Security approach

Security and controlled programme access

MedCorpora separates public website use from controlled medical-data programmes. Patient-level data is not publicly available, and programme access requires defined permissions, privacy review, security controls, diligence and contracting appropriate to the release.

Published 30 July 2026 · Reviewed 12 August 2026 · MedCorpora
01

Public website boundary

The public website is used for information, business contact and cohort requirements. It is not a clinical system, patient portal or channel for uploading patient-level medical data.

02

Programme-specific controls

Security requirements are defined for the applicable programme and can include controlled ingestion, purpose-limited processing, access restrictions, de-identification validation, audit records, secure delivery, retention and deletion terms. Exact controls are confirmed before release.

03

No unverified certification claims

This page does not claim SOC 2, ISO 27001, HIPAA certification or another external certification. Where a buyer requires a specific security or privacy control, MedCorpora addresses it through diligence and programme feasibility rather than assuming coverage.

04

Security contact

Security-related website or business enquiries can be sent to hello@medcorpora.com. Do not include patient-level information in an initial email or website submission.

05

Questions, answered directly.

Can patient data be uploaded through the website?

No. The public website form is for cohort specifications and business contact, not patient-level data.

Does this page claim a security certification?

No. Programme-specific requirements and evidence are addressed through diligence.

Institutional engagement

Define the cohort.