Security
MAC carries some of the most sensitive information in healthcare — patient referrals — between doctors and clinics. We design the network so that protecting that data is the default, not an add-on.
Our practices
Traffic is protected with modern TLS, and data is encrypted at rest. Secrets and keys are managed separately from application data.
Personal health information is reachable only by the people and services that need it for a specific task. Access is role-based and audit-logged.
We aim to store and process personal health information on Canadian infrastructure, with safeguards documented for any exception.
Logging, alerting, and anomaly detection help us spot and respond to unusual activity, backed by an incident-response process.
Sub-processors, including our practice-management platform provider, operate under written data-protection agreements and are reviewed before and during use.
Code review, dependency management, least-privilege service accounts, and environment separation are part of how we ship.
Responsible disclosure
We welcome reports from security researchers. If you believe you've found a vulnerability, contact us before disclosing it publicly and give us a reasonable window to remediate. We won't pursue good-faith research that respects patient privacy and avoids service disruption.
Report a vulnerability
security@medaccesscorp.com
Please include steps to reproduce, affected URLs, and your contact details. Do not access or modify data that isn't yours.