Compliance

Built forregulated healthcare.

HIPAA-ready by design and built around the FDA Medical Device Data System classification. Business Associate terms are available for enterprise deployments, scoped to every plane of the platform.

What is a Medical Device Data System?

MDDS is an FDA regulatory classification for hardware or software that transfers, stores, converts formats, and displays medical device data. It covers the full lifecycle of healthcare data movement, from the point of capture to the point of clinical use.

Under the 21st Century Cures Act, Congress clarified that under the FDA MDDS classification, pure MDDS software functions are not considered medical devices and are not subject to FDA enforcement. This means software that only transfers, stores, converts, or displays medical device data, without modifying its clinical meaning, falls outside the scope of FDA device regulation.

HIPAA compliance features.

Designed from the ground up for environments that handle protected health information. View our HIPAA Notice, or see the security architecture for technical controls. If your board needs our controls and policies in writing, ask us and we will send them.

Encryption in Transit

All peer connections secured with WebRTC DTLS encryption. Data is end-to-end encrypted; even when relayed through TURN infrastructure, we cannot read your data.

Security architecture

Encryption at Rest

Your data stays on your infrastructure, encrypted by your systems. OpenShare never stores protected health information; your integration engine and database remain in your data center.

Access Controls

Console access is governed by OpenShare single sign-on with role-based access control; your engine’s own Mirth/OIE user accounts continue to govern access on the server itself.

Audit Logging

All connection lifecycle events and administrative actions are logged. Maintain the audit trail your compliance program requires.

Business Associate Agreements

For enterprise deployments, a platform-wide BAA is available, scoped to the control plane (Console/admin), data plane (Gateway/Exchange tunnels), and TURN relay fallback. To discuss terms, contact sales@openshare.health or use our contact form. Not legal advice.

Breach Notification

Processes in place per the HIPAA Breach Notification Rule. Timely notification procedures for covered entities and business associates.

Business Associate Agreements.

Available for enterprise deployments: one platform-wide agreement, scoped per infrastructure plane. Not legal advice, consult your compliance counsel.

Control Plane

Console & Admin

The OpenShare Console (browser-based admin interface) and administrative APIs. Your team's access to integration engine management is covered under the BAA.

Data Plane

Gateway & Exchange Tunnels

End-to-end encrypted WebRTC tunnels used by the Gateway Plugin for direct data exchange. Data is encrypted in transit, OpenShare cannot read it.

Relay Fallback

TURN Relay

When a direct connection is blocked, traffic is relayed through OpenShare TURN infrastructure, but remains end-to-end encrypted. Even relayed ePHI is unreadable by OpenShare.

HIPAA Security Rule controls

Administrative safeguards (BAA execution, workforce security), physical safeguards (data center controls), and technical safeguards (audit controls, RBAC access control, encryption in transit via WebRTC DTLS). At-rest encryption is handled by your own infrastructure.

Breach-notification safe harbor

Under HHS guidance, properly encrypted ePHI is generally not treated as a reportable breach under the encryption safe harbor (45 CFR §164.402). OpenShare's E2E-encrypted architecture is designed so that even worst-case relay interception leaves data unreadable, the scenario the safe harbor addresses. Confirm applicability with your compliance counsel.

Ready to execute a BAA? Contact our team directly.

Your compliance checklist.

Healthcare compliance is a shared responsibility. Here’s how HIPAA’s Technical, Administrative, and Physical Safeguards map to our architecture.

OpenShare covers

  • Encrypted transit via WebRTC DTLS (Technical Safeguard §164.312(e))
  • Signaling server security
  • BAA execution (Administrative Safeguard §164.308(b))
  • Connection and access event logging (Technical Safeguard §164.312(b))
  • Platform security updates and patching

Your responsibility

  • Integration engine security configuration
  • Database encryption at rest
  • Network firewall configuration
  • User credential management
  • HIPAA policies and procedures

Frequently asked questions

MDDS is an FDA regulatory classification for hardware or software that transfers, stores, converts formats, and displays medical device data. Under the 21st Century Cures Act, pure MDDS software functions are not considered medical devices and are not subject to FDA enforcement. OpenShare aligns with the MDDS classification, software that transfers, stores, converts, and displays healthcare data without modifying its clinical meaning falls outside FDA device regulation.

For enterprise deployments, Business Associate terms are available, scoped to the control plane (Console/admin), data plane (Gateway/Exchange E2E-encrypted tunnels), and TURN relay fallback. Even when ePHI transits the TURN relay, it is end-to-end encrypted and OpenShare cannot read it. Contact sales@openshare.health.

No PHI is stored by OpenShare. In direct connection mode, OpenShare acts as a signaling-only server and data flows directly between organizations. In TURN relay fallback mode, data transits OpenShare infrastructure but remains end-to-end encrypted (WebRTC DTLS), OpenShare cannot read it. PHI stays on your infrastructure.

OpenShare is designed for HIPAA compliance and implements HIPAA Security Rule controls: administrative safeguards (BAA execution, access management) and technical safeguards (audit logging, RBAC access control, WebRTC DTLS encryption in transit). Encryption of data at rest is handled by your own infrastructure, under your control, and OpenShare stores no PHI. The E2E-encrypted architecture is also designed to support the breach-notification encryption safe harbor under 45 CFR §164.402.

No, and it does not need to be. OpenShare performs pure MDDS functions: transferring, storing, converting, and displaying healthcare data without modifying its clinical meaning. Under the 21st Century Cures Act those functions are explicitly excluded from the FDA medical device definition, so they are not subject to FDA enforcement or device registration. OpenShare's architecture aligns with that classification; alignment is not an FDA registration, and none is required.

ePHI moving through OpenShare is encrypted end-to-end (WebRTC DTLS), including in TURN relay fallback. Under 45 CFR §164.402, ePHI that is properly encrypted per HHS guidance is generally not treated as a reportable breach, because the data remains unreadable and unusable to an unauthorized party. That encryption safe harbor can significantly reduce your breach-notification exposure. Confirm applicability with your compliance counsel.

Questions about compliance?

Email sales@openshare.health or use our contact form and we’ll walk you through the architecture and available terms.