Security & compliance
Built for German healthcare.
From the ground up.
Patient data, medical documentation and billing. No room for shortcuts. This page states how meda handles it.
Data protection
What is structurally true, before any practice data flows.
In line with German healthcare requirements.
Our servers are in EU data centers, encrypted in transit and at rest.
A data processing agreement with every contract.
Notes stay under your control.
If an AI stage fails, the deterministic answer stands. Nothing guesses on your behalf.
Every approved code keeps its link to the note.
Sovereignty, precisely
Our servers are in Europe.
meda reads the documentation — nothing enters your PVS unless you approve it — and every code is a physician's decision. Sovereignty here isn't a server location. It's the architecture.
Documentation and billing context. Nothing goes back without your approval, AVV-covered.
When you book an appointment, your details go into HubSpot with EU data residency. Our website itself sets no tracking cookies and does not load HubSpot in the background — you open the booking page yourself via a link. Contact data is never mixed with product data.
An AVV (Auftragsverarbeitungsvertrag) is in place before any practice data flows.
Security questions? Ask them directly.
We answer data protection and compliance questions before anything else. AVV and technical documentation on request.