A healthcare-first baseline for partners who integrate, deliver, or co-market with MDS - designed to protect patient trust and operational quality.
Partnership Standards are MDS' documented expectations for security, privacy, delivery quality, and claims discipline when working together. They are not certification, accreditation, or medical endorsement.
Governed onboarding. No PHI required at this stage.
These standards exist to ensure partners can operate safely in healthcare, integrate cleanly into growth systems, and communicate responsibly.
role clarity, no medical advice, and governed escalation pathways.
least-privilege access, auditability, and DPA readiness where applicable.
stable APIs, documented integrations, and change control.
SLAs (as scoped), QA processes, support pathways, and handover assets.
approved language, compliant proof usage, and co-marketing governance.
The exact scope will vary by partner category, but these are the non-negotiables we expect before we co-deliver or connect systems.
named owner, implementation SOPs, escalation path, and change approval process.
secure-by-default architecture, access controls, secrets management, and vulnerability management practices.
data minimization, retention policy alignment, and contractual readiness (e.g., DPA) when handling patient or lead data.
API documentation, versioning/change notices, sandbox/testing approach, and rollback plan where relevant.
delivery plan, QA checklist, support model, and handover artifacts for client teams.
measurable outcomes, event taxonomy alignment, and attribution-friendly data handling (as scoped).
compliant claims discipline, approved proof usage, and brand asset governance.
When a partner connects into a healthcare growth system, the priority is safe data handling and predictable operations.
access only what is required for the scoped workflow.
logs for critical actions (auth, data access, configuration changes) where applicable.
capture only required fields; avoid PHI unless explicitly contracted and governed.
encryption in transit; encryption at rest where applicable; key management per best practice.
versioned APIs/integrations; advance notice for breaking changes; rollback path.
defined response path, contact points, and communication expectations per contract.
Healthcare audiences require precision. We only publish proof that is validated and approved.
If you can deliver safely in healthcare and align to a clear operating standard, we will route you to the right track.