MedSystum
Trust & Compliance

Built for the data you can't afford to leak.

MedSystum processes 835/ERA remittance data that contains protected health information. We treat it accordingly — a signed BAA before any PHI moves, encryption end to end, and an AI layer that never sees a patient identifier.

How we protect your data

Compliance is the product, not a footnote

BAA signed first

We sign a Business Associate Agreement before any protected health information is transmitted.

Encrypted in transit & at rest

TLS everywhere, encrypted storage, and sensitive credentials additionally encrypted at the application layer.

Minimum-necessary AI inputs

AI sees claim numbers, procedure codes, and dollar amounts — never names, dates of birth, SSNs, or member IDs.

Least privilege & tenant isolation

Role-based access with least-privilege roles; one organization can never read another organization's data.

Human-reviewed AI

AI drafts explanations and appeal letters for your team to review. Nothing is submitted to a payer automatically.

Deterministic & auditable

The dollar findings are computed by a rule-based engine, not a language model — reproducible line by line.

Compliance status

Where we stand today

We are transparent about what is in place now and what is on the roadmap. Prospective customers can request current status and documentation during evaluation.

HIPAAAligned
Business Associate AgreementAvailable
SOC 2 Type IIIn progress
HITRUSTPlanned
Policies

Read the details

Evaluating MedSystum for your organization?

We'll share our security overview and a Business Associate Agreement so your compliance team can review before any data moves.

Talk to us about security