Get started

Security & compliance

How we protect patient information

Billing means handling patient information, so we build around the HIPAA Security Rule and Medicare and Medicaid billing rules. This page says what we do, and what remains with your practice.

Compliance at a glance

The rules we build around

Each rule below, and how our platform and our agreements address it.

HIPAA Security Rule

Administrative, physical and technical safeguards for electronic patient information.

  • Encryption, individual accounts, two-step sign-in, role-based access, automatic sign-out
  • Tamper-proof audit log and tested backups
  • Data center physical safeguards provided by Microsoft Azure

HIPAA Privacy Rule

Limits on how patient information is used and who may receive it.

  • A business associate agreement with every practice and every vendor that handles patient data
  • Minimum necessary: only what billing needs

Breach Notification Rule

What happens if patient information is exposed.

  • A written incident response plan
  • We notify the practice as our agreement requires

Medicare & Medicaid billing rules

Accurate claims, filed on time, billed to the right party.

  • No automatic code changes; a provider approves every claim
  • Filing deadlines tracked; dual-eligible patients protected from cost sharing

HHS guidance on website tracking

Online trackers can expose visitor information.

  • This website uses no cookies, analytics or third-party scripts

These describe how our platform and agreements are built around each rule. They aren't certifications, and each practice keeps its own responsibilities, listed below.

A note on certification. There is no official HIPAA certification, so we don't claim one. Meeting the rules is a combination of safeguards, agreements and a practice's own policies. Here is each part, plainly.

Agreements that cover patient data

  • A business associate agreement (BAA) with every practice we serve.
  • BAAs with the vendors that handle patient data for us, including Microsoft for hosting. We don't send real patient data through a service until its BAA is in place.
  • Patient data is processed in the United States.

How patient information is protected

  • Encryption: data is encrypted in transit and at rest. The most sensitive fields, like insurance member IDs, get an extra layer of encryption with keys held in a dedicated key vault.
  • A dedicated environment: patient data lives in its own secure Microsoft Azure environment, separate from our other systems, with the database reachable only through the platform.
  • Individual accounts: everyone signs in as themselves, with Microsoft, Google or a password, then enters a one-time code we email them. A trusted device can be remembered for 30 days, and people on shared computers can choose not to. No shared logins.
  • Access by role: billers, providers and administrators see and do only what their job needs. Screens show insurance member IDs as the last four digits.
  • Automatic sign-out after 15 minutes of inactivity.
  • Minimum necessary: we bring in what billing needs, such as demographics, insurance, visits and diagnoses. We don't import clinical notes or Social Security numbers.

A record of everything

  • Every view of a patient or claim, and every change, is logged with who and when. The database refuses edits and deletions of the log, so it stays trustworthy.
  • Claim history keeps old and new versions of anything that changes.
  • Logs are kept for at least six years.

If something goes wrong

  • Daily backups, restorable to any point in the last 35 days, with a copy in a second US region. We test restores.
  • A written incident response plan, and we notify the practice of a security incident as our agreement requires.

Billing accuracy

  • The platform never changes a diagnosis or procedure code on its own. A provider approves every claim before it is sent.
  • Claims are checked before they go out, and code combinations that payers won't pay together are stopped.
  • Patients covered by both Medicare and Medicaid aren't billed for cost sharing they don't owe, and filing deadlines are tracked on every claim.
  • Automatic fixes are limited to correcting data from your own records, with a cap on retries so nothing loops. After that, a person reviews it.

The AI assistant

  • It runs in the same secure Microsoft Azure environment, under Microsoft's business associate agreement, not on a public chatbot.
  • It answers from your records, prepares changes for you to confirm, and never chooses or changes billing codes.
  • Every question it handles is logged.

This website

No cookies, analytics, advertising pixels or third-party scripts. See our privacy page.

What stays with your practice

HIPAA also asks each practice to keep its own written policies, train its staff, name a privacy and security officer and complete its own risk analysis. We build the platform to support those, and we're happy to walk you through how. They remain your practice's responsibility.

Questions about security or compliance? Talk to us. This page describes how our platform works and isn't legal advice.