Skip to content
Security & Compliance

HIPAA & PIPEDA compliance

5 min read Updated July 15, 2026

mePro is built for regulated clinical work. We provide the safeguards and agreements you need to meet HIPAA in the US and PIPEDA in Canada.

What we provide

  • Encryption of protected health information in transit and at rest.
  • A Business Associate Agreement (BAA) for US practices, available on request.
  • Access controls, audit logs, and role-based permissions.
  • Data hosting and handling aligned with PIPEDA for Canadian practices.

Your part of the shared responsibility

Compliance is shared. mePro secures the platform; your practice is responsible for how you use it — strong passwords, appropriate access, obtaining client consent, and following your own policies and local regulations.

Tip: Ask for a BAA before entering client PHI if you're a US covered entity — it's a quick request from Settings → Security.

Frequently asked

Is mePro HIPAA compliant?

+

mePro provides HIPAA-compliant infrastructure and will sign a Business Associate Agreement. HIPAA compliance is a shared responsibility — the platform provides safeguards, and your practice must use them appropriately.

Where is my data stored?

+

Data is stored on secure, access-controlled infrastructure. Canadian practices can ask about data residency options to support PIPEDA obligations.

Was this article helpful?

Still need a hand?

Our team is happy to help. Reach out with a question, or book a live walkthrough and we'll show you around.

Not sure about how it works?

Book a demo to see mePro in action, ask questions, and explore how the platform can support your practice at every stage.

©2026 mePro. All rights reserved.