Security and real-record readiness
Until the agreement package below is accepted for your organization, Lexamed accepts synthetic records only. Do not upload real patient records before then, including records with names removed.
Before real-record access
Readiness work covers vendor agreements, customer contracting, infrastructure verification, access controls, recovery testing, and an accountable review. Product controls and agreement acceptance alone do not establish HIPAA compliance.
The application includes organization-scoped access, session controls, source-linked review, and an audit trail. Verification of the deployed service remains part of the release review.
Customer agreements
Approved customer terms and the business associate agreement will be available as a versioned package. An authorized organization owner must accept the applicable version before real-record access can be enabled.
View published agreementsSecurity questions
Contact hello@lexamed.ai. Do not include patient information, medical records, passwords, or access tokens.