MedVertical

Enterprise · Trust & Security

What Records reads, stores, and can change.

A security review should start with the concrete data flow and operating boundary — not with generic trust language.

Product boundary reviewed 24 August 2026

1. What Records reads and processes

FHIR server surfaceCapabilityStatement, declared resources, supported interactions, and search parameters.
Validation inputSelected FHIR resources for the duration of the validation request or batch.
Validation basisFHIR release, profile packages, terminology sources, rules, thresholds, and environment context.
Operating contextWorkspace, user or machine identity, selected server, run, and deployment configuration.

2. What persists

The product invariant is no source payload retention — not the broader and less precise claim that no sensitive information can ever exist.

Persists

Derived validation and evidence data

Run metadata, findings, counts, configuration context, fingerprints, status, audit events, evidence records, and integrity hashes according to the deployment retention policy.

Does not persist

Source clinical resource payloads

FHIR resources are processed transiently for validation. Records is not a clinical data repository and does not retain the source payload as its system of record.

3. What Records can change

Records does

  • Read resources for validation and comparison
  • Process source resources transiently in the selected deployment environment
  • Store derived metadata, signals, fingerprints, and evidence
  • Allow explicit delegated submissions when edit mode is enabled

Records does not

  • Persist source clinical resource payloads as a CDR
  • Initiate automated writes or bulk mutations
  • Own FHIR authorization, history, or version chains
  • Guarantee regulatory compliance or make clinical decisions

Automated validation is read-only by default. Optional delegated submissions are separate, explicitly enabled user actions and remain owned by the connected FHIR server.

Current status

Current assurance status

Stated plainly so technical controls are not mistaken for certification.

No ISO 27001, SOC 2, or HIPAA certification is claimed

Deployment and product controls can support a review, but MedVertical does not currently present Records as certified under those frameworks. Contract-specific commitments are evaluated separately.