Trust Center

Business Overview

At SpendMend, our mission is to positively impact patient care by delivering value to our healthcare clients through innovative cost-savings solutions, insightful transaction analysis, and improved process visibility.

For over 30 years, we’ve helped healthcare organizations—including hospitals, clinics, pharmacies, and suppliers—address financial leakage and operational inefficiencies. We understand the day-to-day challenges these organizations face, and we believe the losses they experience are both reversible and preventable.

Commitment to Trust and Security

Security, privacy, and compliance are at the core of everything we do at SpendMend.

We have been HITRUST i1 certified for several years. The HITRUST i1 Certification demonstrates SpendMend maintains foundational, best-practice information security controls aligned with leading frameworks like NIST, ISO, and HIPAA. It provides assurance of our cybersecurity readiness. The certification validates our proactive commitment to protecting healthcare data and reducing third-party risk for clients because SpendMend has undergone an independent, standardized, and trusted review of its security posture.

HITRUST Certified

All SpendMend applications undergo annual penetration testing by an independent third party.

Conducting an annual penetration test is a critical demonstration of our commitment to security. It provides an objective, expert assessment of the company’s systems, applications, and defenses, and uncovers vulnerabilities before malicious actors can exploit them. By engaging independent testers, the organization ensures transparency, avoids blind spots, and reinforces a culture of continuous improvement. This proactive approach not only strengthens internal defenses but also builds trust with customers, partners, and auditors who expect evidence of rigorous and repeatable security practices.

SpendMend takes a comprehensive and proactive approach to security, ensuring that our systems and data remain protected at every level.

Our applications are hosted in either Microsoft Azure or Amazon Web Services, leveraging its enterprise-grade infrastructure to support both multitenant and single-tenant environments as needed. All data is stored exclusively within the United States and is encrypted using industry-standard protocols, including AES-256 encryption at rest and TLS 1.2+ in transit. We provide access controls through Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Role-Based Access Control (RBAC) to ensure that only authorized personnel can access SpendMend applications. Our team is trained regularly on security best practices, and all employees undergo background checks as part of our hiring process. In the event of a security incident, we maintain a formal incident response plan to ensure timely identification, containment, and resolution, further demonstrating our commitment to protecting our clients' data and maintaining operational resilience.

For more information about our applications, please visit our Trust Center Resources page.

SpendMend maintains a comprehensive set of policies which demonstrate our commitment to cybersecurity.

Cybersecurity policies are critical for compliance with regulations such as HIPAA, which mandate technical, physical, and administrative safeguards to secure client data. These policies provide clear standards and procedures for staff, reducing the risk of data breaches and unauthorized access to client data.

Regular staff training, as mandated by these policies, helps build a security-aware culture and reduces human error, which is a common entry point for cyber threats. Ultimately, maintaining comprehensive cybersecurity policies is fundamental to protecting patient privacy, upholding legal and ethical responsibilities, and preserving the operational and reputational integrity of SpendMend.

SpendMend is deeply committed to protecting the privacy of our users and customers.

All data within our applications is encrypted both in transit and at rest, ensuring confidentiality and integrity. For sensitive information such as Protected Health Information (PHI), we have implemented review and redaction processes to remove patient data. Our adherence to the HITRUST i1 certification further reinforces this commitment, aligning our controls with industry-recognized standards for data protection and privacy. In addition, we’ve published a comprehensive Privacy Statement that outlines our practices and affirms our compliance with regulations such as the California Consumer Privacy Act (CCPA), ensuring transparency and accountability in how we collect, use, and protect personal data.

Regarding safeguards for personal data and individual privacy, we are committed to complying with the core principles of lawfulness, fairness, and transparency in data processing. We limit data collection to what is necessary for legitimate business purposes, ensure data is accurate and up to date, and retain it only for as long as needed. We implement measures to protect personal data, including encryption and access controls, and we support data subjects' rights such as access, rectification, erasure, and objection. Legitimate subject data requests can be requested by sending an email to privacy@spendmend.com.

At SpendMend, we believe that a strong security posture starts with a well-informed team.

All employees are required to complete security training annually, in addition to standard HR compliance training and role-specific security instruction tailored to their job responsibilities. To reinforce this foundation, we also conduct regular phishing simulation exercises and distribute monthly security awareness messages to keep key threats, and best practices top of mind. Additionally, each employee must review and formally attest to SpendMend’s security policies on an annual basis. This multi-layered approach demonstrates our commitment to building and maintaining a resilient security environment, ensuring that every team member plays an active role in protecting our systems, data, and clients.

SpendMend publishes content drawn from healthcare industry data and the firsthand expertise of our team. While all published content is authored, edited, and approved by qualified SpendMend professionals who are solely responsible for its final form and substance, AI-assisted tools may be used during the research and drafting of such content. SpendMend makes no guarantee that published content is free from error, and readers should independently verify information before relying on it for decision-making.

Contact Us

If you have questions or would like more information about our security practices, we encourage you to contact our security team directly at security@spendmend.com. We believe that transparency is a vital part of building trust with our customers, partners, and stakeholders. By making our security team accessible, we demonstrate our commitment to open communication, accountability, and continuous improvement. Whether you’re conducting due diligence, have compliance inquiries, or simply want to understand more about how we protect your data, we’re here to provide clear and timely responses. Your trust is important to us, and we view transparency as a core pillar of our overall security strategy.

If you still have questions, you can visit our frequently asked questions page.