mePro is built for regulated clinical work. We provide the safeguards and agreements you need to meet HIPAA in the US and PIPEDA in Canada.
What we provide
- Encryption of protected health information in transit and at rest.
- A Business Associate Agreement (BAA) for US practices, available on request.
- Access controls, audit logs, and role-based permissions.
- Data hosting and handling aligned with PIPEDA for Canadian practices.
Your part of the shared responsibility
Compliance is shared. mePro secures the platform; your practice is responsible for how you use it — strong passwords, appropriate access, obtaining client consent, and following your own policies and local regulations.
Tip: Ask for a BAA before entering client PHI if you're a US covered entity — it's a quick request from Settings → Security.
Frequently asked
Is mePro HIPAA compliant?
+
mePro provides HIPAA-compliant infrastructure and will sign a Business Associate Agreement. HIPAA compliance is a shared responsibility — the platform provides safeguards, and your practice must use them appropriately.
Where is my data stored?
+
Data is stored on secure, access-controlled infrastructure. Canadian practices can ask about data residency options to support PIPEDA obligations.