Medora Privacy Notice
Effective August 24, 2026. Read alongside the Callora master Privacy Policy. This addendum documents how Medora handles physician data and PHI.
1. Data categories
- Public directory data — NPPES, state medical board rosters, OIG LEIE, SAM.gov. Public records, no PHI.
- Recruiter-uploaded candidate data — CV, license #s, board certifications, references. Not PHI on its own; may become PHI when combined with placement details.
- PHI (in-scope for BAA customers only) — DEA numbers, malpractice case data, clinical transcripts, peer-review letters.
- Communications — SMS / iMessage / voice transcripts with candidates. Retention: 24 months on paid tiers, 90 days on free.
- Consent records — timestamp, IP, source, hash-chained. Retained for the life of the recruiter account plus 4 years (federal TCPA statute of limitations).
2. Field-level encryption
DEA numbers, license expiration reminders that include DOB, and any BAA-scoped PHI are encrypted at rest using AES-256-GCM with an application-managed key (rotation every 90 days). See the HIPAA architecture page for the full control-family list.
3. Subprocessors (Medora-specific)
| Vendor | Purpose | Region | PHI in-scope? |
|---|---|---|---|
| Twilio | SMS + voice | US-East | Yes (BAA on file) |
| OpenAI | Sarah’s realtime + transcripts | US | Yes (BAA on file, no-training tenant) |
| Docuseal (self-hosted) | LOA e-signature | Customer-controlled | Yes |
| ZeroBounce | Email deliverability | US | No (email only) |
| CMS NPPES | Public provider directory | US-federal | No (public record) |
| MongoDB Atlas | Primary datastore | US-East (VPC-peered) | Yes (BAA on file) |
4. Physician rights
Any physician represented in the Medora directory can:
- Request removal via
POST /api/providers/opt-out(self-service, no account required). - Request a full export of their data at privacy@call.metis.gold.
- Request rectification of any inaccurate license / board / contact record.
- Object to any Sarah-initiated outreach; the STOP / QUIT keyword also functions as an object-to-outreach request.
5. Data residency
Medora data is stored in US-East. EU-region storage is available on the Agency plan on request; contact sales for the region and subprocessor tree.
6. Breach notification
In the event of a security incident affecting your data, Medora will notify you within 24 hours of confirmed detection. For BAA customers we additionally follow the HIPAA Breach Notification Rule’s 60-day window and provide the OCR-required content in the breach notice template.