MediLink handles protected health information and case data. We treat compliance as a baseline requirement, not an afterthought.
Last updated: May 19, 2026
MediLink is a covered entity's business associate when it processes protected health information (PHI) on behalf of medical providers and law firms. We maintain administrative, physical, and technical safeguards consistent with the HIPAA Privacy and Security Rules, including:
Every clinic and firm accepts our Business Associate Agreement at onboarding, and you can read it in full at medilink.vip/baa before you sign up. We are glad to execute it by signature, or to review your own BAA form, on request. We also require a BAA with each infrastructure subprocessor that handles PHI on our behalf.
Before a clinic is matched with referrals, we verify:
Personal injury referrals are governed by overlapping state rules — including fee-splitting, anti-kickback, and physician self-referral restrictions. MediLink's operating model is designed so that attorneys and clinics each contract directly with MediLink for software and verification services, not for case-by-case referral payments. Availability and pricing of certain features may vary by state.
If you believe you've found a security vulnerability or a privacy incident affecting MediLink, please call us at +1 (833) 407-1005. We acknowledge reports within one business day and respond on a coordinated-disclosure basis.