Security & Compliance

DyZen Med is built for environments where accuracy, discretion, and professional responsibility matter.

Security and governance are designed into the platform from the start. DyZen Med supports high‑stakes medical and medical‑legal review workflows while preserving professional control and accountability.

DyZen Med is not a diagnostic or decision‑making system.
It is an assistive intelligence platform intended to support — not replace — the independent judgment of licensed professionals.

Data Handling

DyZen Med processes medical records solely to deliver the structured outputs requested by authorized professionals. Records are not used to train shared or public AI models and are not shared outside the intended workflow.

Where organizations handle PHI, processing is limited to approved, controlled paths and requires acceptance of the current Business Associate Agreement (BAA) in the product before uploads can proceed.

Access Control

DyZen Med is designed for responsible use in professional workflows while remaining accessible to users with a lawful need to organize and review medical records.

Access is managed through secure authentication, with role-based controls and operational logging to support accountability and appropriate use.

DyZen Med is hosted on AWS and uses modern transport security (TLS). Authentication events and admin actions are logged to support accountability.

Agreements, subprocessors, and AI processing

DyZen Med operates in a compliance-aligned environment for PHI: we maintain Business Associate Agreements with AWS and with OpenAI for qualifying processing. AI inference for supported features is configured with Zero Data Retention where available for supported endpoints.

Administrative, billing, and upload flows respect the organization’s BAA state; chat and support messaging are not covered channels for PHI, and the service blocks content that appears to contain patient identifiers in those channels.

Compliance visibility

Organizations can review BAA and compliance status, view acceptance history, and download a point-in-time compliance report (PDF) from Profile → Compliance and Organization → Security & compliance in the application.

Professional Responsibility

All outputs generated by DyZen Med are intended to assist licensed professionals in review and documentation workflows. Responsibility for interpretation, conclusions, and decision‑making remains with the professional user.

For additional security questions, contact info@dyzenmed.com.