← Back to Medora
Medora addendum

Medora Privacy Notice

Effective August 24, 2026. Read alongside the Callora master Privacy Policy. This addendum documents how Medora handles physician data and PHI.

1. Data categories

  • Public directory data — NPPES, state medical board rosters, OIG LEIE, SAM.gov. Public records, no PHI.
  • Recruiter-uploaded candidate data — CV, license #s, board certifications, references. Not PHI on its own; may become PHI when combined with placement details.
  • PHI (in-scope for BAA customers only) — DEA numbers, malpractice case data, clinical transcripts, peer-review letters.
  • Communications — SMS / iMessage / voice transcripts with candidates. Retention: 24 months on paid tiers, 90 days on free.
  • Consent records — timestamp, IP, source, hash-chained. Retained for the life of the recruiter account plus 4 years (federal TCPA statute of limitations).

2. Field-level encryption

DEA numbers, license expiration reminders that include DOB, and any BAA-scoped PHI are encrypted at rest using AES-256-GCM with an application-managed key (rotation every 90 days). See the HIPAA architecture page for the full control-family list.

3. Subprocessors (Medora-specific)

VendorPurposeRegionPHI in-scope?
TwilioSMS + voiceUS-EastYes (BAA on file)
OpenAISarah’s realtime + transcriptsUSYes (BAA on file, no-training tenant)
Docuseal (self-hosted)LOA e-signatureCustomer-controlledYes
ZeroBounceEmail deliverabilityUSNo (email only)
CMS NPPESPublic provider directoryUS-federalNo (public record)
MongoDB AtlasPrimary datastoreUS-East (VPC-peered)Yes (BAA on file)

4. Physician rights

Any physician represented in the Medora directory can:

  • Request removal via POST /api/providers/opt-out (self-service, no account required).
  • Request a full export of their data at privacy@call.metis.gold.
  • Request rectification of any inaccurate license / board / contact record.
  • Object to any Sarah-initiated outreach; the STOP / QUIT keyword also functions as an object-to-outreach request.

5. Data residency

Medora data is stored in US-East. EU-region storage is available on the Agency plan on request; contact sales for the region and subprocessor tree.

6. Breach notification

In the event of a security incident affecting your data, Medora will notify you within 24 hours of confirmed detection. For BAA customers we additionally follow the HIPAA Breach Notification Rule’s 60-day window and provide the OCR-required content in the breach notice template.

Privacy contact: privacy@call.metis.gold · See also the HIPAA architecture page.