Security, Compliance & Certifications
Healthcare organisations trust MEG to manage critical quality, governance and patient safety processes. We support that trust through independently verified security certifications, internationally recognised quality standards, compliance attestations and government-approved supplier status.
Current Certifications & Attestations
MEG is a UK Government Commercial Agency (GCA - formerly know as the Crown Commercial Service) approved G-Cloud supplier on the latest framework (15) via the Public Procurement Gateway. MEG has the following certifications and attestations for the scope of: "The provision, ongoing support, development and maintenance of MEGβs Quality Management Software (QMS) platform for the Healthcare Industry."
ISO/IEC 27001:2022 - Information Security Management Systems
ISO/IEC 27017:2015 - Code of practice for information security controls for cloud services
ISO/IEC 27018:2019 - Code of practice for protection of personally identifiable information in public clouds
Cyber Essentials - UK Government-backed cybersecurity baseline
NHS DSPT - NHS Data Security and Protection Toolkit (Standards Exceeded)
SOC 2 Type II - System and Organization Controls 2, Type II (attested)
HIPAA - Health Insurance Portability and Accountability Act (aligned)
ISO 9001:2015 - Quality Management Systems
ISO/IEC 42001:2023 - Artificial Intelligence Management Systems
Quality, Data Protection, Information Security AND AI Governance
ISO/IEC 42001:2023
Artificial Intelligence Management Systems
Download >>
ISO 9001:2015
Quality Management Systems
Download >>
ISO/IEC 27001:2022
Information Security Management Systems
Download >>
NHS DSPT
NHS Data Security and Protection Toolkit
UK Digital Marketplace
Approved G-Cloud Supplier
HIPAA
Health Insurance Portability and Accountability Act
Cyber Essentials
UK Government-backed cybersecurity baseline
SOC 2 Type II
System and Organization Controls 2, Type II
Why Our Certifications AND ATTESTATIONS Matter
Selecting a healthcare software provider involves evaluating more than functionality. Organisations also need confidence that their technology partner operates with recognised standards for security, quality, privacy and governance.
MEG's certifications, attestations and approvals demonstrate our commitment to maintaining robust management systems, protecting customer information and continually improving the way we develop, deliver and support our healthcare quality management platform.
These credentials provide independent assurance that MEG has been assessed against internationally recognised standards within the defined scope of our Quality Management Software (QMS) platform.
