MYCURE Logo
MYCURE
Back to Home

Security Overview

MYCURE CMS is designed to support healthcare organizations that handle sensitive clinical, patient, operational, and administrative information.

Effective Date: August 11, 2026

Team OPS Inc. dba MYCURE (“MYCURE,” “we,” “us,” or “our”)

Team OPS Inc. dba MYCURE (“MYCURE,” “we,” “us,” or “our”) maintains security measures appropriate to the services and systems we operate.

Security is a shared responsibility. MYCURE is responsible for safeguards applicable to MYCURE CMS and the systems under our control. Customers remain responsible for users, permissions, devices, networks, workflows, third-party systems, and other environments or activities under their control.

This Security Overview describes our general security approach. It is not an exhaustive description of every control, configuration, policy, technology, or procedure and does not establish a service-level commitment.

More specific requirements may be established in an applicable Order Form, service agreement, Data Processing Agreement, Security Agreement, Business Associate Agreement, Service Level Agreement, or other written agreement.

1. Security Principles

MYCURE's security approach is guided by principles that include:

  • protecting Customer Data appropriate to its sensitivity and risk;
  • limiting access according to role and operational need;
  • supporting accountability and auditability;
  • maintaining appropriate technical, administrative, and organizational safeguards;
  • protecting systems and services under MYCURE's control;
  • applying security controls appropriate to healthcare workflows;
  • supporting Customer security and compliance requirements where applicable; and
  • adapting security practices as technology, risks, services, and legal requirements evolve.

Security measures are intended to reduce risk. No information system, network, software service, authentication mechanism, or security control can eliminate all security risk.

2. Shared Responsibility

Security of MYCURE CMS depends both on the safeguards maintained by MYCURE and on how Customers deploy, configure, administer, and use the service.

MYCURE Responsibilities

Depending on the applicable deployment model and written agreement, MYCURE is generally responsible for matters under its control, which may include:

  • application-level security controls;
  • authentication capabilities;
  • role and permission functionality;
  • access controls for MYCURE personnel;
  • security of MYCURE-operated systems;
  • application maintenance and security updates;
  • logging and monitoring appropriate to MYCURE-operated components;
  • support-access controls;
  • security-incident response procedures;
  • vulnerability and threat management for systems under MYCURE's control;
  • backup and recovery processes for MYCURE-hosted services; and
  • appropriate safeguards for Subprocessors engaged by MYCURE.

Customer Responsibilities

Customers are generally responsible for matters under their control, including:

  • determining who may use MYCURE CMS;
  • creating and approving Authorized Users;
  • assigning appropriate roles and permissions;
  • periodically reviewing users and privileges;
  • promptly removing access that is no longer required;
  • protecting passwords and authentication factors;
  • complying with applicable multi-factor authentication requirements;
  • securing Customer-controlled email accounts;
  • securing Customer-controlled devices, browsers, endpoints, and networks;
  • preventing unauthorized account sharing or access;
  • securing information exported or downloaded from MYCURE CMS;
  • configuring Customer workflows and integrations appropriately;
  • training personnel on appropriate privacy and security practices;
  • maintaining appropriate internal security and privacy policies;
  • responding to security events within Customer-controlled environments;
  • maintaining appropriate downtime and business-continuity procedures; and
  • complying with laws and regulatory requirements applicable to the Customer.

The applicable written agreement may further define or modify this allocation for a particular deployment.

3. Hosting and Deployment Models

MYCURE CMS may be deployed using different hosting and infrastructure arrangements.

MYCURE-Hosted Services

For MYCURE-hosted services, MYCURE is responsible for the hosting, platform, application, and related infrastructure safeguards within the scope of the systems and services operated by MYCURE and its authorized Subprocessors.

Specific hosting locations, Subprocessors, backup arrangements, and contractual responsibilities may be described in the applicable Customer agreement and our Subprocessor List.

Client-Hosted and Customer-Managed Environments

MYCURE CMS may also be deployed in infrastructure selected, provided, administered, or controlled by the Customer.

Unless otherwise expressly agreed in writing, the Customer is responsible for the security and administration of its Customer-controlled environment, including as applicable:

  • cloud accounts or subscriptions;
  • servers or compute infrastructure;
  • operating systems;
  • container or orchestration infrastructure;
  • databases and storage controlled by the Customer;
  • networks;
  • firewalls;
  • network-security configurations;
  • identity and access controls for the Customer environment;
  • encryption or key-management systems controlled by the Customer;
  • infrastructure monitoring;
  • infrastructure logging;
  • backups and recovery for Customer-controlled systems;
  • vulnerability management for Customer-controlled infrastructure;
  • patching and maintenance of Customer-controlled components; and
  • physical or environmental security where applicable.

MYCURE may provide deployment support, application support, troubleshooting, or technical guidance relating to MYCURE CMS.

Unless separately agreed in writing, such activities do not make MYCURE the administrator or operator of the Customer-controlled infrastructure and do not transfer responsibility for that environment to MYCURE.

The applicable Order Form, Statement of Work, service agreement, Security Agreement, or other written agreement may provide a more specific allocation of responsibilities.

4. Data Protection

MYCURE applies safeguards designed to protect Customer Data processed through systems under MYCURE's control.

Depending on deployment and applicable functionality, these measures may include:

  • encrypted network connections;
  • encryption or equivalent safeguards for stored data where applicable;
  • authentication controls;
  • role-based access controls;
  • administrative access restrictions;
  • audit, application, authentication, or security logging;
  • security monitoring;
  • backup and recovery processes;
  • secure configuration practices;
  • personnel access controls;
  • confidentiality requirements;
  • security-incident procedures; and
  • internal security policies and processes.

The specific technologies and implementation of these safeguards may evolve over time.

MYCURE may modify, replace, upgrade, reconfigure, or discontinue internal technologies and security components as reasonably necessary to maintain, secure, develop, or improve MYCURE CMS.

5. Access Control

MYCURE CMS provides access-control functionality intended to help Customers restrict access according to organizational roles and operational requirements.

Depending on the applicable configuration and enabled functionality, controls may include:

  • individual user accounts;
  • role-based permissions;
  • administrator controls;
  • account and organization settings;
  • authentication requirements;
  • session controls;
  • functional or module-level restrictions;
  • user-access management; and
  • activity records.

Customers are responsible for assigning appropriate permissions and promptly removing access when a user is no longer authorized.

A technical access-control capability does not determine whether a particular person should legally or operationally have access to particular information. That determination remains the Customer's responsibility.

6. Multi-Factor Authentication and Account Security

MYCURE CMS supports multi-factor authentication and may require MFA or other reasonable authentication controls for some or all users, accounts, or functionality.

Where MYCURE requires MFA or another security control as a condition of access, Customers and affected users must complete and maintain the applicable security requirement.

Customers and users are responsible for:

  • keeping passwords and authentication factors confidential;
  • maintaining access to required account email addresses;
  • not sharing accounts or authentication factors with unauthorized persons;
  • protecting account-recovery credentials;
  • securing devices used to access MYCURE CMS;
  • promptly reporting suspected credential compromise;
  • regularly reviewing Authorized Users; and
  • not disabling, bypassing, or circumventing required security controls.

MYCURE may restrict, suspend, reset, or revoke access where reasonably necessary to address suspected credential compromise, unauthorized access, misuse, or another material security risk.

7. Logging and Auditability

MYCURE CMS maintains logging and activity records appropriate to applicable service components.

Depending on configuration and technical availability, recorded information may include:

  • user or account identifiers;
  • authentication events;
  • date and time information;
  • source network information where available;
  • administrative activity;
  • material application activity;
  • changes to records;
  • system events; and
  • security-related events.

Logging supports purposes such as:

  • security;
  • troubleshooting;
  • operational monitoring;
  • accountability;
  • investigation; and
  • incident response.

The availability, granularity, and retention of particular events may vary according to the component, deployment model, technical feasibility, security requirements, and evolution of MYCURE CMS.

MYCURE logging is not represented as a complete forensic system capable of detecting every unauthorized action or reconstructing every activity performed through the service.

Customers should not rely on MYCURE logging as their sole organizational, regulatory, fraud-detection, or personnel-monitoring control.

8. MYCURE Personnel and Support Access

Access to production Customer Data by MYCURE personnel is restricted to authorized personnel with an appropriate operational need.

Such access may occur where reasonably necessary for:

  • support;
  • maintenance;
  • troubleshooting;
  • security;
  • incident investigation or response;
  • backup or recovery;
  • service administration;
  • compliance with applicable law; or
  • other activities necessary to provide the applicable service.

Authorized personnel are subject to applicable access controls and confidentiality obligations.

Customers should avoid including unnecessary Patient Data, credentials, passwords, authentication factors, or sensitive information in support communications.

Where specific Customer Data is reasonably necessary to diagnose or resolve an issue, Customers should provide only the information necessary for that purpose.

9. Backups, Recovery, and Business Continuity

For MYCURE-hosted services, MYCURE maintains backup, recovery, and business-continuity processes appropriate to the applicable service and risk.

Backup architecture, frequency, retention, technology, and recovery procedures may vary or evolve based on:

  • deployment model;
  • service architecture;
  • technology;
  • capacity;
  • security requirements;
  • operational requirements; and
  • applicable written agreements.

Unless expressly established in a separately executed Service Level Agreement or other written agreement, this Security Overview does not establish:

  • a guaranteed recovery-point objective;
  • a guaranteed recovery-time objective;
  • uninterrupted availability;
  • zero data loss;
  • a guaranteed backup-retention period; or
  • a guaranteed restoration time.

For client-hosted or Customer-managed deployments, backup and recovery responsibilities for Customer-controlled infrastructure remain with the Customer unless expressly assigned otherwise in writing.

Customers remain responsible for maintaining any independent exports, archives, downtime procedures, or additional records required for their legal, regulatory, clinical, or operational needs.

10. Secure Development and Maintenance

MYCURE maintains development and maintenance practices designed to support the security and reliability of MYCURE CMS.

Depending on the system and development activity, these practices may include:

  • code review;
  • software testing;
  • access controls for development and production systems;
  • issue and defect tracking;
  • dependency management;
  • vulnerability review;
  • change management;
  • security updates;
  • monitoring;
  • maintenance; and
  • separation of development activities from production Customer Data where appropriate.

Production Customer Data is not authorized for use in development tools merely for software-development convenience.

Development and security practices may evolve as MYCURE CMS, technology, risks, and applicable requirements change.

11. Vulnerability and Threat Management

MYCURE maintains processes designed to identify, assess, and respond to material security threats and vulnerabilities affecting systems under MYCURE's control.

Depending on the circumstances, activities may include:

  • vulnerability review;
  • dependency updates;
  • security patches;
  • configuration changes;
  • access restrictions;
  • monitoring;
  • investigation;
  • mitigation;
  • remediation; and
  • other appropriate protective measures.

No vulnerability-management process guarantees that every vulnerability will be identified before exploitation or that every security issue can be eliminated.

For Customer-controlled environments, Customers remain responsible for vulnerability, patch, configuration, and infrastructure-security management within their control unless otherwise expressly agreed in writing.

12. Subprocessors and Service Providers

MYCURE may engage third-party providers to help provide, operate, secure, maintain, support, or recover MYCURE CMS.

A provider is considered a Subprocessor of Customer Data only where it processes Customer Data on behalf of MYCURE in connection with the applicable service.

Not every software vendor, corporate service provider, website vendor, or technology used by MYCURE is therefore a Subprocessor of Customer Data.

Current material Subprocessors and processing locations are identified in our:

Subprocessor List
https://mycure.md/subprocessors

MYCURE requires Subprocessors processing Customer Data on its behalf to be subject to appropriate confidentiality, security, and data-protection obligations based on the nature of the processing and applicable law.

Customers may also select or control third-party integrations or infrastructure providers. A third party independently selected or controlled by a Customer does not become a MYCURE Subprocessor solely because MYCURE CMS communicates with or operates within that service.

13. Artificial Intelligence

MYCURE may introduce AI-assisted, machine-learning, automation, or similar functionality as MYCURE CMS evolves.

The use of AI functionality does not automatically mean that Customer Data is provided to an external artificial-intelligence provider.

Where a third-party AI or large-language-model provider will process Customer Data on MYCURE's behalf, MYCURE will address applicable contractual, Subprocessor, privacy, security, and authorization requirements before or in connection with that processing.

Current material external Subprocessors are identified in our Subprocessor List.

Development or productivity tools that do not receive production Customer Data do not become Subprocessors of Customer Data merely because they are used by MYCURE personnel.

14. Security Incident Response

MYCURE maintains procedures for assessing and responding to identified Security Incidents affecting systems under its control.

Depending on the incident, response activities may include:

  • investigation;
  • containment;
  • account or session restriction;
  • credential reset;
  • preservation of available relevant logs;
  • vulnerability remediation;
  • recovery;
  • communication with affected Customers; and
  • other appropriate response measures.

Where MYCURE becomes aware of a Security Incident affecting Customer Data, MYCURE will provide notice and cooperation as required by the applicable Customer agreement and applicable law.

Customers remain responsible for reporting incidents originating from Customer-controlled users, credentials, devices, networks, infrastructure, integrations, or other systems where required under the applicable agreement.

Each party remains responsible for legal or regulatory notification obligations imposed directly upon it.

Customers should promptly report suspected:

  • credential compromise;
  • unauthorized MYCURE CMS account access;
  • lost or compromised devices with access to MYCURE CMS;
  • circumvention of security controls; or
  • other security concerns affecting MYCURE CMS or Customer Data.

Reports should be sent to:

privacy@mycure.md

15. Privacy, Healthcare, and Regulatory Responsibilities

MYCURE CMS provides technology used by healthcare organizations in different jurisdictions and operational settings.

Privacy, healthcare, medical-record, professional, consumer-protection, security, telehealth, and other requirements vary by jurisdiction, Customer, and use case.

Customers remain responsible for determining the legal and regulatory requirements applicable to their organization and their use of MYCURE CMS.

Depending on the applicable relationship, additional contractual documentation may be required, such as:

  • Data Processing Agreements;
  • Security Agreements;
  • Business Associate Agreements;
  • Service Level Agreements;
  • jurisdiction-specific terms;
  • deployment-responsibility schedules; or
  • other written agreements.

MYCURE does not represent that MYCURE CMS is approved, certified, or legally suitable for every jurisdiction or regulated use merely because the service is technically available there.

16. Patient Data and Clinical Responsibility

MYCURE CMS is an information-technology system.

MYCURE is not a healthcare provider merely by providing MYCURE CMS and does not replace the independent professional judgment of licensed healthcare professionals.

Customers and their healthcare professionals remain responsible for matters such as:

  • clinical judgment;
  • diagnoses;
  • treatment decisions;
  • prescriptions and orders;
  • patient care;
  • accuracy and review of clinical information;
  • patient communications;
  • consent and authorization requirements;
  • medical-record obligations;
  • regulatory reporting; and
  • professional compliance.

Security controls provided by MYCURE support the service but do not transfer those clinical or professional responsibilities to MYCURE.

17. Enterprise Security and Compliance Reviews

Customers may request reasonable security and privacy information in connection with procurement, contracting, risk assessment, or regulatory review.

Depending on the Customer relationship, applicable agreement, sensitivity of the information, and nature of the request, MYCURE may provide or complete materials such as:

  • security questionnaires;
  • privacy and data-processing documentation;
  • security summaries;
  • deployment-responsibility information;
  • Subprocessor information;
  • incident-response information;
  • architecture information;
  • applicable contractual security terms; and
  • other reasonable documentary information.

MYCURE may first satisfy routine reviews through existing security documentation, questionnaires, written responses, policy summaries, or other appropriate evidence.

Certain information concerning MYCURE's infrastructure, security architecture, internal procedures, vulnerabilities, personnel, or other confidential systems may be restricted or subject to confidentiality protections.

Nothing in this Security Overview provides a right to penetration testing, vulnerability exploitation, source-code access, destructive testing, unrestricted infrastructure access, or access to information concerning other Customers.

Any audit or more extensive review remains subject to the applicable Customer agreement and applicable law.

18. Changes to Security Measures

MYCURE may modify, replace, upgrade, reconfigure, add, or discontinue security technologies, infrastructure components, software, tools, controls, and procedures as MYCURE CMS evolves.

Changes may be made in response to:

  • technology developments;
  • identified risks;
  • Service changes;
  • operational requirements;
  • security requirements;
  • availability requirements; or
  • legal and regulatory developments.

This Security Overview does not permanently commit MYCURE to a particular cloud provider, monitoring technology, database, security product, authentication technology, software library, or infrastructure architecture.

Where a change materially affects Customer Data processing and requires Customer notice, authorization, contractual changes, or another mechanism under applicable law or an applicable written agreement, MYCURE will follow that requirement.

19. Reporting Privacy or Security Concerns

Suspected security incidents, unauthorized access, credential compromise, privacy concerns, or other security or data-protection matters relating to MYCURE should be reported promptly to:

Privacy & Security Contact
privacy@mycure.md

Please do not send passwords, authentication factors, or unnecessary Patient Data through unsecured communications.