Data security at a glance
The eight things healthcare executives ask us first, answered before you have to ask.
The questions people don’t always ask.
Choosing a medical billing partner means giving a company you’ve never met access to your patients’ records and your practice’s money. A handful of things are worth knowing before that happens, and most go unasked because they feel impolite. We’d rather answer them here than have you find out later.
Where is our patient data stored?
In the United States, in your own systems — it doesn’t move.
Protected health information stays in your US-hosted EHR, practice management or billing platform, or other US infrastructure you approve. We don’t copy it, migrate it, or hold it on servers of our own. There is no OneMed database with your patients in it, which also means there’s nothing to hand back if you leave.
Then who can access it, and how?
Named OneMed employees, through encrypted role-based access.
A Business Associate Agreement is executed before anyone touches PHI. Access is granted per role on a least-privilege basis, sessions run over encrypted connections into your environment, and activity is logged and reviewable. The people doing the work are our own employees in our own delivery centres — never subcontractors, freelancers or marketplace workers.
What do your certifications actually cover?
Different things — and one of them isn’t a certification at all.
ISO 27001 covers our information security management system. ISO 9001 covers quality management. PCI DSS applies where card-payment data is involved. HIPAA is not a certification — no body issues one. It is a legal obligation, and any vendor claiming to be “HIPAA certified” is describing something that doesn’t exist. Certification numbers and registrar details are available on request.
What if we want to leave?
Nothing to extract. Your data was never ours.
Because we work inside your systems, your claims, notes and history stay in your platform throughout — no proprietary layer to unpack and no export to negotiate. Notice periods sit in the service agreement; ask about them during the sales conversation rather than after.
Will you tell us things we don’t want to hear?
Yes, and it’s the main reason to hire us.
If your documentation doesn’t support the level being billed, we’ll say so. If a denial is correct, we’ll close it rather than bill you to appeal it. If a claim is past the point of being worth chasing, we’ll tell you and record why.
If any answer above stops being true, it should change here before anyone has to discover it. That’s the standard we hold this page to.
One accountable operation, two locations
Our US headquarters holds the client relationship, the commercial terms and the infrastructure standards. Our delivery centres run the daily revenue cycle work against those standards.
Where the relationship and the data sit
4th Floor, Nemours Building
1007 N Orange St, Wilmington, Delaware 19801
(315) 366-8242
- The entity you contract with
- Commercial operations and account ownership
- US-hosted data and infrastructure standards
- Client escalation and resolution
Where the work gets done
Dedicated OneMed delivery centres, Kolkata — aligned to your working hours.
- Medical coding and charge entry
- Claims, denial management and AR follow-up
- Prior authorization and credentialing
- Our own employees, in our own offices
Built to take the admin burden off providers
OneMed was founded in 2020 to lift administrative load off healthcare providers. What started as a small team with a handful of clients now supports hundreds of healthcare organizations across the United States — from solo practitioners and multi-specialty groups to surgery centres and hospital systems.
One principle has held throughout: listen first, then build around the client rather than the other way round. Whether it’s a telehealth startup finding its feet or a hospital tightening a mature healthcare revenue cycle, the priorities stay the same — accuracy, integrity and care.
Illustrative of growth, not a plotted figure.
Four things we'd want to be judged on
Accuracy
Coded to what the record supports — no higher — and claims tracked to resolution.
Transparency
Straight answers, including when the honest one doesn't win us more work.
Responsiveness
Escalating rather than sitting on a problem, and adapting to how you already work.
Accountability
A named team on your account, and reporting that shows the work rather than describing it.
In-house, another vendor, or us
All three are legitimate depending on your size and situation. An honest read on the trade-offs.
| Consideration | In-house staff | Typical vendor | OneMed Billing |
|---|---|---|---|
| Data residency | Stays in your systems | Varies — ask directly | Stays in your US-hosted systems |
| Cost structure | Salaries plus benefits, fixed | Fixed fees, often bundled | Flexible and à la carte |
| Staffing | Limited capacity, exposed to turnover | Resources often shared across clients | A dedicated team on your account |
| Scaling up or down | Slow — requires hiring | Depends on contract terms | Scales with volume |
| Specialty coverage | Whatever your team knows | Varies by vendor | 30+ specialties |
| Access to the people doing the work | Direct — they’re down the hall | Often ticket-based | Direct access to your named team |
In-house genuinely wins on proximity. If your volume is low and you already have someone excellent, keeping billing in-house can be the right answer — and we’ll say so on a discovery call.
Our certifications, and what each one means
Badges are easy to display. This is what they actually cover — certificate numbers and registrar details available on request.
ISO 27001:2022
Information security management — how we protect data.
ISO 9001:2015
Quality management — how we keep processes consistent.
PCI DSS
Applies where card payment data is handled.
HIPAA workflows
A legal obligation, not a certification — no body issues one.
If a vendor tells you they're "HIPAA certified", ask who issued it. Nobody does.
Book a discovery call
A conversation, not a pitch. Tell us how your revenue cycle runs today and we'll tell you where we'd help — including if the honest answer is that you don't need us yet. Bring the security questions; they're the right ones to ask.
- No obligation, and no pressure to hand over the whole cycle
- BAA executed before any records are shared
- Certificate details, security documentation and references on request
Book a discovery call
We'd love to learn about your practice and how we can help.