Merge Network is built to handle Protected Health Information (PHI) and privileged case data the way a legal and healthcare product actually should — with real access control, not just a privacy policy that says the right words.
Sharing on Merge Network is explicit, not default-open. A medical provider only ever sees the cases they've been assigned to — never a firm's full caseload, never another provider's patients. When a provider is removed from a case, their access is revoked immediately, not on the next data sync. This is enforced at the platform level, inside the data model itself, not just as an application-layer rule that a bug could bypass.
Access is granted per-case, per-party — not role-wide. Removing a provider from a case revokes their access to it instantly.
All accounts support MFA, enforced at login — not an optional setting buried in account preferences.
Data is encrypted both while moving between systems and while stored — the same standard used across Salesforce's platform.
Idle sessions expire automatically, reducing exposure from an unattended, logged-in device.
Every access and change to a record is logged — who viewed what, and when, is always traceable.
Merge Network runs natively on Salesforce's platform — backed by a signed Business Associate Agreement (BAA) with Salesforce covering the underlying infrastructure.
Merge Network is built HIPAA-compliant from the ground up — record-level access control, encryption, audit logging, and a signed BAA with Salesforce are the foundation, not an add-on. For firm- or provider-specific compliance questions (your own BAA, data residency requirements, retention policy, or current security documentation), our team addresses these directly on a discovery call so you get accurate, current answers for your specific situation rather than generic marketing copy.
Email: support@mergenetwork.com
Phone: (786) 630-7371