Skip to main content

Security and integrity

Assessment Integrity Requires Clear Rules, Reliable Records, and Human Review

MedicReady supports controlled access and structured evidence records while leaving assessment rules, event review, and final determinations with authorized department users.

Access follows the role and the assigned work.

Department administrators

Authorized operations users manage configured assessment content, candidates, publication, and department workflows.

Authorized evaluators

Reviewers access the attempts and evidence made available for their evaluation responsibilities.

Candidates

Candidates use department-issued access to enter their own assigned assessment experience.

Protected content and attempts

Assessment content and candidate-specific attempt records are kept within their intended workflows.

Configured assessments may collect an evidence record.

Depending on department configuration, an attempt may include typed responses, audio, video, transcripts, timing, module navigation, technical events, or integrity-related events.

  • Recording disclosure

    Candidates should receive notice before beginning whenever camera, microphone, or recording is required.

  • Technical expectations

    Instructions should identify device, room, browser-permission, and support expectations.

  • Prohibited assistance

    Departments define rules for notes, other people, additional devices, navigation, and outside assistance.

  • Consent and consequences

    The department should explain applicable consent and what may happen if assessment rules are not followed.

An integrity event is a review signal, not an automatic finding.

MedicReady may identify and record potential assessment-integrity events based on rules approved by the administering department. Depending on configuration, a candidate may receive a warning, the event may be flagged, or the assessment may be discontinued. Authorized department reviewers remain responsible for the final determination.

Use fictional or properly de-identified patient information.

Departments should not upload real patient records or protected health information unless an authorized MedicReady agreement and configuration explicitly supports that use.