A formal description of the MediCare HIS security posture for procurement committees, IT leadership and compliance officers. Save as PDF (⌘P / Ctrl+P) for distribution. Companion to the live Trust page at /security, which is the always-current view of every active control.
Document version: 2026-05-14 · Latest version always at medicarehis.com/security-whitepaper
MediCare HIS handles protected health information (PHI), payment and insurance data, and staff authentication credentials. We design controls against six adversary classes:
Every claim in this whitepaper is verifiable by an outside party with no special access. Three classes of verification:
Run from any browser, no credentials:
Run from any terminal:
curl -I medicarehis.com — inspect response headers (HSTS, CSP, X-Frame-Options, etc.)nslookup _dmarc.medicarehis.com — DMARC policyRead on this site:
We map controls to four standards. Detail in the compliance roadmap.
Reports go to [email protected]. Discoverable via our RFC 9116 security.txt at medicarehis.com/.well-known/security.txt. Acknowledgement SLA: 2 working days. Severity-tiered fix SLA:
External penetration testing: first formal engagement scheduled. Annual cadence thereafter per the incident-response policy. Bug bounty: Stage 2+ (not yet active).
Companion documents: Procurement evidence pack · Brochure · Deployment architecture · Compliance roadmap · SLA · Support · Onboarding
Enter the subdomain your IT team gave you. We'll redirect you to your hospital's secure login.