Security

Mykare AI’s security program is designed around industry-standard controls for healthcare SaaS platforms, with a focus on HIPAA Security Rule, DPDP Act, and SOC 2 Type II alignment.

Secure Infrastructure

Encryption & Data Protection

Access Control & Identity Management

Application & Vulnerability Management

Monitoring, Logging, and Incident Response

Compliance

Mykare AI serves hospitals and healthcare providers in the United States and across international markets, and operates as a HIPAA-aligned, cloud-based Business Associate and, where applicable, a Data Processor under the DPDP Act and GDPR.

HIPAA

DPDP Act, 2023 (India)

SOC 2 Type II (in progress)

Other Regulatory Considerations

Privacy & Data Handling

Mykare AI maintains a separate Privacy Policy that describes in detail how we collect, use, and disclose information in connection with our Website and Services. Key principles for PHI and Customer data are summarized below.

Roles & Responsibilities

Data Flows & Usage

De-identification and Analytics

Data Residency & Access

AI & Quality Assurance

Mykare AI uses multiple specialized AI agents, orchestrated workflows, and human oversight to deliver fast, accurate, and patient-safe communication services to hospitals and healthcare providers.

AI in Patient-Facing Workflows

AI Disclosure & Synthetic Voices

Human Oversight & Quality Assurance

Model Improvement & Data Protection

Subprocessors & Infrastructure Partners

Mykare AI works with carefully selected subprocessors and infrastructure partners to deliver the Services at scale and with high reliability.

These partners fall into categories such as:

Where a subprocessor may access or process PHI, Mykare AI requires contractual commitments and security controls appropriate for Business Associates, including data-protection obligations and, where applicable, HIPAA-aligned terms.

If you would like a current list of subprocessors with specific vendor names, or more detail on specific services, you can request it by contacting us at support@mykare.ai. Customers receive at least thirty (30) days’ notice of new subprocessors that handle PHI, in accordance with the BAA and DPA.

Documents & Agreements

Public versions of our key legal and compliance documents are linked below. Private or pre-populated copies are available on request to support@mykare.ai.

Privacy Policy

How we collect, use, and protect information across the Website and Services.

View

Terms of Use

The SaaS Customer Agreement that governs use of the KareOS platform.

View

HIPAA BAA

Standard Business Associate Agreement covering processing of PHI.

View

Data Processing Addendum

For Customers subject to the GDPR, UK GDPR, or DPDP Act — includes SCCs and UK IDTA as applicable.

Request

Consent Certificate (Exhibit A)

Template for multi-entity arrangements (hospital networks, OHCAs) authorizing PHI sharing.

Request

SOC 2 Type II Report

Available under a mutual NDA after the audit concludes.

Request

Contact & Reporting

If you have questions about Mykare AI’s security, privacy, or compliance practices, or wish to report a security concern, please contact:

Mykare Technologies Inc. 251 Little Falls Drive
Wilmington, New Castle County
Delaware 19808, USA
Email: support@mykare.ai

If you believe you have discovered a security vulnerability affecting Mykare AI, please provide a description of the issue, steps to reproduce (without sharing PHI), and your contact details so we can follow up. We aim to acknowledge security reports within one (1) business day.