HIPAA audited
The platform has been audited for compliance, with safeguards, access control by role and audit logging for protected health information.
Trust & data
Clinics hand us the two most sensitive records a person has: their clinical history and their genome. This page says plainly how both are handled.
The platform has been audited for compliance, with safeguards, access control by role and audit logging for protected health information.
A clinic's data is held in the AWS region for the jurisdiction it operates in, agreed in writing before onboarding.
Signed with covered entities in the United States before any protected health information is processed.
The platform has been audited for compliance with the Health Insurance Portability and Accountability Act. Administrative, physical and technical safeguards are in place for protected health information, including role-based access control, audit logging of access to records, encryption in transit, and a defined breach notification procedure.
Where a clinic in the United States is a covered entity, we enter into a Business Associate Agreement before any protected health information is processed. Ask us for the current form and for the summary of the most recent audit.
Our privacy policies are based on the Canadian Standards Association's Code for the Protection of Personal Information, CAN/CSA-Q830-96, and those principles are built into how the company operates rather than kept in a drawer. Privacy legislation expects organisations to hold policies that demonstrate the standards the public expects; ours are published in full.
The platform runs mainly on Amazon Web Services. A clinic's data is held in the AWS region for the jurisdiction that clinic operates in — a practice in the United States is served from United States infrastructure — and the applicable region is agreed in writing before onboarding. In a small number of cases we use other vendors or their affiliates for parts of the service.
Information held as part of the service sits in a database with physical and technological security controls in place, as the applicable regulations require. We do not guarantee that access is never interrupted — no one honestly can — and the service is occasionally taken down for maintenance and upgrades.
Data entered or transferred during use of the service is encrypted in transit using transport-layer security of the same class banks use for online transactions. Clinical data, DNA test results and other personal data are stored separately from names and other common identifying information.
Security is never finished. We keep updating our procedures, and we will not claim that any set of them is completely proof against failure. What we can commit to is the standard we work to and the things we will not do.
Full legal text
Privacy policy · Terms of serviceBusiness Associate Agreement
Available on request for covered entities in the United States.Laboratory partner terms
The terms under which a laboratory delivers results to clinics through the platform — ask us for the current form.Security or privacy questions
info@biomdgenetics.comHalf an hour, your cycle types, your lab, your questions about migrating what you already have.