Security & privacy
Patient records, protected at every step.
Remitz is built with the sensitivity of PHI in mind. Only verified physicians can authorize a search for patient records, and every request is logged. We sign a Business Associate Agreement with every customer and keep all patient data in the United States.
-
Verified physicians only
ID, facial and credential checks -
BAA with every customer
Signed at signup -
Never used to train AI
Protected under your BAA -
US-only data storage
Stored and processed in the US
Who can access records
Every record search starts with a verified physician.
Before patient record search is turned on, Remitz confirms who a physician is and that they are a licensed clinician. Record requests then run through regulated interoperability frameworks, which support treatment use cases and set rules that Remitz and every user follow.
How verification works-
Identity verified
Every physician verifies their identity with a government-issued photo ID and facial verification before record search is turned on.
-
Credentials confirmed
We confirm each physician's Type 1 NPI and professional credentials. Record search stays off until every check passes.
-
Treatment use supported
Records are requested through regulated interoperability frameworks, which support treatment use cases. Their rules apply to Remitz and every user.
-
Every request logged
Each patient search and record retrieval is recorded in an audit log.
For your patients, this means every record search is authorized by a verified clinician, and every request is on record.
AI and your patient data
AskREMI reads the record. It never trains on it.
AskREMI helps you find and understand what's in a patient's records. Patient data is never used to train AI models. Any AI service that processes it does so under a HIPAA Business Associate Agreement and zero-data-retention terms, so the service keeps no copy of your prompts or patient data.
Learn more about AskREMI-
Never used for training
Your patients' records are never used to train AI models.
-
Protected during processing
AI services that handle patient data work under a HIPAA BAA and keep no copy after responding.
-
Answers you can check
Answers drawn from patient records link to the source document, so you can verify them in one click.
-
You make the decisions
AskREMI supports your clinical judgment. It never makes clinical decisions for you.
AskREMI works within your permissions. It can only use records and documents you are authorized to access.
Your AskREMI conversations are saved in your Remitz account and linked to the relevant patient profile, covered by your BAA like the rest of your patient data.
Compliance
HIPAA safeguards, a signed BAA, and regulated record exchange.
Remitz handles protected health information in clinical and billing workflows, so these commitments apply to every customer from day one.
Our Privacy Policy and Terms of Use explain how we handle personal and patient information.
-
Built for HIPAA
Remitz is designed to support HIPAA-compliant healthcare workflows and maintains administrative, physical, and technical safeguards designed to protect protected health information (PHI), including encryption, access controls, audit logging and incident response.
-
A BAA with every customer
Every Remitz customer signs a Business Associate Agreement at signup. It sets out how we protect and handle patient information for you.
Questions about our BAA? privacy@remitz.com
-
Regulated interoperability frameworks
Remitz exchanges records through regulated interoperability frameworks that connect healthcare networks for secure record exchange. Their rules apply to Remitz and every user.
Safeguards
How we protect patient data
Eight safeguards work together, from the moment you sign in to where your data is stored.
-
Encryption
Patient data is encrypted both while it is transmitted, using TLS, and while it is stored.
-
Multi-factor sign-in
Multi-factor authentication is available on every account and required for all Remitz staff.
-
Role-based access
Practice administrators choose which team members can use patient record search. Remitz staff can access only what their role requires.
-
Audit logging
Access to, changes to, and deletion of patient data are logged, creating a detailed record for review.
-
US-only infrastructure
All patient data is stored and processed in the United States, across leading cloud providers and a dedicated, access-controlled US data center.
-
Incident response
Documented incident response and breach notification procedures help us act quickly and notify you as HIPAA requires.
-
Trained team
Every team member completes HIPAA and privacy training before getting access, plus ongoing security awareness training.
-
Data retention
Clear policies set how long data is kept and how it is securely deleted when no longer needed.
Roadmap
In place today, and what's next
We're open about where we are. Here's what protects patient data now, and the independent validation we're working toward.
In place today
Now- HIPAA administrative, physical and technical safeguards
- A Business Associate Agreement with every customer
- Verified physician access: photo ID, facial verification, NPI and credential checks
- Record requests through regulated interoperability frameworks
- US-only data storage and processing
- Multi-factor authentication on every account, required for staff
Next
2027- HITRUST certification
We're working toward HITRUST certification in 2027, for independent validation of the safeguards already in place today. We'll update this page as we reach each milestone.
Last updated September 2026
FAQ
Security questions, answered
Straight answers to what physicians, practices and compliance teams ask us most. More questions are on our FAQ page.
Have a question that isn't here?Email privacy@remitz.com and our team will get back to you.
Compliance & certifications
Is Remitz HIPAA compliant?
Remitz is designed to support HIPAA-compliant healthcare workflows and maintains administrative, physical, and technical safeguards designed to protect protected health information (PHI).
Does Remitz sign a Business Associate Agreement (BAA)?
Yes. Remitz requires customers to enter into a Business Associate Agreement as part of signup. The BAA defines the responsibilities associated with protecting and handling PHI when using Remitz.
Does Remitz undergo security and compliance assessments?
Remitz maintains an ongoing security and compliance program designed for the requirements of healthcare data. Additional independent assessments and certifications may be pursued as the platform and organization continue to grow.
Is Remitz HITRUST certified?
Remitz is not currently HITRUST certified. HITRUST certification is part of Remitz’s security and compliance roadmap as the company continues to expand its platform and enterprise capabilities.
Can my organization request additional security or compliance information?
Yes. Organizations evaluating Remitz can contact our team to discuss security, privacy, compliance, or organizational requirements and request additional information when appropriate.
Access & verification
Who can access patient information in Remitz?
Access to patient information is controlled through user permissions and role-based access controls. Organizations can manage which authorized team members have access to sensitive information and capabilities, including patient record search.
How does Remitz verify physicians before enabling patient record search?
Before patient record search is activated, Remitz verifies physician identity and professional credentials. The verification process includes identity verification and validation of applicable professional information, including the physician’s Type 1 NPI.
Can anyone with a Remitz account search for patient records?
No. Patient record search is a controlled capability. Appropriate verification and authorization are required before access is enabled, and organizations can manage which authorized users have access to patient record search functionality.
Does Remitz support multi-factor authentication (MFA)?
Yes. Multi-factor authentication is available to help provide an additional layer of protection for Remitz accounts. Remitz personnel with access to internal systems are subject to additional security requirements.
Does Remitz maintain audit logs?
Yes. Remitz maintains audit logs for relevant activity involving patient information and other sensitive actions within the platform. This helps organizations maintain visibility and accountability around access and use.
AI & AskREMI
Is patient data used to train AI models?
No. Patient records and PHI processed through Remitz are not used to train AI models.
Do AI providers retain my patient data or prompts?
AI services used by Remitz to process PHI are configured and contracted with healthcare-appropriate data protections, including applicable Business Associate Agreements and zero-data-retention requirements. Conversations or information intentionally saved within your Remitz environment are maintained by Remitz in accordance with applicable agreements and policies.
How does Remitz protect information used by AskREMI?
AskREMI operates within the access and permissions available to the user and their organization. Patient information processed by AskREMI is protected by the same privacy and security safeguards that apply throughout the Remitz platform and is not used to train AI models.
Data protection
How does Remitz protect patient information?
Remitz uses administrative, physical, and technical safeguards designed to protect patient information. These include encryption, access controls, authentication, audit logging, secure infrastructure, and policies governing how sensitive healthcare information is accessed and handled.
Is data encrypted?
Yes. Remitz uses encryption to protect sensitive information both while it is transmitted and while it is stored.
Where is patient data stored and processed?
Patient data is stored and processed using secure, U.S.-based infrastructure designed to support the privacy and security requirements associated with healthcare information.
How long does Remitz retain patient information?
Remitz maintains policies governing the retention and secure deletion of information. Specific data-handling and retention requirements are governed by applicable agreements and policies, including the Business Associate Agreement, Privacy Policy, and Terms of Use.
What happens if Remitz identifies a security incident?
Remitz maintains incident response and breach notification procedures designed to support the investigation, containment, remediation, and notification of security incidents in accordance with applicable requirements.
Your organization’s data & integrations
How is my organization’s private knowledge and proprietary data protected?
Your organization’s private knowledge, uploaded documents, proprietary data, workflows, and other organization-specific resources are logically isolated from other Remitz customers and restricted to your organization’s environment. Access is governed by your organization’s user permissions and access controls.
How does Remitz protect credentials for connected applications and APIs?
Credentials and secrets used for connected applications, APIs, and integrations are protected using secure cloud-provider secrets management. Access to these credentials is restricted and managed through appropriate security controls.
How does Remitz protect data accessed through connectors and integrations?
Information accessed through connected applications and integrations is subject to Remitz’s security and access controls. Users and organizations control which supported systems they connect, and access is limited according to the permissions and authorization available for those connections.
Questions about security or privacy?
Our team can answer questions about how Remitz protects patient data, share our security documentation, or walk you through our BAA.
Found a security issue? Report it to privacy@remitz.com. We review every report.