Security

Security Measures

MedicalRide.org uses technical and organizational measures intended to protect ride, provider, payment, privacy, and operational data. This page summarizes safeguards used to operate the service responsibly.

Publisher details are available in the Legal Notice.

Current safeguards

  • HTTPS transport where supported by the deployment environment
  • HttpOnly, SameSite, secure production cookies for admin and provider sessions
  • Signed session tokens with explicit expiry for admin and provider sessions
  • Admin login rate limiting with hashed email/IP identifiers
  • Authenticator-app MFA support and administrative access policy controls
  • Same-origin checks for privileged admin server-action mutations
  • Admin API mutation routes require signed webhook auth or same-origin admin sessions
  • Same-origin checks for provider-authenticated AI Assistant API mutations
  • Sensitive-data access logging for admin ride-request, privacy-rights, provider, equipment, vendor-evidence, and subject-export views
  • Provider Compliance Desk workspace views, file downloads, and packet downloads audited in the provider compliance ledger
  • Role-based permission checks for privacy, security, and admin-management workflows
  • Restricted handling controls for covered-entity and business-associate workflows
  • Role/account checks for protected admin and provider areas
  • Consent evidence logging for key customer, provider, cookie, and privacy-rights events
  • Privacy-rights queue with status, deadline, and internal-note tracking
  • Approval-gated retention execution runner for eligible ready-only deletion/redaction batches
  • Payment card handling delegated to payment processors instead of storing full card numbers
  • Non-essential analytics and advertising tags gated behind cookie/privacy choices
  • Operational audit queues for live payment, routing, provider, and workflow issues

Privacy operations supported by these controls

The safeguards above connect to the broader privacy program MedicalRide publishes across its legal pages.

  • Clear operator identity

    MedicalRide.org is operated by Tipmunk SASU, with public controller and contact details listed in the Legal Notice and Privacy Policy.

    Legal Notice
  • Directory platform boundary

    MedicalRide presents a directory and request platform. Independent providers remain responsible for transportation services, vehicles, drivers, licensing, insurance, pricing, and ride completion.

    Terms
  • Consent and privacy choices

    Non-essential analytics and advertising tags stay off unless allowed, Global Privacy Control is honored where applicable, and key consent choices are recorded.

    Privacy Choices
  • Rights request workflow

    People can request access, correction, deletion, portability, consent withdrawal, and California privacy choices through a dedicated intake form.

    Data Rights
  • Retention and deletion controls

    MedicalRide publishes baseline retention categories and uses review, legal-hold, and approval steps before eligible deletion or redaction runs.

    Retention
  • Vendor transparency

    The vendor register lists core provider categories, data categories, transfer evidence, BAA availability, and public legal evidence links.

    Subprocessors
  • Security and audit controls

    Admin/session controls, role-based permissions, rate limits, same-origin checks, and sensitive-access audit logs support privacy operations.

    Security
  • Organization agreement evidence

    Organizations can accept directory-platform terms through an electronic agreement flow that records authority, accepted text, and request context.

    Organization agreement

Sensitive data handling

MedicalRide.org aims to collect only information reasonably needed to evaluate, quote, coordinate, support, and document a transportation request. Ride information may include mobility, accessibility, disability, equipment, address, appointment, and caregiver details that require extra care even where HIPAA does not apply. Covered-entity and BAA prerequisites are summarized on the Patient Data and HIPAA Context page.

Non-essential trackers are blocked unless the visitor allows the relevant consent category. California privacy choices, including Do Not Sell or Share and Limit Use of Sensitive Personal Information controls, are available on the Privacy Choices page.

Vendor and payment safeguards

MedicalRide.org uses vendors for hosting, database services, payments, communications, address lookup, analytics, and operations. Vendor categories are published in the Subprocessors and Vendor Register. Payment card details are handled by payment processors; MedicalRide should retain only payment metadata needed for coordination, receipts, refunds, disputes, tax/accounting, and legal obligations.

Reporting security or privacy concerns

Report suspected security, privacy, or data-handling issues to support@medicalride.org. Privacy rights requests can also be submitted through the Data Rights Request form.