Security Overview
Last updated: August 2026
Your payer rates, denial patterns, and revenue picture are competitively sensitive even with every patient identifier removed. This page answers the questions a practice administrator or IT reviewer should ask any vendor: where the data lives, who can see it, how long we keep it, and what happens if something goes wrong.
The Short Version
Most vendors protect sensitive data with controls after they collect it. Our first control is not collecting it. Patient identifiers are scrubbed in your browser before anything is uploaded, and the format that reaches our servers is a fixed set of billing columns: there is no field in it that can hold a patient name, date of birth, address, or ZIP code. What we do receive is encrypted in transit and at rest, the working report files delete themselves after 24 hours, and day-to-day access to production systems is limited to one person.
What This Page Covers
- What leaves your browser, and what never does
- What we store, and for how long
- Encryption and hosting
- Who can access your data
- Subprocessors
- If something goes wrong
- A straight answer on SOC 2
Questions
Security questionnaires and reviewer questions: hello@medvient.com