Built for healthcare. Audited by design.
Every record attributed, every action logged, every tenant isolated. Here is how Nem protects clinic data, and what we sign before any patient data reaches us.
Last updated August 1, 2026
Fail-closed access control
Role-based permissions that deny by default. Every page verifies your session, role, clinic, and record existence on the server. A URL never grants access.
Complete audit trail
Every create, change, and deletion is attributed and timestamped. Nothing is silently removed; records are retired, never erased without a trace.
Encryption and 2FA
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Two-factor authentication and modern password standards protect every account.
Tenant isolation
Each clinic is a hard data boundary keyed on clinicId. Multi-clinic organizations see only what their roles allow, per clinic.
PHI-free email policy
Email never carries Protected Health Information. An automated guard blocks any outbound message that looks like it might contain PHI.
Retention and deletion
Your data stays available for 30 days after termination so you can export it, then we delete it. Audit logs are kept for at least 6 years. Deletion is a documented process backed by schema-enforced soft deletion, not an automated purge engine.
Subprocessors
Vendors that process data on our behalf. A Business Associate Agreement is executed with every PHI-touching subprocessor before any live patient data is onboarded.
Vendor agreements. BAAs are executed progressively ahead of any PHI, not all at once. The status column below is the current position for each vendor, and executed agreements and their records are retained. This list was last reviewed on August 1, 2026.
Where our people are. Nem is operated with the support of its affiliate NEMSOL (Pvt) Ltd (CUIN 0342731), registered in Pakistan. Named engineering and support personnel of that affiliate access the platform. Access to Protected Health Information is permitted only under an intercompany Business Associate Agreement executed before any PHI is processed in production, and we will tell customers before that arrangement changes.
| Vendor | Purpose | Touches PHI | BAA status |
|---|---|---|---|
| Retell AI | Voice infrastructure | Yes (at go-live) | BAA executed (Jul 2026) |
| Google Workspace | Business email and documents | Possible; BAA executed | BAA + CDPA executed (Jul 2026) |
| AWS | File storage, email transport | Yes (at go-live) | BAA executed at account setup |
| Vercel | Application hosting | Yes (at go-live) | BAA executed at PHI go-live |
| Neon | Database | Yes (at go-live) | BAA executed at PHI go-live |
| NEMSOL (Pvt) Ltd | Engineering and support personnel (Pakistan) | Yes (at go-live) | Intercompany BAA executed before any PHI access |
| Stripe | Subscription billing and payments | No, billing data only | Not required; PHI-free by design |
| Cloudflare Turnstile | Bot protection on sign-in and sign-up | No, IP address and challenge token only | Not required; never in a PHI path |
| Resend | Transactional email | No, PHI-free by policy | Not required |
| PostHog | Product analytics | No, no patient data | Not required |
Documents
Honest framing. Nem is in beta. Every demo environment runs on synthetic data only; no real patient data is accepted until your BAA and our vendor BAAs are in place. HIPAA has no official certification, and no organization can be certified HIPAA compliant, so we do not claim one. What we can say is that our architecture is built to the HIPAA Security Rule safeguards, our self-attestation is in progress, and SOC 2 is planned rather than held. We will never claim a certification we do not have. The statements above describe our architecture and practices.

