Security & data practices
NexLookup is built for medical billing operations. Free reference tools do not require protected health information. Agency Suite is designed for operational references (claim numbers, account refs, payer names, work status)— not as a clinical system of record. We take security seriously and are deliberate about what we claim.
Current safeguards
- Client isolation. Agency Suite data is scoped by owning account and by client record so work for one client is not mixed with another in the product model.
- Free tools, public data. ICD-10, CARC/RARC, NPI, POS, modifiers, HCPCS, and taxonomy lookups use public or CMS-sourced reference content. No patient chart is required to use them.
- Encryption in transit. Production traffic is served over HTTPS (TLS).
- Access control. Paid workbenches require authentication. Product entitlement checks gate Agency Suite features.
- Operational logging. Significant actions (for example analysis runs, notes, draft generation) can be recorded for internal accountability.
- No “store everything by default.” The product is oriented toward workqueue and reference fields. Customers should avoid entering full clinical notes or unnecessary identifiers.
What we do not claim today
NexLookup has not completed a formal HIPAA risk assessment, BAA program, or independent compliance audit for use as an ePHI system of record. We do not market the product as “HIPAA compliant.”
Roadmap
We plan to harden the path for agencies that need stronger assurances: formal risk assessment, documented policies, BAA availability where appropriate, tighter controls on any fields that could hold ePHI, and clearer retention/export/deletion procedures. Timeline depends on demand and readiness reviews—we will publish updates rather than imply certification we have not finished.
Customer responsibility
Agencies remain responsible for how staff use the tool, what data they enter, and whether their own policies allow a given workflow. If your use case requires a BAA and audited controls before any identifiable data is stored, wait for those milestones or limit use to non-PHI operational references and free public tools.
Questions: admin@nexlookup.cc · Privacy Policy · FAQ