Security & trust
Built on public data. Designed to never hold PHI.
EarnestMD turns insurers’ own public rate filings into benchmarks. The product is deliberately scoped so the riskiest healthcare data never enters it — and what you do share is protected with standard, audited controls.
No PHI, by design
We don’t accept the data that creates the most risk.
Because the Service is designed not to receive PHI, EarnestMD is not a HIPAA business associate and no BAA is required. The following are out of scope and not accepted:
- Protected Health Information (PHI) — no patient identifiers, diagnoses, or encounter data
- Claims data — yours or any payer's
- Executed payer contracts or PHI-derived materials
- Substance-use-disorder records (42 CFR Part 2)
- Payment card numbers — Stripe handles those directly; they never touch our systems
Where the data comes from
Public, federal, and independent.
Our benchmarks are built from data the government already requires to be public. EarnestMD is independent and not affiliated with any insurer.
Payer transparency files
Negotiated rates every commercial insurer must publish under the federal Transparency in Coverage rule.
CMS fee schedules
Public Medicare allowed-amount references used to normalize comparisons.
NPPES & PECOS
The public federal provider directories we use to resolve NPIs and build peer groups.
How we protect your data
Standard controls, applied consistently.
Encryption in transit & at rest
TLS 1.2+ on all public endpoints; encryption at rest at the database layer.
Authentication & MFA
Sign-in is handled by Clerk — we never see your password. Multi-factor authentication is enforced on internal accounts.
Tenant isolation
Role-based access plus server-side controls that prevent the assistant from widening its own data access beyond your scope.
Audited privileged actions
User provisioning, role changes, roster saves, and report generation are written to an append-only audit log with actor, context, and timestamp.
Managed secrets
Credentials live in our hosting providers' managed secret storage — never in source control.
Error tracking without your content
Sentry captures stack traces for reliability, configured to redact submitted queries and uploaded data from error reports.
Certifications & incident response
We don’t claim certifications we haven’t earned.
EarnestMD is SOC 2-ready — our controls are designed to map to the SOC 2 Common Criteria — but we are not yet SOC 2 certified. We’ll say so plainly here the day that changes.
In the event of a confirmed security incident affecting your data, we notify the affected customer without undue delay and, in any case, within 72 hours of confirming impact — with the nature of the incident, the data involved, and our remediation steps.
Subprocessors
Every vendor that touches the service.
Each operates under a data processing agreement. We give customers at least 30 days’ notice before adding or replacing a material subprocessor. The authoritative list, with policy links, lives in our Privacy Policy.
| Subprocessor | Purpose | Region |
|---|---|---|
| Clerk | Authentication (sessions, MFA) | United States |
| Vercel | Marketing site + portal frontend hosting | United States |
| Render | Backend API hosting | United States |
| Neon | Managed Postgres (accounts, audit log, rosters) | United States |
| MotherDuck | Rate warehouse (analytics queries) | United States |
| Anthropic | LLM inference (the assistant) | United States |
| Stripe | Payment processing (card data handled directly by Stripe) | United States |
| Sentry | Application error tracking | United States |
| Plausible | Cookie-free site analytics (no personal identifiers) | European Union |
Your uploads
Yours, de-identified, and revocable.
Uploading practice volumes, rate sheets, or rosters is optional. When we derive aggregate market statistics from customer uploads, identifying fields are stripped, no aggregate row may represent fewer than five distinct organizations, geography is generalized to state/CBSA, and rates are reported only as group statistics. We never license customer-derived aggregates to payers, and you can opt out at any time.
Security questions, DPA requests, and incident reports go to info@earnestmd.com.