Trust & security
How MedRamp handles your facility's data
Written for facility administrators. Plain language, no jargon. If anything here is unclear, ask us directly and we'll answer in the same plain language.
No PHI collected or stored
By design, MedRamp never asks for or stores patient health information. Nurses use it for logistics and orientation questions (badges, parking, crash cart location, unit-specific workflow) only. Patient names, MRNs, and clinical data are out of scope for the product.
Per-facility data isolation
Each facility's questions, answers, and documents are walled off from every other facility. A coordinator at one hospital cannot see, search, or query another hospital's data. Isolation is enforced in the database, not just in the UI.
Full data export on request
Any facility can request a full export of its MedRamp data at any time, in a machine-readable format (CSV or JSON), at no cost. We deliver the export within 5 business days.
24-hour deletion on request
When a facility asks us to delete its data, we complete deletion within 24 hours and confirm in writing. This covers questions, answers, uploaded documents, and audit history for that facility.
AI transparency
The MedRamp chat assistant is clearly labeled as an AI assistant. It answers using your facility's approved knowledge base and provides source documents where available. Nurses should still follow unit policies and verify safety-critical information with on-site staff.
SOC 2 Type I: roadmap, not current
RoadmapWe are targeting SOC 2 Type I audit completion by the end of our first paid pilot. We are not currently SOC 2 certified. We would rather tell you this honestly than display a badge we haven't earned. This page will update when the audit is complete.
Questions about how we handle your data?
Reach out and we'll answer directly, usually within one business day.
Last updated: July 2026 · Back to home