuous monitoring

Security isn't a one-time setup. We run continuous, automated checks across multiple independent channels.

6. Enterprise governance & compliance posture

Security isn't just code — it's a governance framework, a policy library, and a documented compliance trajectory. We publish ours so prospective customers and their auditors can see exactly where we stand against international standards rather than taking our word for it.

7. Independent verification

We don't just claim a security posture — we publish the external grades. These checks can be re-run against our production domain at any time.

Independent checkResultRe-run at
Qualys SSL LabsA+ssllabs.com/ssltest
Mozilla ObservatoryA+ (10/10)observatory.mozilla.org
Sucuri SiteCheckClean (no blacklist, no malware)sitecheck.sucuri.net

8. Vulnerability disclosure

If you've found a security issue in MediCare HIS, please email [email protected]. We follow RFC 9116 — our machine-readable contact is at /.well-known/security.txt.

9. Recent updates

Security is a continuous practice. Recent improvements, most recent first:

This page reflects the security state as of 14 May 2026. It is auto-generated from a single source of truth and regenerates whenever a security control is added, changed, or removed. The full internal audit-grade record (including specific configuration, verification commands, and open follow-up items) is available to enterprise customers under NDA — email [email protected] to request it.