Security & compliance
Security and privacy by design.
Patient trust is the product. Here is how WorldEHR protects data — stated plainly, without overclaiming.
Role-based access + audit
Every route is permission-gated by role, and every read/write to patient data is written to an audit log.
Encryption
Encrypted in transit (TLS) and at rest. Secrets live in a managed secret store, never in code.
PHI-safe AI
Any AI that can touch patient data runs on Google Vertex under BAA — never on vendors without a BAA.
Region data residency
Deployments align data location with the region you operate in.
Accessibility
Designed to WCAG 2.1 AA and Section 508, verified in CI.
SOC 2 in progress
Building toward SOC 2 (Trust Services Criteria). We do not claim certification we don't yet hold.
Honest status: WorldEHR is in active development and is not ONC-certified. The public demo uses synthetic data only. Real patient data runs on the secured cloud stack after a signed BAA and agreed pilot scope. HIPAA-aligned (US) and designed for India's DPDP-2023.
Want the security details for your review?
We'll walk your team through controls, data flows, and the BAA.