Loading...

Data security at a glance

The eight things healthcare executives ask us first, answered before you have to ask.

PHI remains in your US-hosted systems
No PHI stored on servers outside the US
Encrypted remote access only
Role-based permissions, least privilege
Comprehensive, reviewable audit logs
BAA executed before any PHI access
Dedicated OneMed employees only
No subcontractors or freelancers
Straight answers

The questions people don’t always ask.

Choosing a medical billing partner means giving a company you’ve never met access to your patients’ records and your practice’s money. A handful of things are worth knowing before that happens, and most go unasked because they feel impolite. We’d rather answer them here than have you find out later.

Where is our patient data stored?

In the United States, in your own systems — it doesn’t move.

Protected health information stays in your US-hosted EHR, practice management or billing platform, or other US infrastructure you approve. We don’t copy it, migrate it, or hold it on servers of our own. There is no OneMed database with your patients in it, which also means there’s nothing to hand back if you leave.

Then who can access it, and how?

Named OneMed employees, through encrypted role-based access.

A Business Associate Agreement is executed before anyone touches PHI. Access is granted per role on a least-privilege basis, sessions run over encrypted connections into your environment, and activity is logged and reviewable. The people doing the work are our own employees in our own delivery centres — never subcontractors, freelancers or marketplace workers.

What do your certifications actually cover?

Different things — and one of them isn’t a certification at all.

ISO 27001 covers our information security management system. ISO 9001 covers quality management. PCI DSS applies where card-payment data is involved. HIPAA is not a certification — no body issues one. It is a legal obligation, and any vendor claiming to be “HIPAA certified” is describing something that doesn’t exist. Certification numbers and registrar details are available on request.

What if we want to leave?

Nothing to extract. Your data was never ours.

Because we work inside your systems, your claims, notes and history stay in your platform throughout — no proprietary layer to unpack and no export to negotiate. Notice periods sit in the service agreement; ask about them during the sales conversation rather than after.

Will you tell us things we don’t want to hear?

Yes, and it’s the main reason to hire us.

If your documentation doesn’t support the level being billed, we’ll say so. If a denial is correct, we’ll close it rather than bill you to appeal it. If a claim is past the point of being worth chasing, we’ll tell you and record why.

If any answer above stops being true, it should change here before anyone has to discover it. That’s the standard we hold this page to.

How we're structured

One accountable operation, two locations

Our US headquarters holds the client relationship, the commercial terms and the infrastructure standards. Our delivery centres run the daily revenue cycle work against those standards.

United States — Headquarters

Where the relationship and the data sit

4th Floor, Nemours Building
1007 N Orange St, Wilmington, Delaware 19801
(315) 366-8242

  • The entity you contract with
  • Commercial operations and account ownership
  • US-hosted data and infrastructure standards
  • Client escalation and resolution
Delivery Operations

Where the work gets done

Dedicated OneMed delivery centres, Kolkata — aligned to your working hours.

  • Medical coding and charge entry
  • Claims, denial management and AR follow-up
  • Prior authorization and credentialing
  • Our own employees, in our own offices
Our story

Built to take the admin burden off providers

OneMed was founded in 2020 to lift administrative load off healthcare providers. What started as a small team with a handful of clients now supports hundreds of healthcare organizations across the United States — from solo practitioners and multi-specialty groups to surgery centres and hospital systems.

One principle has held throughout: listen first, then build around the client rather than the other way round. Whether it’s a telehealth startup finding its feet or a hospital tightening a mature healthcare revenue cycle, the priorities stay the same — accuracy, integrity and care.

a small team a few clients
hundreds of organizations
2020 today

Illustrative of growth, not a plotted figure.

WHAT WE'RE TRYING TO BE GOOD AT

Four things we'd want to be judged on

Accuracy

Coded to what the record supports — no higher — and claims tracked to resolution.

Transparency

Straight answers, including when the honest one doesn't win us more work.

Responsiveness

Escalating rather than sitting on a problem, and adapting to how you already work.

Accountability

A named team on your account, and reporting that shows the work rather than describing it.

In-house, another vendor, or us

All three are legitimate depending on your size and situation. An honest read on the trade-offs.

Consideration In-house staff Typical vendor OneMed Billing
Data residency Stays in your systems Varies — ask directly Stays in your US-hosted systems
Cost structure Salaries plus benefits, fixed Fixed fees, often bundled Flexible and à la carte
Staffing Limited capacity, exposed to turnover Resources often shared across clients A dedicated team on your account
Scaling up or down Slow — requires hiring Depends on contract terms Scales with volume
Specialty coverage Whatever your team knows Varies by vendor 30+ specialties
Access to the people doing the work Direct — they’re down the hall Often ticket-based Direct access to your named team

In-house genuinely wins on proximity. If your volume is low and you already have someone excellent, keeping billing in-house can be the right answer — and we’ll say so on a discovery call.

Standards

Our certifications, and what each one means

Badges are easy to display. This is what they actually cover — certificate numbers and registrar details available on request.

ISO 27001:2022

Information security management — how we protect data.

ISO 9001:2015

Quality management — how we keep processes consistent.

PCI DSS

Applies where card payment data is handled.

HIPAA workflows

A legal obligation, not a certification — no body issues one.

If a vendor tells you they're "HIPAA certified", ask who issued it. Nobody does.

LET'S TALK

Book a discovery call

A conversation, not a pitch. Tell us how your revenue cycle runs today and we'll tell you where we'd help — including if the honest answer is that you don't need us yet. Bring the security questions; they're the right ones to ask.

  • No obligation, and no pressure to hand over the whole cycle
  • BAA executed before any records are shared
  • Certificate details, security documentation and references on request
Prefer to talk now? (315) 366-8242

Book a discovery call

We'd love to learn about your practice and how we can help.

By submitting, you consent to be contacted about your enquiry and to the processing of your information as described in our Privacy Policy.