MedSystum processes 835/ERA remittance data that contains protected health information. We treat it accordingly — a signed BAA before any PHI moves, encryption end to end, and an AI layer that never sees a patient identifier.
We sign a Business Associate Agreement before any protected health information is transmitted.
TLS everywhere, encrypted storage, and sensitive credentials additionally encrypted at the application layer.
AI sees claim numbers, procedure codes, and dollar amounts — never names, dates of birth, SSNs, or member IDs.
Role-based access with least-privilege roles; one organization can never read another organization's data.
AI drafts explanations and appeal letters for your team to review. Nothing is submitted to a payer automatically.
The dollar findings are computed by a rule-based engine, not a language model — reproducible line by line.
We are transparent about what is in place now and what is on the roadmap. Prospective customers can request current status and documentation during evaluation.
Encryption, access control, HIPAA/BAA, logging, and incident response.
How we use AI safely — no patient data to models, human review, no upcoding.
How long we keep data, and how it is returned or destroyed.
How we collect, use, disclose, and protect information and PHI.
The terms that govern your use of MedSystum.
Your choices about the sale or sharing of personal information.
We'll share our security overview and a Business Associate Agreement so your compliance team can review before any data moves.
Talk to us about security