Trust architecture
Built for healthcare data from the first table.
MEDBIX is designed for PHI workloads in production — and this page says exactly what that means, and what we don't claim. Each billing company is a tenant; PostgreSQL row-level security enforces the boundary inside the database, not only in the interface. Admin, Supervisor, Biller and Accountant roles scope access, with billers limited to the practices they work. Claims need a named person's approval before submission, and every tenant write leaves an immutable audit trail with a person and a timestamp. Demos on this site use synthetic data; card details stay with Stripe; we do not claim "HIPAA certified" or "SOC 2 certified" here. Ask for our current compliance documentation and we'll share where things stand, clearly labelled.
Isolation
Five layers between a claim and a leak.
When a practice asks who else can see their data, the answer is short — and each layer is something you can explain.
Northside Billing Co.
tenant · 12 staff
Lakeview Ortho
patients · claims · statements
Bayside Derm
patients · claims · statements
Cedar Family Med
patients · claims · statements
- 01
Database isolation
Each billing company is a tenant. PostgreSQL row-level security enforces the boundary inside the database, not only in the interface.
- 02
Application scoping
Admin, Supervisor, Biller and Accountant roles, with billers scoped to the practices they work. Every request carries that scope.
- 03
Named human approval
No AI output finalizes money or coding. Claims need a person's approval before submission, recorded with a timestamp.
- 04
Immutable audit trail
Every tenant write and every approval is recorded with a person and a timestamp, and can't be edited after the fact.
- 05
Credential handling
Clearinghouse and integration credentials follow encrypted secret-handling patterns; JWT sign-in with optional two-factor.
Audit log · immutable
- 10:42 T. Brooks approved CLM-24-08809
- 10:38 Denial agent proposed patch on CLM-24-07655
- 10:39 K. Ahmed applied proposal to draft
- 10:21 T. Brooks returned CLM-24-08790 to draft: "wrong rendering NPI"
- 09:58 L. Ortiz posted ERA #8841 · $4,112.60
Traceability
An audit log nobody can rewrite.
Approvals, returns, postings, rule changes and AI proposals all leave a trace. That's what auditors, payers and clients ask for.
Access
Four roles, practice-scoped.
Access follows the roles your admin assigns. See how each role works day to day on the solutions pages.
Admin console · users & practices
| User | Role | Practices | 2FA |
|---|---|---|---|
| T. Brooks | Supervisor | All | |
| K. Ahmed | Biller | Lakeview, Bayside | |
| L. Ortiz | Accountant | All (finance) | off |
| P. Singh | Admin | All |
Handling
Data handling principles
- Synthetic data only in demos and on this website
- Billing-relevant data only — no clinical charts
- Card details handled by Stripe, never stored by MEDBIX
- SMS opt-outs honored automatically
- Cross-company data use switched off without legal consent
About certifications
Your obligations still matter
Isolation
Walls that hold when a client asks who can see their data.
Each billing company is a tenant. PostgreSQL row-level security enforces the boundary inside the database — not only in the UI.
- RLS on every tenant table
- Practice scoping for billers
- No cross-company leakage by design

Audit
An audit log nobody can rewrite.
Approvals, returns, postings, rule changes and AI proposals leave a named, timestamped trace. That's what auditors and clients ask for.
- Immutable write history
- Person + timestamp on approvals
- Exportable for reviews

Access
Four roles that match real job titles.
Admin, Supervisor, Biller, Accountant — with optional two-factor and encrypted handling of clearinghouse credentials.
- Least-privilege by default
- Optional 2FA in settings
- Secrets never stored in plain text


Honesty
Compliance language without marketing stretch.
We share readiness documentation and walk BAAs with you. We don't claim vague 'HIPAA certified' slogans on the marketing site.
- Ask for current documentation
- Your staff policies still matter
- Synthetic data only on this website
Common questions
Where is data stored?
MEDBIX runs on PostgreSQL with row-level security. We'll confirm hosting region and details for your account during onboarding.
Do you sign a BAA?
Talk to us about your Business Associate Agreement requirements; we'll walk through them before any PHI is involved.
Is two-factor authentication available?
Yes, in user settings. Many companies make it mandatory policy.
Can AI access all our data?
AI agents work on the request in front of them inside your tenant. Their proposals are logged and require human decisions.
How do I report a security issue?
Email us from the contact page with the subject 'Security' and we'll respond promptly.
Want to walk MEDBIX against your real claim mix?
Thirty minutes with sample data. We'll follow one claim through the gate, then talk about your payers, practices and where the rework hurts today.
Notes from the billing floor
Occasional, practical writing on denials, A/R and running a billing company. No spam, unsubscribe any time.
