Lexamed

Security and real-record readiness

Until the agreement package below is accepted for your organization, Lexamed accepts synthetic records only. Do not upload real patient records before then, including records with names removed.

Before real-record access

Readiness work covers vendor agreements, customer contracting, infrastructure verification, access controls, recovery testing, and an accountable review. Product controls and agreement acceptance alone do not establish HIPAA compliance.

The application includes organization-scoped access, session controls, source-linked review, and an audit trail. Verification of the deployed service remains part of the release review.

Customer agreements

Approved customer terms and the business associate agreement will be available as a versioned package. An authorized organization owner must accept the applicable version before real-record access can be enabled.

View published agreements

Security questions

Contact hello@lexamed.ai. Do not include patient information, medical records, passwords, or access tokens.