HIPAA • GDPR • CPRA Compliance

Medical Cookie Governance & Tracking Policy

Last Updated: August 2026 • Explains how Medstufise uses strictly essential, functional, and performance cookies to power accredited medical education without capturing Protected Health Information (PHI).

1. Clinical Purpose of Cookies

Medstufise Inc. operates an accredited continuing medical education platform. We utilize cookies and browser storage mechanisms solely to authenticate healthcare providers, deliver secure 4K clinical video streams, track completed credit hours for state medical boards, and preserve student quiz progress.

Under no circumstances do our educational cookies cross-track clinicians across unrelated consumer websites for behavioral advertising.

πŸ›‘οΈ

3. Zero Protected Health Information (PHI) Guarantee

In accordance with the Health Insurance Portability and Accountability Act (HIPAA), Medstufise ensures that all patient case studies and simulated medical scenarios are completely de-identified in strict adherence to the Safe Harbor method (45 CFR Β§ 164.514). No client cookies contain, track, or transmit Protected Health Information.

4. Authorized Third-Party Sub-Processors

We only deploy third-party cookies from accredited infrastructure providers who maintain active Business Associate Agreements (BAAs) and SOC 2 Type II certifications:

  • Cloudflare Inc.: DDoS mitigation, bot detection, and edge routing.
  • Stripe Payments: PCI-DSS Tier 1 encrypted billing and tax invoicing.
  • Zoom Video Communications: Encrypted WebRTC broadcasting for live Grand Rounds.
βœ“
Review Submitted Successfully! Thank you for contributing to the Medstuffies clinical community.