Last Updated: September 24, 2026
MedSystum ("Company," "we," "us," or "our"), processes sensitive healthcare payment data, including Protected Health Information ("PHI") contained in the 835/ERA remittance files you submit. This page summarizes the technical and organizational safeguards we use to protect that data.
Note: This page is provided for the initial release of the marketing website and describes our target security posture. It does not constitute a warranty or legal advice and will be updated as controls are formalized and independently assessed.
We act as a Business Associate with respect to PHI in your Remittance Data. We enter into a Business Associate Agreement ("BAA") with you before you transmit any PHI. We use PHI solely to provide the Service and apply the minimum-necessary principle to every access and transmission.
The Service is multi-tenant. Every record is scoped to the organization that owns it, and access is enforced so that one organization cannot read another organization's data, reports, or configuration.
Certain optional features generate plain-English explanations and draft appeal letters using third-party AI providers. Where such providers process data on our behalf, they do so under agreements — including BAAs where applicable — and through endpoints configured for zero or limited data retention. Requests to these providers exclude patient names, dates of birth, Social Security numbers, and member IDs; claim-level references (claim control numbers, procedure codes, and dollar amounts) may be included, and are only ever sent through the retention-limited or BAA-covered endpoints described above. See our Responsible AI page for details.
The Service relies on the following subprocessors:
We will update this list before adding a subprocessor that handles PHI.
The Service is hosted on HIPAA-eligible cloud infrastructure. We rely on the provider's physical security, network isolation, and availability controls, and configure our environment to limit network exposure.
We maintain audit logging of significant system and data-access events, including access to PHI, to support security review and our regulatory obligations. We monitor for anomalous activity and errors.
We track dependencies for known vulnerabilities, apply security updates on a timely basis, and intend to engage independent third parties for periodic penetration testing.
We maintain an incident-response process. In the event of a security incident involving PHI, we will investigate, remediate, and provide notifications in accordance with our BAAs, HIPAA, and applicable law.
We retain data only as long as necessary to provide the Service and meet our obligations, and we return or destroy PHI on termination as described in our Data Retention Policy and the applicable BAA.
We are building toward recognized third-party assurance (such as SOC 2 and HITRUST). Status updates will be provided to prospective customers upon request.
If you believe you have found a security vulnerability, please contact us at security@medsystum.com. We appreciate responsible disclosure and will work with you to validate and remediate reported issues.