MedLegal Vault

Medical records, managed correctly.

A records-request platform for personal injury firms and the clinics that serve them. Every request tracked, every authorization on file, every action audited — with a trail that holds up in court.

Compliance
HIPAA · HITECH
Encryption
AES-256 · TLS 1.3
Jurisdictions
NJ · NY
Doe v. Acme Transit Co.
Cases · Open · Miami-Dade
ExportNew request
Requests · 6 of 6
Opened Apr 03 · MM/DD/YYYY
ProviderSentStatusAgeFee
Jackson Memorial Hospital
HIM · Fax 305-585-6789
Apr 03Received17d$124.00
Miami Orthopaedic Group
Portal · MyChart
Apr 03Received9d$48.00
Coral Gables Imaging
Fax · 305-442-1104
Apr 05Follow-up14d
Vargas Chiropractic
Direct · Clinic
Apr 05Received4d$26.00
Mount Sinai Pain Mgmt.
Mail · Records Dept.
Apr 07Overdue24d
Dr. L. Okafor, M.D.
Fax · 305-390-2277
Apr 07Sent12d
Product

Built around the records workflow. No more, no less.

Designed for the paralegal running eighty cases and the clinic office manager fielding the faxes those cases generate. Simple enough to learn in a morning.

Request tracking

Every records request — firm-submitted or clinic-logged — captured with the patient, requester, authorization, and status in one place.

Clinic log

Clinics log incoming fax and mail requests, mark authorizations as received, and record records sent with pages and fees.

Authorization workflow

Upload the signed HIPAA release, match it to the request, enforce its presence before records are released.

Structured summary

When records are complete, a seven-part brief — overview, injury, treatment, findings, billing, red flags, strength — compiled for partner review.

Append-only audit

Every action, every actor, every timestamp — recorded permanently at the database layer. Never modified, never deleted.

Role-based access

Owners, admins, staff, attorneys, paralegals — each sees what their role requires, nothing more. Scoped per organization.

How it works

From intake to delivery, in one workflow.

Each step produces a dated artifact the next step depends on. Nothing is reconstructed from memory.

The demand-letter-ready summary, prepared as records arrive.

When the final request is fulfilled, the system compiles a structured brief the attorney can review in fifteen minutes — organized exactly as a demand letter is.

Seven conventional sections

Overview, injury, treatment timeline, diagnostic findings, billing, red flags, strength.

Provenance on every claim

Each statement cites the document and page it was drawn from.

Editable before it leaves the firm

Nothing exports without a human sign-off on the review screen.

Summary · Doe v. Acme Transit Co.
Draft · v3
Overview
34-year-old female, rear-end collision, Oct 03 2025. Conscious on scene; transported to Jackson Memorial.
Injury
Herniation at L4–L5. Cervical paraspinal strain. Contusion, left shoulder.
Treatment
Six weeks physical therapy. Two orthopedic consultations. Ongoing chiropractic care.
Findings
MRI positive for herniation. X-ray negative for fracture.
Billing
$48,312.04 unpaid, in collection.
Red flags
Four-day gap, weeks III–IV. Pre-existing note, 2019.
Assessment
Workable. Recommend demand at completion of current course of care.
01

Open the matter

Patient, requester, jurisdiction — one canonical record.

02

Log the request

Firm submits, or clinic logs an incoming fax or mail.

03

Track to close

Authorization received, records sent, fees reconciled.

04

Deliver the brief

Seven-part summary, reviewed and exported.

Security & compliance

Built to the standard your compliance officer will ask about.

Everything PHI-adjacent is encrypted, logged, scoped, and available for audit.

HIPAA & HITECH

Administrative, physical, and technical safeguards. BAAs with every sub-processor.

Encryption at rest

AES-256 at the storage layer. Key material isolated from the application database.

Field-level PHI encryption

Patient identifiers encrypted with authenticated AES-GCM before they hit the database row.

TLS 1.3 in transit

Modern ciphers only. HSTS. HttpOnly cookie authentication — no client-side token handling.

Append-only audit

Every PHI-touching write logged with actor, timestamp, and before/after state. Enforced at the database.

Multi-tenant isolation

Tenant scoping enforced at the query layer, verified by automated tests on every model.

Overview

See MedLegal Vault end-to-end, in two minutes.

From logging a request to delivering the summary brief. Coming as soon as every feature shown is final.

Video placeholderApprox. 2:00
Product overview, coming soon.