Meridian · Operations Platform

Compliance Overview

How Meridian protects healthcare data while automating middle-office operations across a private-equity portfolio.

Business-level summary · Technical documentation available to authorized reviewers

Meridian · Healthcare Operations Platform
Version 1.1 · October 2026

What Meridian does

Meridian is an AI-powered operations platform for healthcare businesses. Its software agents prepare administrative work — billing and revenue-cycle follow-up, clinical documentation drafts, scheduling, intake, and reporting — and every action that would touch a business's systems or its people is first reviewed and approved by a human.

The platform runs entirely on Microsoft Azure's managed, HIPAA-eligible cloud services, the same infrastructure foundation trusted by major health systems, and is deployed separately for each business so that no two businesses' data ever mixes.

Security & privacy — the plain-language answers

QuestionAnswer
Who can see patient data?Only approved users of that specific business. Sign-in uses Microsoft Entra ID with multi-factor authentication, and each business's records are isolated from every other business on the platform.
Can the AI act on its own?No. Meridian is 100% human-in-the-loop. Every agent action requires a person to approve it first — in the Meridian approval queue or a Microsoft Teams approval card — before anything is sent, changed, or billed.
Is data encrypted?Yes — in transit (TLS 1.2+) and at rest with double encryption (AES-256 plus a second infrastructure-encryption layer). Data is replicated to a second Azure region for durability, and all platform access to storage uses managed identities — no shared access keys exist anywhere in the platform. Each business's data is additionally protected by its own encryption keys, rotated on a regular schedule.
Does the AI provider keep or learn from our data?No. Language-model calls run under a zero-data-retention configuration: prompts and responses are not stored or used to train AI models by the provider. Meridian also sends the minimum information necessary.
Is there a record of everything?Yes. A tamper-evident audit log records every recommendation, approval, rejection, and executed action, with timestamps and user attribution.
What happens if something goes wrong?There is a documented incident-response and HIPAA breach-notification runbook, with defined containment steps, a formal four-factor breach risk assessment, and statutory notification timelines.
Is there a signed BAA?Yes. A Business Associate Agreement is executed with Microsoft (the cloud provider), and Meridian signs BAAs with its portfolio companies as part of onboarding.

Compliance control domains

DomainHow Meridian addresses it
Identity & access controlMicrosoft Entra ID single sign-on, multi-factor authentication, role-based access (portfolio / business / read-only), unique user identification per HIPAA §164.312(a)(2)(i).
Human oversightEvery consequential agent action passes through a human approval gate before execution — a design-level control, not a policy.
Encryption & tenant isolationAES-256 at rest with a second infrastructure-encryption layer, geo-redundant replication, TLS 1.2+ in transit, per-business encryption keys, cryptographic separation between businesses, and keyless managed-identity storage access.
Data minimization & AI governanceZero-data-retention AI provider configuration, prompt minimization, and an audited AI gateway for all model calls.
Audit & accountabilityCentralized logging of all agent activity, approvals, and administrative actions with retention and export for compliance review.
Continuity & backupGeo-redundant storage replicated to a paired Azure region, database point-in-time restore (30 days), and full infrastructure-as-code enabling complete environment reconstruction — a documented disaster-recovery posture, not just backups.
Network securityPrivate-network-first architecture: services are isolated from the public internet wherever technically supported, with documented exceptions and remediation plans tracked in the risk register.
Risk managementAnnual HIPAA §164.308(a)(1)(ii)(A) risk analysis with a maintained risk register and scheduled reviews.
Incident responseDocumented runbook covering detection, containment, HIPAA breach risk assessment, and 60-day notification workflows.

The full documentation set

Compliance officers, IT security teams, and diligence reviewers can receive the complete technical Trust Pack — platform architecture, security and network design, LLM data-handling analysis, a control-by-control HIPAA safeguards mapping, risk register, BAA framework, incident-response plan, and a pre-filled security questionnaire.

Signed-in Meridian administrators: read the full documentation at the full Trust Pack page (requires sign-in).

Everyone else: request it from your Meridian account team during diligence — it is shared under NDA.