Security & Compliance
You are placing client health and financial records with a vendor. Here is exactly what happens to them.
This page is written to be read by the attorney performing vendor diligence, not by a procurement department. Every claim below is one we will restate in writing in a signed agreement — and we have left off anything we cannot yet stand behind.
Where the data lives
Client records, uploaded documents, and generated forms are stored with Supabase (managed Postgres and object storage) and served through Vercel. Both are US-hosted.
The full subprocessor list is available on request, and we will tell you before adding one that touches client data.
Encryption
Data is encrypted in transit with TLS and at rest by the storage layer. Documents are served through short-lived signed URLs rather than public links.
Signed URLs expire in one hour and are issued per request, so a copied link does not remain usable.
Separation between firms
Every record carries the firm that owns it, and access is enforced in the database itself through row-level security — not only in the application. A firm portal shows that firm’s data or nothing at all.
This is the control we test most, because it is the one that matters most in shared infrastructure.
Access control inside your firm
Staff logins belong to one firm. Clients and case contacts reach only their own matter through the portal, and estate planning drafts are restricted to the client of record rather than every contact on the case.
Removing a departed employee’s access is immediate and something you control.
Access control inside our company
Production access is limited to the people who operate the service. We do not browse client matters, and we do not use matter content for anything other than running the service for you.
We are a small company and we would rather say plainly what is true than describe a process we do not yet have.
Audit trail
Each matter keeps a timeline: documents received, forms generated, signature requests sent, withdrawn, and completed, and submissions made. Records are retained rather than deleted when something is superseded.
A withdrawn signature request stays on the record — a document that was sent and pulled back is part of the history of the matter.
The AI analysis
Bank statement analysis and document classification run through Anthropic and OpenAI. The output is a worklist for the attorney; it is never a determination and never files anything.
Attorney review is required. MedicaidHQ does not determine eligibility.
HIPAA and the business associate agreement
Whether your firm is a HIPAA covered entity, a business associate, or neither depends on who retained you — a firm engaged by a nursing home is in a different position from one engaged by the client directly. We will sign a business associate agreement where one is required, and a data protection agreement where it is not.
Ask and we will tell you exactly which we think applies to your engagement, and why.
Getting your data out
Matters, documents, and generated forms export in full, at any point, including during the free month. The record is yours and leaving does not cost you it.
On termination we delete client data on request and confirm when it is done.
What we do not do
We do not train models on your client data. We do not sell, share, or license matter content to anyone. We do not host client data outside the United States. And we do not claim certifications we have not earned — when you ask what we have, you will get a straight answer rather than a badge.