Security reviews in medical devices usually start with one question: where is the patient data? Our answer shortens the conversation considerably.
ManaMD contains no patient records, no PHI, and no claims-level detail about individuals. The market data in the app is aggregate, provider-level information published by federal agencies: CMS, NPPES, openFDA, and ClinicalTrials.gov. There is no patient data to breach because none is collected, stored, or transmitted, and the product is deliberately built so that stays true. Because no PHI is involved, no business associate agreement (BAA) is required.
Visit logs, notes, follow-ups, and account statuses are stored on the rep's iPhone or iPad, protected by iOS's built-in encryption at rest and the device passcode. The app is built offline-first: a rep's day never depends on a signal, and any data that moves does so over encrypted connections, scoped to your organization.
All network traffic, data updates and AI requests alike, travels over TLS-encrypted connections. AI requests are processed by Anthropic under API terms that exclude them from model training.
The app is built for iPhone and iPad, and every build passes Apple's review and code-signing chain before it reaches a device. The website is statically hosted with no server-side code and no database of its own.
We are a young company and we say plainly what we have and haven't done: we do not yet hold formal certifications such as SOC 2. What we offer instead is a materially smaller attack surface, with no patient data anywhere in the system, and straight answers to security questionnaires. If your evaluation requires specifics, ask through the support page and you will get them.
If you believe you have found a security issue in the app or this site, contact us through the support page with enough detail to reproduce it. We will acknowledge the report promptly, and we will not pursue good-faith research.