Built for healthcare. Audited by design.
Every record attributed, every action logged, every tenant isolated. Here is how Nem protects clinic data, and what we sign before any patient data reaches us.
Last updated August 13, 2026
Fail-closed access control
Role-based permissions that deny by default. Every page verifies your session, role, clinic, and record existence on the server. A URL never grants access.
Complete audit trail
Every create, change, and deletion is attributed and timestamped. Nothing is silently removed; records are retired, never erased without a trace.
Encryption and 2FA
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Two-factor authentication and modern password standards protect every account.
Tenant isolation
Each clinic is a hard data boundary keyed on clinicId. Multi-clinic organizations see only what their roles allow, per clinic.
PHI-free email policy
Email never carries Protected Health Information. An automated guard blocks any outbound message that looks like it might contain PHI.
Retention and deletion
Your data stays available for 30 days after termination so you can export it, then we delete it. Audit logs are kept for at least 6 years. Deletion is a documented process backed by schema-enforced soft deletion, not an automated purge engine.
Subprocessors
Vendors that process data on our behalf. A Business Associate Agreement is executed with every PHI-touching subprocessor before any live patient data is onboarded.
Vendor agreements. BAAs are executed progressively ahead of any PHI, not all at once. The status column below is the current position for each vendor, and executed agreements and their records are retained. This list was last reviewed on September 2, 2026.
| Vendor | Purpose | Touches PHI | BAA status |
|---|---|---|---|
| Retell AI | Voice infrastructure | Yes | BAA executed (Jul 2026) |
| Google Workspace | Business email and documents | Yes | BAA + CDPA executed (Jul 2026) |
| AWS | File storage, email transport | Yes | BAA executed at account setup |
| Google Cloud | Production application hosting and database (us-central1) | Yes | BAA executed August 8, 2026 |
| Vercel | Marketing site hosting | No, never in a PHI path | Not required; PHI-free by architecture |
| Neon | Development database | No, development data only | Not required; PHI-free by architecture |
| Stripe | Subscription billing and payments | No, billing data only | Not required; PHI-free by design |
| Cloudflare Turnstile | Bot protection on sign-in and sign-up | No, IP address and challenge token only | Not required; never in a PHI path |
| Resend | Transactional email | No, PHI-free enforced by a fail-closed send-time scan | Not required |
| PostHog | Product analytics | No, no patient data | Not required |
Documents
Honest framing. Nem is in beta. Every demo environment runs on synthetic data only; no real patient data is accepted until your BAA and our vendor BAAs are in place. HIPAA has no official certification, and no organization can be certified HIPAA compliant, so we do not claim one. What we can say is that our architecture is built to the HIPAA Security Rule safeguards, our self-attestation is in progress, and SOC 2 is planned rather than held. We will never claim a certification we do not have. The statements above describe our architecture and practices.

