Trust & Security

How we protect your account and content

The safeguards behind member access, licensed publications, certification, and PHI prevention.

Effective date: September 21, 2026 · Last updated: September 21, 2026

PHI Prevention Mode

Ask ClaimetryX, guided denial workflows, and contact forms screen input before it is processed and block content that looks like a patient identifier. Guided workflows use fixed-choice answers, so the normal path collects no free-text patient data at all.

Server-side authorization

Every paid guide, resource, and paid data table is authorized on the server for each request against your actual entitlement. Paid rows are never shipped inside the public page, and a direct URL cannot bypass the check.

Row-level database rules

Member data is stored with row-level access rules so a signed-in account can only read its own records. Administrative tables require an explicit admin role checked on the server.

Per-buyer licensed files

Purchased publications are stored privately and delivered as watermarked copies stamped with the buying account and license key, so a leaked copy is traceable to its buyer. Resource files are released through short-lived links issued only after the entitlement check.

Exam integrity

Certification attempts are stored as immutable snapshots, finalized atomically, and scored server-side. Answer keys are withheld from the client.

Source accountability

Operational guidance carries its source, edition, and verification state. Where a requirement has not been verified against a current official source, the page says so instead of implying certainty.

Common questions

How does ClaimetryX handle HIPAA and business-associate questions?

ClaimetryX is designed as a reference and training platform that should not receive protected health information, and you must keep every submission de-identified. ClaimetryX does not represent that this zero-PHI design alone resolves your organization's HIPAA or business-associate analysis — you should evaluate your own relationships and legal obligations with your advisers.

Where is data stored?

Account, entitlement, learning, and content records live in a managed Postgres database with row-level access rules. Purchased files live in private storage and are released only after a server-side entitlement check, either as a short-lived link or streamed directly to the buyer.

Do you sell or share personal data?

No. See the Privacy Policy for the full list of service providers we rely on to run the platform.

How do you handle payment details?

Card data is handled entirely by our payment processor. We store only the plan, license, and transaction references needed to grant access.

How do I report a security concern?

Send it through the contact page and choose the security reason. Please include enough detail to reproduce the issue, and never include patient data.