What could your health system do with more insight and visibility?

Discover why the nation’s leading health systems trust SpendMend to develop lasting, transformative solutions in spend management.

At SpendMend, our mission is to positively impact patient care by delivering value to our healthcare clients through innovative cost-savings solutions, insightful transaction analysis, and improved process visibility.

For over 30 years, we’ve helped healthcare organizations—including hospitals, clinics, pharmacies, and suppliers—address financial leakage and operational inefficiencies. We understand the day-to-day challenges these organizations face, and we believe the losses they experience are both reversible and preventable.

HITRUST Certification

Current HITRUST i1 Certification Letter
Current HITRUST i1 Certification Letter (with scope)

SpendMend Policies

Access Control Policy
Acceptable Use Policy
This policy documents the requirements for acceptable use of all SpendMend resources.
Backup Policy

This policy documents the requirements for backs of all SpendMend resources.

Change Management Policy
This policy establishes a framework to ensure that all SpendMend system changes are documented, reviewed, approved, and communicated.
Data Management Policy

This policy defines the data classification taxonomy at SpendMend.

Incident Management Policy

This policy establishes a framework and supporting procedures for responding to incidents.

Information Security Incident Management Policy

This policy provides a framework and supporting procedures concerning information security incident management.

Password Policy
This policy specifies guidelines for the construction and use of passwords.
Risk Management Policy

This policy provides a framework for managing risk.

Third-Party Risk Management Policy

This policy establishes methods by which SpendMend will manage security risks that are introduced by third parties, including contracted vendor service providers and partners.

Vulnerability Management Policy

This policy provides a framework to ensure the organization monitors systems and applications for vulnerabilities and remediates vulnerabilities in a timely manner.

Penetration Tests

SpendMend Penetration Test
Rebate Insight Penetration Test
Trulla Direct Penetration Test
Trulla Pro Penetration Test