Skip to main content
MedSimAI Trust & Policy Center

Policies that protect our learners, partners, and research.

Explore how MedSimAI handles privacy, security, accessibility, and AI governance today, plus the ongoing work that keeps partner and learner data safeguarded.

Last updated: July 2026IRB-aligned research program

Data Protection & Privacy

Operational

Personal data is encrypted in transit and at rest, and access is limited through server-enforced roles and institution-scoped permissions.

  • Fernet-encrypted PII stored in PostgreSQL with hashed identifiers for lookups.
  • TLS 1.2+ is enforced from the browser through CloudFront and to the application load balancer origin.
  • Public media delivery uses a CloudFront-backed path, while application buckets remain private and SSL-enforced.

Data Lifecycle & Stewardship

In Progress

The repo shows defined retention behavior for some stored artifacts today, while broader transcript and generated-artifact deletion workflows are still being formalized.

  • Product playback access to stored voice recordings expires after 30 days; broader physical S3 retention automation remains in progress under a reviewed deletion gate.
  • The current codebase includes scoped deletion primitives for stored assets, including managed uploads and generated media.
  • Approved cloud, AI inference, and voice service providers support selected platform features under documented access and data-handling controls.
  • Broader end-to-end customer deletion workflows across transcripts, stored artifacts, and provider-side data are still being completed.

AI Model Governance

Operational

MedSimAI orchestrates third-party AI systems for inference and voice runtime. Conversation prompts and scoring rubrics are version-controlled and change-tracked before release.

  • Approved AI providers support bounded authoring, assessment, action-routing, and simulated-participant experiences under purpose-specific controls.
  • Scenario prompts undergo review and change tracking before deployment.
  • Prompt and scoring updates are version-controlled so partner reviews can trace every change.

Access Controls & Account Management

Operational

Role-based access separates student, instructor, researcher, and admin workflows with server-enforced session policies and consent tracking.

  • Strict RBAC gates dashboards and API access.
  • Idle sessions time out after 2 hours and use secure cookies with CSRF protections.
  • Institution-specific SAML SSO with metadata retrieved from InCommon MDQ.
  • Institution and platform administrators can export recent auth and account-management audit logs with timestamps, actions, and source IP context.

Incident Response & Support

In Progress

Structured audit records are available for investigation, while formal incident-response playbooks and partner notification SLAs are still being completed.

  • Auth events now generate structured audit records with request metadata for follow-up and review.
  • Engineering standards in the repo call for incident contacts, escalation paths, and operational playbooks.
  • Documented response playbooks and notification SLAs remain in progress.

Accessibility & Inclusion

In Progress

The team is working toward WCAG 2.1 AA with automated checks in CI, public status reporting, and documented remediation targets for protected workflows.

  • Core public and authentication pathways have automated accessibility checks, and keyboard coverage is being expanded across protected workflows.
  • The public accessibility statement documents known gaps, roadmap targets, and the current VPAT / ACR refresh status.
  • Inclusive language and assistive-technology testing remain release requirements for the covered workflows.

Need more detail?

We can walk through the repo-backed controls, public documentation, and any additional operational materials available during institutional review.

Email: contact@medsimai.com

Response target: typically within the next business day

Connect with the team