Loading...
Loading...
This page gives hospital IT and security teams the data, hosting, authentication, and operational facts needed to review Meridyon — plus the domains, browser requirements, email delivery guidance, and support escalation paths needed to prepare for go-live.
It doubles as a starting point for security questionnaires. For a security packet or any questions, email [email protected].
Meridyon is PHI-free by design. It stores no patient records or clinical data — it schedules clinicians, not patients. Because no PHI is stored, a HIPAA Business Associate Agreement is generally not required; we recommend IT confirm with their own counsel. Your security review covers a workforce-scheduling tool, not a clinical data system.
In transit: TLS 1.2+ — HTTPS on port 443 only.
At rest: data at rest is managed by the hosting provider’s infrastructure.
Third-party vendors Meridyon relies on to operate the service.
We state this plainly because it’s deliberate. What we do stand behind: no patient records or clinical data, verified-ID-token SSO, audit trails with real before/after values, backups we’ve actually restored from, and a public status page.
Meridyon will not function reliably without these.
*.meridyon.comHTTPS/443schedule.meridyon.comHTTPS/443The app can run without these, but monitoring, analytics, or email may degrade.
*.sentry.ioHTTPS/443api.resend.comHTTPS/443static.cloudflareinsights.comHTTPS/443cloudflareinsights.comHTTPS/443Meridyon supports current stable browser versions and does not support Internet Explorer or legacy embedded webviews.
Meridyon sends transactional scheduling mail from sender addresses on the meridyon.com domain. Allow these domains for notifications, request replies, invitations, and password reset messages.
No lock-in. Customers can export their data at any time: