Skip to content
MEDBIX

Trust architecture

Built for healthcare data from the first table.

MEDBIX is designed for PHI workloads in production — and this page says exactly what that means, and what we don't claim. Each billing company is a tenant; PostgreSQL row-level security enforces the boundary inside the database, not only in the interface. Admin, Supervisor, Biller and Accountant roles scope access, with billers limited to the practices they work. Claims need a named person's approval before submission, and every tenant write leaves an immutable audit trail with a person and a timestamp. Demos on this site use synthetic data; card details stay with Stripe; we do not claim "HIPAA certified" or "SOC 2 certified" here. Ask for our current compliance documentation and we'll share where things stand, clearly labelled.

Isolation

Five layers between a claim and a leak.

When a practice asks who else can see their data, the answer is short — and each layer is something you can explain.

  1. 01

    Database isolation

    Each billing company is a tenant. PostgreSQL row-level security enforces the boundary inside the database, not only in the interface.

  2. 02

    Application scoping

    Admin, Supervisor, Biller and Accountant roles, with billers scoped to the practices they work. Every request carries that scope.

  3. 03

    Named human approval

    No AI output finalizes money or coding. Claims need a person's approval before submission, recorded with a timestamp.

  4. 04

    Immutable audit trail

    Every tenant write and every approval is recorded with a person and a timestamp, and can't be edited after the fact.

  5. 05

    Credential handling

    Clearinghouse and integration credentials follow encrypted secret-handling patterns; JWT sign-in with optional two-factor.

Traceability

An audit log nobody can rewrite.

Approvals, returns, postings, rule changes and AI proposals all leave a trace. That's what auditors, payers and clients ask for.

Access

Four roles, practice-scoped.

Access follows the roles your admin assigns. See how each role works day to day on the solutions pages.

Handling

Data handling principles

  • Synthetic data only in demos and on this website
  • Billing-relevant data only — no clinical charts
  • Card details handled by Stripe, never stored by MEDBIX
  • SMS opt-outs honored automatically
  • Cross-company data use switched off without legal consent

About certifications

MEDBIX has compliance readiness documentation, but we don't claim to be "HIPAA certified" or "SOC 2 certified" on this site. Those words have specific meanings. Ask us for our current documentation and we'll share exactly where things stand.

Your obligations still matter

A Business Associate Agreement, your consent practices for SMS and your own staff policies all remain part of compliance. We'll go through them with you during onboarding.

Isolation

Walls that hold when a client asks who can see their data.

Each billing company is a tenant. PostgreSQL row-level security enforces the boundary inside the database — not only in the UI.

  • RLS on every tenant table
  • Practice scoping for billers
  • No cross-company leakage by design
Secure operations workstation

Audit

An audit log nobody can rewrite.

Approvals, returns, postings, rule changes and AI proposals leave a named, timestamped trace. That's what auditors and clients ask for.

  • Immutable write history
  • Person + timestamp on approvals
  • Exportable for reviews
Professional reviewing operational records

Access

Four roles that match real job titles.

Admin, Supervisor, Biller, Accountant — with optional two-factor and encrypted handling of clearinghouse credentials.

  • Least-privilege by default
  • Optional 2FA in settings
  • Secrets never stored in plain text
Supervised access review at a laptop
Quiet professional clinic workspace

Honesty

Compliance language without marketing stretch.

We share readiness documentation and walk BAAs with you. We don't claim vague 'HIPAA certified' slogans on the marketing site.

  • Ask for current documentation
  • Your staff policies still matter
  • Synthetic data only on this website

Common questions

Where is data stored?

MEDBIX runs on PostgreSQL with row-level security. We'll confirm hosting region and details for your account during onboarding.

Do you sign a BAA?

Talk to us about your Business Associate Agreement requirements; we'll walk through them before any PHI is involved.

Is two-factor authentication available?

Yes, in user settings. Many companies make it mandatory policy.

Can AI access all our data?

AI agents work on the request in front of them inside your tenant. Their proposals are logged and require human decisions.

How do I report a security issue?

Email us from the contact page with the subject 'Security' and we'll respond promptly.

Want to walk MEDBIX against your real claim mix?

Thirty minutes with sample data. We'll follow one claim through the gate, then talk about your payers, practices and where the rework hurts today.

Notes from the billing floor

Occasional, practical writing on denials, A/R and running a billing company. No spam, unsubscribe any time.

Security & trust | MEDBIX