Security & compliance

Security and privacy by design.

Patient trust is the product. Here is how WorldEHR protects data — stated plainly, without overclaiming.

Role-based access + audit

Every route is permission-gated by role, and every read/write to patient data is written to an audit log.

Encryption

Encrypted in transit (TLS) and at rest. Secrets live in a managed secret store, never in code.

PHI-safe AI

Any AI that can touch patient data runs on Google Vertex under BAA — never on vendors without a BAA.

Region data residency

Deployments align data location with the region you operate in.

Accessibility

Designed to WCAG 2.1 AA and Section 508, verified in CI.

SOC 2 in progress

Building toward SOC 2 (Trust Services Criteria). We do not claim certification we don't yet hold.

Honest status: WorldEHR is in active development and is not ONC-certified. The public demo uses synthetic data only. Real patient data runs on the secured cloud stack after a signed BAA and agreed pilot scope. HIPAA-aligned (US) and designed for India's DPDP-2023.

View the in-app compliance page →

Want the security details for your review?

We'll walk your team through controls, data flows, and the BAA.

Talk to us