HIPAA SECURITY SAFEGUARDS

Security Architecture & Controls

How Remedy protects Explanation of Benefits and hospital billing records with field-level encryption.

ENCRYPTION PROTOCOLS

AES-256 & TLS 1.3

All medical claim data, EOB PDFs, and line-item audits are encrypted at rest using AES-256 and transmitted securely using modern TLS 1.3.

TENANT ISOLATION

Database Access Rules

Claim records are strictly restricted to authenticated user sessions. Multi-tenant partitioning prevents unauthorized cross-account visibility.

1. Technical & Administrative Safeguards

Medical Claim Manager implements technical safeguards aligned with healthcare security standards:

  • Strict Authentication: Tenant-bound token authorization on all cloud functions and database reads/writes.
  • Bounded Session Timeouts: Automatic credential expiration and refresh rotation.
  • Content Security Policy: Strict browser CSP, preventing cross-site scripting (XSS), framing/clickjacking, and unauthorized third-party scripts.

2. SOC 2 Compliant Cloud Infrastructure

All servers, databases, and backup systems reside in SOC 2 Type II and ISO 27001 certified Google Cloud Platform facilities located in the United States.

3. Vulnerability Disclosure

To report a vulnerability or inquire about security architecture, contact our security team at security@medicalclaimmanager.com.