Skip to main content
The claims you send us contain protected health information (PHI). This Trust Center describes how we handle it: what we do, as it’s built today. It doesn’t list certifications; we haven’t been audited for any.

Security

Encryption, access control, audit logs and how we build.

Privacy and your data

The business associate agreement, retention, deletion and export.

Subprocessors

The services we run on, and what each one handles.

Contact

Report a security concern or ask a question.

In short

  • No patient data before a signed business associate agreement. Every way in for a practice stays closed until its BAA is signed.
  • Encrypted in transit and in the database. HTTPS everywhere, and sensitive fields encrypted by the application before they’re stored.
  • Least access. Practice roles, two-step verification, passkeys and single sign-on; every request is checked against who may see what.
  • Logged. Access to patient data is written to an audit log we keep for six years.
  • Patients stay in control. A patient’s details show only after they confirm their date of birth, and they can revoke their authorization any time.