
This DPA explains how hospitals, clinics, laboratories, pharmacies, HMOs, and other enterprise customers authorize Medhandy to process data on their behalf for healthcare operations.
Controller and processor
Describes when a customer acts as controller and when Medhandy acts as processor or service provider.
Processing rules
Covers scope, purpose, security, subprocessors, breach handling, and retention.
Hospital use
Useful for enterprise onboarding and institutional procurement review.
Contents
Support
For privacy, legal, or policy questions, contact support@medhandy.net.
This agreement applies when an organization uses Medhandy to process patient or operational data. The customer remains responsible for determining the lawful purpose and instructions for processing, subject to applicable law and contractual terms.
The customer instructs Medhandy to process information for healthcare administration, care coordination, records management, security, reporting, and related operational workflows.
Medhandy may use service providers for hosting, monitoring, messaging, support, and other operational functions. Such providers should be bound by appropriate confidentiality and security obligations.
Where a reportable incident occurs, Medhandy should investigate, contain, and communicate the issue in accordance with the contract, applicable law, and internal incident procedures.
Data should be retained and deleted according to the customer's instructions, legal retention requirements, and operational needs. Medical records may require longer retention periods.
For enterprise or procurement questions, contact support@medhandy.net.
This DPA should be attached to the enterprise onboarding pack for hospitals and institutional customers.