Security | Medplum

Security as a Company Value

Medplum’s security & compliance principles guide how we deliver our products and services, enabling people to simply and securely access the digital world.

Secure Personnel

Medplum takes the security of its data and that of its clients and customers seriously and ensures that only vetted personnel are given access to their resources.

Secure Development

Secure Testing

Medplum deploys third party penetration testing and vulnerability scanning of all production and Internet facing systems on a regular basis.

Cloud Security

Hosted Medplum provides maximum security with complete customer isolation in a modern, multi-tenant cloud architecture. Hosted Medplum leverages the native physical and network security features of the cloud service, and relies on the providers to maintain the infrastructure, services, and physical access policies and procedures.

Guidelines

General Server Security (NIST SP 800-123)

All servers will be installed, hardened, and maintained in accordance with the principles outlined in NIST SP 800-123. This includes, but is not limited to:

Application Container Security (NIST SP 800-190)

For all applications deployed in containers, we will follow the security guidelines provided in NIST SP 800-190. This includes, but is not limited to:

Definition and Use of Microservices, Application Containers, and System Virtual Machines (NIST SP 800-180)

We will adhere to the definitions and best practices outlined in NIST SP 800-180 when designing and implementing architectures involving microservices, application containers, and system virtual machines. This includes:

Web Application Security Scanning (NIST SP 500-269)

In alignment with the best practices defined in NIST SP 500-269, "Software Assurance Tools: Web Application Security Scanner Functional Specification", we utilize software assurance tools throughout our software development lifecycle (SDLC) to ensure the security of our web applications. Medplum uses AWS Web Application Firewall as an additional layer of protection against common exploits. By default, the WAF includes the following rule groups:

Application Security

Continuous Security Commitment

Compliance

Medplum is committed to providing secure products and services to safely and easily manage billions of digital identities across the globe. Our external certifications provide independent assurance of Medplum’s dedication to protecting our customers by regularly assessing and validating the protections and effective security practices Medplum has in place.

SOC 2 Type 1 & 2

Orangebot, Inc (dba Medplum) successfully completed the AICPA Service Organization Control (SOC) 2 Type II audit. The audit confirms that Orangebot, Inc (dba Medplum)’s information security practices, policies, procedures, and operations meet the SOC 2 standards for security. Medplum was audited by Prescient Assurance, a leader in security and compliance certifications for B2B, SAAS companies worldwide. Prescient Assurance is a registered public accounting in the US and Canada and provide risk management and assurance services which includes but not limited to SOC 2, PCI, ISO, NIST, GDPR, CCPA, HIPAA, CSA STAR etc. For more information about Prescient Assurance, you may reach out them at info@prescientassurance.com. An unqualified opinion on a SOC 2 Type II audit report demonstrates to the Medplum’s current and future customers that they manage their data with the highest standard of security and compliance.

Security Tools

Medplum continuously monitors all services to track security best practices.

SonarCloud

SonarCloud is a cloud-based code quality and security service.

Mozilla Observatory

Mozilla Observatory is a tool that is geared towards informing website owners of best practices for securing their sites.

SSL Labs

SSL Labs is an online service that performs a deep analysis of the configuration of any SSL web server on the public Internet.

Socket

Socket is a security platform that specializes in analyzing and monitoring software dependencies throughout the development pipeline, with a particular focus on detecting malicious code and vulnerabilities in real-time during pull requests.

Docker Scout

Docker Scout is a security solution that analyzes container images by creating a Software Bill of Materials (SBOM) and checking components against known vulnerabilities in real-time, helping organizations proactively identify and address security weaknesses in their containerized applications.

Docker Hardened Images (DHI)

Medplum builds server images on Docker Hardened Images (DHI), a minimal, security-focused base image designed to reduce attack surface and unnecessary packages. Moving to DHI significantly reduces downstream CVE noise in customer security scans without changing application behavior.

Security Scorecard

Security Scorecard is an information security company that rates cybersecurity postures of corporate entities through completing scored analysis of cyber threat intelligence signals for the purposes of third party management and IT risk management.

OpenSSF Scorecard

OpenSSF Scorecard is a tool that automatically checks a project's repository against a set of security best practices and assigns a risk score.

OpenSSF Best Practices

OpenSSF Best Practices is a badge program that allows open source projects to demonstrate their adherence to security-related best practices.

Snyk

Snyk is a comprehensive developer security platform that integrates security scanning across proprietary code, open source dependencies, container images, and cloud infrastructure, providing unified vulnerability detection and remediation capabilities throughout the development lifecycle.

GitHub CodeQL

CodeQL is a semantic code analysis engine that treats code as queryable data, allowing developers to write and run queries to identify potential vulnerabilities and their variants across an entire codebase.

GitHub Dependabot

GitHub Dependabot is an automated dependency management tool that continuously monitors repository dependencies, creating pull requests to update outdated packages and alerting developers to security vulnerabilities in their project's dependencies.

Availability

Medplum tracks and reports status on the Medplum Status Page using StatusCake and Pingdom.

Report Vulnerabilities

Found a potential issue? Please help us by reporting it so we can fix it quickly. Contact us at security@medplum.com