How we think about security
Nem handles operational and clinical data for healthcare practices. We design our platform to meet the technical, administrative, and physical safeguards required under the HIPAA Security Rule. This page summarizes the current state of our security posture in plain language, including what we have not done.
HIPAA has no official certification, and no organization can be certified HIPAA compliant, so we do not claim one. What we can say is that our architecture is built to the HIPAA Security Rule safeguards, our self-attestation is in progress, and SOC 2 is planned rather than held. We will never claim a certification we do not have.
Data protection
- Encryption at rest - all data is encrypted using AES-256 by our database provider.
- Encryption in transit - TLS 1.2 or higher on all network connections.
- Access control - role-based access control (RBAC) gates every API and every page.
- Audit logging - significant actions (record access, billing edits, configuration changes) are logged with actor, timestamp, and target.
- Secrets management - API keys and credentials are stored in environment variables managed by our hosting providers; never in source code.
HIPAA alignment
Nem implements HIPAA-aligned safeguards. A Business Associate Agreement is available to every clinic and must be in place before any Protected Health Information is processed. BAAs are executed customer by customer, and with our PHI-touching subprocessors, ahead of live patient data. Until your BAA is in place, we recommend testing with synthetic data only.
For customers processing Protected Health Information (PHI), the Business Associate Agreement (BAA) governs the handling of PHI and controls over any conflicting term. The order of precedence for PHI is: (1) the BAA, (2) your subscription order, (3) the Terms of Service, (4) the Privacy Policy, and (5) any other posted policy.
- Technical - encryption, access control, automatic session timeout, audit logs.
- Administrative - internal access control policy, vendor risk policy, incident response plan, employee training (in progress).
- Physical - handled by our cloud hosting providers (currently Neon and Vercel, US regions). SOC 2 Type II reports available on request from those providers.
Subprocessors
Nem uses a small set of subprocessors. PHI-touching subprocessors are Retell AI (voice infrastructure), Google Workspace (business email and documents), AWS (file storage, email transport), Vercel (application hosting), Neon (database) and NEMSOL (Pvt) Ltd (engineering and support personnel (pakistan)), each under a Business Associate Agreement executed before any PHI is processed in production. PHI-free services are Stripe (subscription billing and payments), Cloudflare Turnstile (bot protection on sign-in and sign-up), Resend (transactional email) and PostHog (product analytics); they operate under a strict PHI-free policy and never receive PHI. Cloudflare offers a Business Associate Agreement only at its Enterprise tier, which is precisely why Turnstile is kept out of every PHI path.
Nem is operated with the support of its affiliate NEMSOL (Pvt) Ltd (CUIN 0342731), registered in Pakistan. Named engineering and support personnel of that affiliate access the platform. Access to Protected Health Information is permitted only under an intercompany Business Associate Agreement executed before any PHI is processed in production, and we will tell customers before that arrangement changes.
This list was last reviewed on August 1, 2026. A current subprocessor list is available on request to info@nemsol.org and on our Trust Center.
A full breakdown, including each vendor's BAA status, is on our Trust Center.
Incident response
We maintain a documented incident response process.
If we discover a security incident affecting customer data, we notify affected customers without unreasonable delay and no later than five (5) business days after discovery. The clock starts when we discover the incident, not when we finish confirming it. We provide the facts as they are known and keep updating until the matter is resolved.
For Protected Health Information the Business Associate Agreement sets this obligation and controls over any other document, including this page.
Backups and continuity
- Database backups are taken at least daily.
- Backups are encrypted and overwritten on a rolling 30-day cycle.
- Point-in-time recovery is available on production environments.
Data retention and offboarding
Active customer data is retained for the duration of your subscription. After termination or cancellation your data remains available for 30 days so you can export it (CSV download); after that window we delete it, unless a legal or contractual retention obligation requires us to keep it longer. Deletion is a documented process we run, not an automated purge job. Encrypted backups are overwritten on a rolling 30-day cycle, so a copy can persist in backup for up to 30 days after deletion. Audit logs are retained for at least 6 years to support HIPAA-aligned operations.
For Protected Health Information, the return-or-destroy obligation in the Business Associate Agreement controls, including its infeasibility carve-out for data held in backup.
Reporting a vulnerability
If you believe you have found a security vulnerability in Nem, please email info@nemsol.org. We commit to acknowledging your report within 2 business days and to working with you in good faith to resolve the issue.
What is not yet in place
We believe transparency about what we have not done is as important as listing what we have. As of this document's last update:
- SOC 2 Type II is not yet completed.
- HIPAA self-attestation is in progress; BAAs are being executed on a customer-by-customer basis.
- ISO 27001 and HITRUST are out of scope for the current stage.
- Pen testing is conducted internally; an external pen test is planned ahead of broader US rollout.
Contact
For security questions, BAA requests, or vendor questionnaires:
info@nemsol.org · info@nemsol.org

