Minimum necessary access
Practice and billing-company scope is enforced server-side. Users only reach workflows their role and client-practice access allow.
Privacy
Medi handles medical billing data for billing companies and the practices they serve. Privacy starts with scoped access, audit logging, and a signed production agreement before PHI work begins.
Controls
Operational records remain tenant-scoped. Any de-identified data use is tracked separately from live billing operations and is not a shortcut around the signed agreement.
Practice and billing-company scope is enforced server-side. Users only reach workflows their role and client-practice access allow.
PHI-sensitive activity is logged with user, tenant, action, and timing evidence so access can be reviewed later.
Medi separates operational PHI from de-identified data. Benchmark or network use requires explicit rights, de-identification controls, and suppression gates before customer-visible use.
Requests