MediSynth Open console
Trust

Compliance & data scope

MediSynth generates synthetic patient cohorts. The data we produce is synthetic by construction and contains no real protected health information (PHI) or personal information about real people. This page explains what that means for your compliance scope, and what we do and do not claim.

Data scope

Synthetic by construction, not de-identified.

Every cohort is generated from deterministic, seeded models. It is not sampled, masked, or de-identified from real patient records, so there is no underlying real person to re-identify. Identifiers, contact details, and clinical values are minted from reserved, non-routable, fictional ranges rather than drawn from any real registry or source system.

Synthetic data & HIPAA scope

Synthetic data generally falls outside HIPAA's BAA requirements.

HIPAA obligations, including Business Associate Agreements (BAAs), generally attach to protected health information. Because MediSynth generates only synthetic data and does not receive, create, or process your patients' real PHI, a BAA is generally not required for its intended use — but your own compliance team should confirm what your organization's policies and regulators require for your specific use case. MediSynth is not designed or intended to receive real PHI; do not upload real patient data to the service.

Signed attestation

Every cohort ships a signed PHI-free attestation.

Each generated cohort includes a machine-readable attestation (attestation.json) and a detached Ed25519 signature (attestation.sig). The attestation records the statement that the artifact set is fully synthetic and contains no real PHI, the generator version, the deterministic seed, and a SHA-256 digest of every file in the artifact set. You can verify the signature against the public key embedded in the attestation, so the guarantee is independently checkable rather than something you have to take on trust.

Structural PHI-freedom checks

Guarantees enforced at generation time.

The attestation lists the structural checks the generator enforces so that synthetic records cannot address or reference real people:

  • Provider and facility NPIs are generated from prefix blocks MediSynth sets aside for synthetic data (the 177, 188, 198, and 199 ranges); they are not checked against, and should not be assumed absent from, the real NPI registry.
  • Email and endpoint hostnames use RFC 2606 / RFC 6761 example domains and cannot address real recipients.
  • Telephone numbers use the reserved 555-0100 through 555-0199 fictional range.
  • MRNs and other identifiers are minted from deterministic synthetic namespaces and are not sampled from source registries.
  • Dates of birth are generated from the deterministic cohort model and are never linked to real persons.
What we do not claim

Honest scope: no certifications claimed.

MediSynth does not claim SOC 2, HIPAA, ISO 27001, or HITRUST certification, and this page should not be read as an assertion of any audit or certification status. Our compliance position rests on a simple, verifiable fact: the data we generate is synthetic and contains no real PHI. We operate the platform with industry-standard security practices, including encryption in transit and access controls, as described in our Privacy Policy.

Your responsibilities

Use synthetic data for its intended purpose.

MediSynth is built for development, testing, demos, QA, migrations, and integration work. Synthetic cohorts are not real patients and must not be used for clinical care, real-world treatment decisions, or as a substitute for real medical records. Keep real PHI out of the service.

Questions

Talk to us about scope.

For questions about data scope, the attestation, or how MediSynth fits your compliance review, contact us at support@cloud.medisynth.io.