How Merid protects your data
Written for the person who has to sign off on us. If something here is not enough for your review, ask — we would rather answer the hard question now than have it come up after a contract.
What we receive
Only what the work requires: remittance (835) and claim (837) files, your payer contract terms, and — for cases we are actively appealing — the specific chart excerpts a payer’s stated policy criteria require. We do not receive or store complete medical records.
Where it lives
Amazon Web Services, in a private network with no public database endpoint, under a signed Business Associate Agreement. Encrypted with AES-256 at rest and TLS 1.2+ in transit.
Each customer’s data is isolated at the database level and encrypted with a key specific to that customer. Those are two independent controls rather than one: the isolation is enforced by the database on every query, and the encryption means a record retrieved by some path that bypassed it still cannot be read.
Who can see it
- Named individuals only, each with a unique login and multi-factor authentication. No shared accounts, including for our own staff.
- Role-limited to what the job requires — biller, reviewer, administrator.
- Every access to your data is logged with the user, the record, and the timestamp, in a tamper-evident log the application itself cannot rewrite, retained six years and available to you on request.
Our AI processing
All AI processing runs under a Business Associate Agreement with our model provider, configured for zero data retention where the provider offers it. Only the minimum necessary information is sent — the chart excerpts a specific criterion requires, never whole charts. No customer data is used to train models, and nothing is shared across customers.
Money arithmetic, contract rates, and filing deadlines are computed in deterministic code, not by a language model. That is a correctness decision, not a cost one: arithmetic is the part of this system that must be exactly right every time, and it is also the part a model is worst at.
Our commitments
- Annual penetration testing; vulnerability scanning every six months.
- A documented incident response plan with 72-hour notification.
- Annual security risk analysis.
- We are building to the HHS Security Rule updates proposed for 2027 rather than to today’s minimum — the requirements are the right security regardless, and retrofitting them later costs far more than building to them now.
SOC 2 Type II in progress.
What we never do
- We never take custody of your money. Payer payments go directly to you and we invoice afterward, against remittances that actually posted.
- We never contact your patients. Every dispute here is with a payer.
- We never sell or share your data, or use it for any purpose beyond the recovery work you have authorized.
- Your data stays yours, exportable at any time, with a defined export-and-deletion process and a certificate of destruction if you leave.
We will send the BAA template, our subprocessor list, and the insurance certificate before you ask for them. Email security@merid.health.