Security

How we handle protected health information and protect the data our clients trust us with. Stated plainly, and only where we can stand behind it.

1. Our role under HIPAA

Mindlox AI handles protected health information (PHI) as a business associate of the healthcare organizations we serve. We execute a Business Associate Agreement with each covered entity before PHI is handled, and our obligations under HIPAA and that agreement govern everything below.

2. HIPAA-conscious workflows

Every stage of the revenue cycle is designed around the minimum-necessary standard: people see only the information their task requires.

  • Documented policies and procedures for handling PHI across registration, coding, claims, posting, denials, A/R, and patient billing.
  • Workforce HIPAA training at onboarding and on a recurring basis, with role-specific guidance.
  • A defined incident response process, including client notification as required by HIPAA and our agreements.

3. Access control

Access to client systems and data is granted by role, reviewed on a defined cadence, and removed promptly when a role changes or ends.

  • Role-based permissions scoped to the accounts and functions each team member works.
  • Multi-factor authentication on the systems that support it.
  • Periodic access reviews and same-day offboarding.

4. Audit logging

Claim actions taken by our team are recorded and visible to the client through their dashboard, so every status change has a who, what, and when. Logs are retained for the period set out in the client agreement.

5. Data protection

Data is encrypted in transit and at rest on the systems we operate. Claims, remittances, and eligibility transactions are exchanged with clearinghouses and payers over established secure channels. We do not send PHI by unencrypted email, and this website is not designed to receive it.

6. Working inside your systems

Wherever possible we work within the EHR and practice management systems a client already uses, under the client's own access controls, rather than exporting data into separate tools. Specific connectivity is agreed during discovery and documented in the engagement.

7. Security documentation and assessments

Our security policies, and any third-party assessments we hold, are available to prospective and current clients on request under a confidentiality agreement. We do not publish claims about certifications or attestations on this website; ask us and we will share what is current.

8. Reporting a security concern

If you believe you have found a security issue involving Mindlox AI, email info@mindlox.ai or call 817-256-4378. We acknowledge reports promptly, investigate, and keep you informed. We ask that you give us a reasonable opportunity to address an issue before sharing it publicly, and that you do not access or retain data that is not yours.

Let's identify where your practice is losing revenue — and build a plan to recover it.