Security & data practices

NexLookup is built for medical billing operations. Free reference tools do not require protected health information. Agency Suite is designed for operational references (claim numbers, account refs, payer names, work status)— not as a clinical system of record. We take security seriously and are deliberate about what we claim.

Current safeguards

What we do not claim today

NexLookup has not completed a formal HIPAA risk assessment, BAA program, or independent compliance audit for use as an ePHI system of record. We do not market the product as “HIPAA compliant.”

Roadmap

We plan to harden the path for agencies that need stronger assurances: formal risk assessment, documented policies, BAA availability where appropriate, tighter controls on any fields that could hold ePHI, and clearer retention/export/deletion procedures. Timeline depends on demand and readiness reviews—we will publish updates rather than imply certification we have not finished.

Customer responsibility

Agencies remain responsible for how staff use the tool, what data they enter, and whether their own policies allow a given workflow. If your use case requires a BAA and audited controls before any identifiable data is stored, wait for those milestones or limit use to non-PHI operational references and free public tools.

Questions: admin@nexlookup.cc · Privacy Policy · FAQ