Skip to content
LynxMediq

Security and compliance

Patient data protected by design

Security is an architecture decision, made once for every product in the LynxMediq portfolio. The mechanisms below are the ones that ship in PixelMediq today, and we say just as plainly which certifications are not held.

Controls

The safeguards a healthcare platform should have

Each point below is published by PixelMediq as a mechanism that ships. Future portfolio areas are held to the same set.

Data protection

  • TLS for all user access and gateway traffic
  • Archived objects encrypted at rest by the storage layer
  • Tenant isolation enforced in the database with row-level security
  • Optional de-identification, off by default

Access control

  • Role-based access, scoped within the organization hierarchy
  • OpenID Connect sign-in with short-lived tokens
  • Per-gateway credentials over mutual TLS
  • Site visibility checked on every path

Auditability

  • Append-only audit log
  • A dedicated PHI access log: who saw which patient, and when
  • Operational telemetry that excludes PHI
  • An auditable record of access for your own reviews

Compliance posture

  • Designed for HIPAA safeguards
  • Designed to address GDPR requirements
  • Designed to address India DPDP Act 2023 requirements
  • Data residency decided per deployment

Compliance posture

Designed for compliance, honest about what that means

There is no certification that makes software HIPAA compliant on its own. PixelMediq implements the safeguards the rules call for and gives your team the controls to run a compliant program. We are careful not to overclaim: no SOC 2, ISO 27001, or third-party HIPAA attestation is held today, and AI is decision support with a physician in the loop.

  • Designed for HIPAA administrative, physical, and technical safeguards
  • Designed to address GDPR requirements for EU health data
  • Designed to address India DPDP Act 2023 requirements
  • Business associate agreements discussed during contracting
  • A published DICOM conformance statement for your technical review

Deployment

Run it the way your policies require

PixelMediq runs as three deployment profiles from one codebase, so the deployment can match what your organization and your regulators expect.

  • Multi-tenant cloud with isolation between organizations
  • Fully on-premise, running inside your own estate
  • Hybrid, with an on-premise edge gateway and a cloud archive
  • Storage from on-premise disk to AWS HealthImaging
Current product

PixelMediq

PixelMediq publishes its security model in full: tenant isolation, scoped access, gateway identity, the PHI audit log, subprocessors, and the certifications it does not hold.

You buy, deploy, and run PixelMediq. LynxMediq is the portfolio it belongs to, and there is no second product to purchase alongside it.

FAQ

Questions security and procurement teams ask

Is LynxMediq HIPAA compliant?
LynxMediq is a portfolio, not a deployed system, so the question applies to PixelMediq, the product you run. There is no official HIPAA certification for software. PixelMediq is designed for HIPAA compliance and implements the safeguards the rules call for, including access control, audit logging, encryption, and tenant isolation. A third-party HIPAA attestation is not held today. Ask us about the agreements your program requires, including a business associate agreement.
Does Pixbots hold SOC 2 or ISO 27001?
No. PixelMediq states plainly that SOC 2, ISO 27001, and third-party HIPAA attestation are on its roadmap and are not held today. We would sooner tell you now than during your security review.
Where is imaging data stored?
You choose. PixelMediq abstracts storage across local disk, NAS, S3, S3-compatible object storage, and AWS HealthImaging, and it runs as a cloud, fully on-premise, or hybrid deployment. Data residency is decided per deployment.
Is any of this a regulated medical device?
No FDA clearance or approval is held or claimed, and PixelMediq is not CE marked. AI anywhere in the portfolio is assistive decision support: a physician triggers it, reads the result, and decides. AI models that interpret images carry their own regulatory status, set by the model developer.
How will AI governance work?
Today, AI in PixelMediq runs only when a permitted user triggers it, and the result is an input to a report, never the report. The portfolio direction adds orchestration that records which model and version produced each finding, with confidence scores and an audit trail. That part is in development or on the roadmap and is not available yet.
Can this help us meet GDPR and India DPDP requirements?
PixelMediq is designed to address GDPR and India DPDP Act 2023 requirements, with encryption, scoped access control, an auditable record of access, optional de-identification, and data residency decided per deployment. Your data protection team stays in control of residency and processing.

Bring your security questions

PixelMediq documents the mechanisms. For questions about how future portfolio areas will be held to them, talk to us.