Security & privacy

Patient records, protected at every step.

Remitz is built with the sensitivity of PHI in mind. Only verified physicians can authorize a search for patient records, and every request is logged. We sign a Business Associate Agreement with every customer and keep all patient data in the United States.

  • Verified physicians only

    ID, facial and credential checks
  • BAA with every customer

    Signed at signup
  • Never used to train AI

    Protected under your BAA
  • US-only data storage

    Stored and processed in the US

Who can access records

Every record search starts with a verified physician.

Before patient record search is turned on, Remitz confirms who a physician is and that they are a licensed clinician. Record requests then run through regulated interoperability frameworks, which support treatment use cases and set rules that Remitz and every user follow.

How verification works
  1. Identity verified

    Every physician verifies their identity with a government-issued photo ID and facial verification before record search is turned on.

  2. Credentials confirmed

    We confirm each physician's Type 1 NPI and professional credentials. Record search stays off until every check passes.

  3. Treatment use supported

    Records are requested through regulated interoperability frameworks, which support treatment use cases. Their rules apply to Remitz and every user.

  4. Every request logged

    Each patient search and record retrieval is recorded in an audit log.

For your patients, this means every record search is authorized by a verified clinician, and every request is on record.

AI and your patient data

AskREMI reads the record. It never trains on it.

AskREMI helps you find and understand what's in a patient's records. Patient data is never used to train AI models. Any AI service that processes it does so under a HIPAA Business Associate Agreement and zero-data-retention terms, so the service keeps no copy of your prompts or patient data.

Learn more about AskREMI
  • Never used for training

    Your patients' records are never used to train AI models.

  • Protected during processing

    AI services that handle patient data work under a HIPAA BAA and keep no copy after responding.

  • Answers you can check

    Answers drawn from patient records link to the source document, so you can verify them in one click.

  • You make the decisions

    AskREMI supports your clinical judgment. It never makes clinical decisions for you.

AskREMI works within your permissions. It can only use records and documents you are authorized to access.

Your AskREMI conversations are saved in your Remitz account and linked to the relevant patient profile, covered by your BAA like the rest of your patient data.

Compliance

HIPAA safeguards, a signed BAA, and regulated record exchange.

Remitz handles protected health information in clinical and billing workflows, so these commitments apply to every customer from day one.

  • Built for HIPAA

    Remitz is designed to support HIPAA-compliant healthcare workflows and maintains administrative, physical, and technical safeguards designed to protect protected health information (PHI), including encryption, access controls, audit logging and incident response.

  • A BAA with every customer

    Every Remitz customer signs a Business Associate Agreement at signup. It sets out how we protect and handle patient information for you.

    Questions about our BAA? privacy@remitz.com

  • Regulated interoperability frameworks

    Remitz exchanges records through regulated interoperability frameworks that connect healthcare networks for secure record exchange. Their rules apply to Remitz and every user.

Safeguards

How we protect patient data

Eight safeguards work together, from the moment you sign in to where your data is stored.

  • Encryption

    Patient data is encrypted both while it is transmitted, using TLS, and while it is stored.

  • Multi-factor sign-in

    Multi-factor authentication is available on every account and required for all Remitz staff.

  • Role-based access

    Practice administrators choose which team members can use patient record search. Remitz staff can access only what their role requires.

  • Audit logging

    Access to, changes to, and deletion of patient data are logged, creating a detailed record for review.

  • US-only infrastructure

    All patient data is stored and processed in the United States, across leading cloud providers and a dedicated, access-controlled US data center.

  • Incident response

    Documented incident response and breach notification procedures help us act quickly and notify you as HIPAA requires.

  • Trained team

    Every team member completes HIPAA and privacy training before getting access, plus ongoing security awareness training.

  • Data retention

    Clear policies set how long data is kept and how it is securely deleted when no longer needed.

Roadmap

In place today, and what's next

We're open about where we are. Here's what protects patient data now, and the independent validation we're working toward.

In place today

Now
  • HIPAA administrative, physical and technical safeguards
  • A Business Associate Agreement with every customer
  • Verified physician access: photo ID, facial verification, NPI and credential checks
  • Record requests through regulated interoperability frameworks
  • US-only data storage and processing
  • Multi-factor authentication on every account, required for staff

Next

2027
  • HITRUST certification

We're working toward HITRUST certification in 2027, for independent validation of the safeguards already in place today. We'll update this page as we reach each milestone.

Last updated September 2026

FAQ

Security questions, answered

Straight answers to what physicians, practices and compliance teams ask us most. More questions are on our FAQ page.

Have a question that isn't here?Email privacy@remitz.com and our team will get back to you.

Compliance & certifications

Is Remitz HIPAA compliant?

Remitz is designed to support HIPAA-compliant healthcare workflows and maintains administrative, physical, and technical safeguards designed to protect protected health information (PHI).

Does Remitz sign a Business Associate Agreement (BAA)?

Yes. Remitz requires customers to enter into a Business Associate Agreement as part of signup. The BAA defines the responsibilities associated with protecting and handling PHI when using Remitz.

Does Remitz undergo security and compliance assessments?

Remitz maintains an ongoing security and compliance program designed for the requirements of healthcare data. Additional independent assessments and certifications may be pursued as the platform and organization continue to grow.

Is Remitz HITRUST certified?

Remitz is not currently HITRUST certified. HITRUST certification is part of Remitz’s security and compliance roadmap as the company continues to expand its platform and enterprise capabilities.

See our security roadmap

Can my organization request additional security or compliance information?

Yes. Organizations evaluating Remitz can contact our team to discuss security, privacy, compliance, or organizational requirements and request additional information when appropriate.

Email privacy@remitz.com

Access & verification

Who can access patient information in Remitz?

Access to patient information is controlled through user permissions and role-based access controls. Organizations can manage which authorized team members have access to sensitive information and capabilities, including patient record search.

How does Remitz verify physicians before enabling patient record search?

Before patient record search is activated, Remitz verifies physician identity and professional credentials. The verification process includes identity verification and validation of applicable professional information, including the physician’s Type 1 NPI.

How verification works

Can anyone with a Remitz account search for patient records?

No. Patient record search is a controlled capability. Appropriate verification and authorization are required before access is enabled, and organizations can manage which authorized users have access to patient record search functionality.

Does Remitz support multi-factor authentication (MFA)?

Yes. Multi-factor authentication is available to help provide an additional layer of protection for Remitz accounts. Remitz personnel with access to internal systems are subject to additional security requirements.

Does Remitz maintain audit logs?

Yes. Remitz maintains audit logs for relevant activity involving patient information and other sensitive actions within the platform. This helps organizations maintain visibility and accountability around access and use.

AI & AskREMI

Is patient data used to train AI models?

No. Patient records and PHI processed through Remitz are not used to train AI models.

Do AI providers retain my patient data or prompts?

AI services used by Remitz to process PHI are configured and contracted with healthcare-appropriate data protections, including applicable Business Associate Agreements and zero-data-retention requirements. Conversations or information intentionally saved within your Remitz environment are maintained by Remitz in accordance with applicable agreements and policies.

How does Remitz protect information used by AskREMI?

AskREMI operates within the access and permissions available to the user and their organization. Patient information processed by AskREMI is protected by the same privacy and security safeguards that apply throughout the Remitz platform and is not used to train AI models.

Data protection

How does Remitz protect patient information?

Remitz uses administrative, physical, and technical safeguards designed to protect patient information. These include encryption, access controls, authentication, audit logging, secure infrastructure, and policies governing how sensitive healthcare information is accessed and handled.

Is data encrypted?

Yes. Remitz uses encryption to protect sensitive information both while it is transmitted and while it is stored.

Where is patient data stored and processed?

Patient data is stored and processed using secure, U.S.-based infrastructure designed to support the privacy and security requirements associated with healthcare information.

How long does Remitz retain patient information?

Remitz maintains policies governing the retention and secure deletion of information. Specific data-handling and retention requirements are governed by applicable agreements and policies, including the Business Associate Agreement, Privacy Policy, and Terms of Use.

Privacy Policy · Terms of Use

What happens if Remitz identifies a security incident?

Remitz maintains incident response and breach notification procedures designed to support the investigation, containment, remediation, and notification of security incidents in accordance with applicable requirements.

Your organization’s data & integrations

How is my organization’s private knowledge and proprietary data protected?

Your organization’s private knowledge, uploaded documents, proprietary data, workflows, and other organization-specific resources are logically isolated from other Remitz customers and restricted to your organization’s environment. Access is governed by your organization’s user permissions and access controls.

How does Remitz protect credentials for connected applications and APIs?

Credentials and secrets used for connected applications, APIs, and integrations are protected using secure cloud-provider secrets management. Access to these credentials is restricted and managed through appropriate security controls.

How does Remitz protect data accessed through connectors and integrations?

Information accessed through connected applications and integrations is subject to Remitz’s security and access controls. Users and organizations control which supported systems they connect, and access is limited according to the permissions and authorization available for those connections.

Questions about security or privacy?

Our team can answer questions about how Remitz protects patient data, share our security documentation, or walk you through our BAA.

Found a security issue? Report it to privacy@remitz.com. We review every report.