Med-Stop

Security Policy and Information

Security Policy and Information

Use of Med-Stop websites, services, and applications requires you to review this Security Policy.

Med-Stop Security Policy

Med-Stop takes the security of customer, employer, employee, donor, testing, medical, and compliance-related information seriously. We use administrative, technical, and physical safeguards designed to protect information from unauthorized access, disclosure, alteration, misuse, loss, or destruction.

Security is built into the way Med-Stop operates its websites, applications, APIs, databases, infrastructure, and support processes. We use layered security controls, including secure cloud infrastructure, firewalls, encryption, access controls, monitoring, backups, and incident response procedures.

No system connected to the Internet can be guaranteed to be completely secure. However, Med-Stop continuously evaluates security risks and implements reasonable safeguards to protect the confidentiality, integrity, and availability of Med-Stop systems and information.

Secure Cloud Infrastructure

Med-Stop systems are hosted using secure cloud infrastructure, including Microsoft Azure services. Azure data centers use physical, environmental, and operational security controls designed to restrict access to authorized personnel only and protect hosted systems from unauthorized physical access, power loss, fire, environmental damage, and other operational risks.

Med-Stop uses cloud-based architecture, network controls, system configuration, monitoring, and operational procedures designed to protect Med-Stop services and support reliable system operation.

Cloudflare Protection

Med-Stop uses Cloudflare and related security services to help protect public-facing websites, applications, and services. These protections may include web application firewall controls, traffic filtering, distributed denial-of-service protection, bot mitigation, DNS security, rate limiting, caching, and monitoring of suspicious traffic patterns.

Cloudflare helps reduce exposure to common web attacks and improves the availability and resilience of Med-Stop services.

Firewalls and Network Security

Med-Stop uses firewalls, network security controls, access restrictions, and traffic monitoring to help protect systems from unauthorized access and malicious activity.

Firewalls are used to restrict network traffic and allow only authorized communication between systems, services, users, and trusted partners. Network activity may be logged and monitored for security, auditing, troubleshooting, abuse prevention, and incident response purposes.

Med-Stop also uses segmentation and access controls where appropriate to limit exposure between systems and reduce the risk of unauthorized access.

AI-Assisted Monitoring and Threat Detection

Med-Stop uses monitoring tools, automated alerts, and advanced AI-assisted security analysis to help detect suspicious activity, unusual behavior, abuse patterns, access anomalies, system errors, and potential threats.

Security monitoring may include analysis of application activity, authentication activity, network events, API usage, system logs, firewall activity, and other operational signals. These tools help Med-Stop identify and respond to security, reliability, and compliance concerns more quickly.

AI-assisted monitoring is used as part of Med-Stop's broader security program and does not replace human review, investigation, or response where needed.

Encryption

Med-Stop uses modern encryption technologies to help protect sensitive information transmitted over the Internet. Med-Stop websites, applications, and APIs use HTTPS with TLS encryption to protect data in transit between users, browsers, applications, APIs, and Med-Stop systems.

Med-Stop also uses encryption and other protective controls for stored data where appropriate, including databases, backups, credentials, and sensitive system information.

Older encryption technologies such as SSL and outdated cipher methods are not used as the standard for modern Med-Stop secure communications.

User Accounts and Authentication

Each authorized user should have a unique account and login credentials. Users are responsible for keeping their usernames, passwords, API keys, and other credentials confidential and secure.

Med-Stop uses authentication, access controls, user roles, account permissions, session controls, and other security methods to help ensure that users can access only the information and functions they are authorized to use.

Account access may be restricted, suspended, or disabled if Med-Stop detects suspicious activity, unauthorized use, security risk, policy violations, or other activity that may place Med-Stop systems or data at risk.

Passwords and Access Credentials

Users must protect their passwords and access credentials. You should not share passwords, API keys, tokens, or other access credentials with unauthorized persons.

Passwords should be strong, unique, and difficult to guess. Users should avoid common words, reused passwords, personal information, predictable patterns, or passwords used on other websites or systems.

You should immediately notify Med-Stop if you believe your account, password, API key, token, device, or other access credential has been lost, stolen, exposed, or used without authorization.

Device and Browser Security

Users are responsible for maintaining the security of their own computers, mobile devices, browsers, networks, and email accounts used to access Med-Stop services.

To use Med-Stop services securely, users should use a modern browser, keep operating systems and browsers updated, enable security updates, protect devices with passwords or biometric controls, use antivirus or endpoint protection where appropriate, and avoid accessing Med-Stop systems from unsecured or shared devices.

Med-Stop services may require cookies, JavaScript, secure browser settings, and other browser capabilities needed for authentication, session management, fraud prevention, security monitoring, and application functionality.

Cookies and Session Security

Med-Stop may use cookies, session identifiers, device identifiers, and similar technologies to support authentication, session management, user preferences, fraud prevention, security monitoring, and authorized access to secure applications.

Cookies cannot be used to run programs or deliver viruses to your computer. Cookies are assigned to your browser or device and are used only for purposes related to website functionality, security, analytics, or authorized service access.

Disabling cookies or browser security features may prevent Med-Stop services from working properly.

Sign Out and Session Timeout

Users should sign out of Med-Stop services when finished or when leaving a computer or device unattended. Signing out helps prevent unauthorized access by other users of the same device.

Med-Stop may automatically time out inactive sessions. After a session timeout, the user may be required to sign in again before continuing to use secure areas of the service.

Users should also close the browser or lock the device when using a shared, public, or unattended computer.

Data Backup and Recovery

Med-Stop uses backup and recovery procedures designed to protect information against accidental loss, system failure, hardware failure, operational errors, and disaster events.

Med-Stop may use redundant systems, database backups, encrypted backups, off-site backups, cloud backups, and recovery procedures to support business continuity and restoration of services.

Backup data is protected using access controls and security safeguards appropriate to the sensitivity of the information.

Off-Site Backups and Disaster Recovery

Med-Stop maintains off-site backup and recovery capabilities to help protect against local system failures, physical incidents, natural disasters, ransomware, accidental deletion, and other events that could affect system availability or data integrity.

Disaster recovery and contingency procedures are reviewed and improved as needed to support service continuity, data recovery, and incident response.

Application and API Security

Med-Stop applies security controls to its websites, applications, and APIs. These controls may include authentication, authorization, input validation, logging, rate limiting, API keys, secure development practices, access scopes, monitoring, and review of suspicious or abusive activity.

API users and integration partners are responsible for securing their own applications, systems, API credentials, networks, users, and data handling processes. API keys and credentials must not be exposed in public code repositories, browser-side code, screenshots, support tickets, logs, or other insecure locations.

Access Control and Least Privilege

Med-Stop uses access control practices designed to limit access to systems and information based on business need, user role, authorization, and responsibility.

Users should be granted only the access they need to perform their work. Employers and account administrators are responsible for reviewing user access, removing users who no longer need access, and ensuring that authorized users have appropriate permissions.

Employee and Operational Security

Med-Stop limits access to sensitive systems and information to authorized personnel with a legitimate business need. Med-Stop personnel are expected to follow security, confidentiality, privacy, and acceptable-use requirements.

Operational access may be logged, monitored, reviewed, restricted, or revoked based on job responsibility, security risk, compliance requirements, or business need.

Third-Party Providers

Med-Stop may rely on trusted third-party providers for hosting, infrastructure, security, communications, payment processing, analytics, support, laboratory processing, Medical Review Officer services, and other operational services.

Med-Stop works to use providers that maintain appropriate security controls for the services they provide. However, some third-party systems, laboratories, collection sites, communication networks, government systems, and payment systems are outside Med-Stop's direct control.

Security Incidents

Med-Stop maintains processes for identifying, investigating, responding to, and mitigating security incidents. Security events may be reviewed using system logs, monitoring tools, security alerts, user reports, and other available information.

If Med-Stop determines that a security incident affects personal information, protected health information, DOT-regulated testing information, or other sensitive information, Med-Stop will respond in accordance with applicable legal, regulatory, contractual, and operational requirements.

Email and Phishing Protection

Med-Stop will not ask users to send passwords, API keys, tokens, or full payment card numbers by email.

If you receive an email, text message, phone call, or website link that appears to be from Med-Stop but asks for your password, API key, payment information, or other sensitive credentials, treat it as suspicious. Do not click links or provide sensitive information unless you can verify the request.

Suspicious messages claiming to be from Med-Stop should be forwarded to security@med-stop.com. If possible, include the full email headers, sender information, screenshots, and any links or attachments involved.

Your Security Responsibilities

Security is a shared responsibility. Med-Stop protects its systems and services, but users, employers, administrators, developers, and integration partners are responsible for protecting their own accounts, devices, networks, applications, and credentials.

You are responsible for using strong passwords, protecting access credentials, keeping contact information current, removing inactive users, reviewing account activity where available, reporting suspected unauthorized access, and using Med-Stop services only from trusted devices and secure networks.

Reporting Security Concerns

If you believe you have discovered a security vulnerability, unauthorized access, exposed credential, suspicious activity, phishing message, or other security concern involving Med-Stop systems, please contact Med-Stop promptly at security@med-stop.com.

Please include enough information to help Med-Stop understand and investigate the issue, such as the affected system, date and time, description of the concern, screenshots, logs, URLs, account information, and steps to reproduce the issue where appropriate.

Changes to this Security Policy

Med-Stop may update this Security Policy from time to time to reflect changes in technology, security practices, services, legal requirements, or operational needs. When updates are made, the updated version will be posted or otherwise made available by Med-Stop.

Do you need more information?

If you need our assistance, or want to know more about Med-Stop, please write below how we can help or call us at 1-(877) 633-3633

Contact us

Contact information

For inquiries or additional information about Med-Stop, feel free to contact us through our support form or via the contact details listed below.

Toll-Free Phone:
1-(877) NEED-MED
Email
support@med-stop.com

Send us a message

Max. 500 characters