Privacy
Does SpendMend sign Business Associate Agreements (BAAs)?
Yes, SpendMend signs Business Associate Agreements (BAAs) with covered entities and other applicable partners in accordance with the Health Insurance Portability and Accountability Act (HIPAA). We recognize the importance of clearly defining our responsibilities when handling Protected Health Information (PHI) and are fully committed to maintaining the privacy and security of that data. BAAs outline the safeguards we have in place and affirm our compliance with HIPAA requirements, including administrative, physical, and technical protections. We are happy to provide a standard BAA upon request as part of the onboarding or diligence process
How long will you retain my data?
SpendMend retains customer data only for as long as necessary to fulfill the purposes for which it was collected, including providing services, meeting contractual obligations, and complying with applicable legal, regulatory, or audit requirements. Retention periods may vary depending on the nature of the data and the terms of our agreement with each client. Once data is no longer needed, it is securely deleted in accordance with our data retention and disposal policies. If you have specific retention requirements or would like to discuss our data lifecycle practices further, please contact our team at security@spendmend.com.
Where is SpendMend data hosted?
SpendMend data is hosted exclusively in the United States within secure, enterprise-grade data centers provided by Microsoft Azure or Amazon AWS. Our cloud infrastructure is designed for high availability, scalability, and security, leveraging built-in compliance, monitoring, and physical protections. All data remains within U.S. borders to align with regulatory requirements and client expectations around data residency and sovereignty.
Does SpendMend transfer data across borders?
No, SpendMend does not transfer customer data across borders. All data is securely stored and processed within the United States in our U.S.-based data centers. We do not utilize international data storage or processing services, and we ensure that all data remains within U.S. jurisdiction to maintain compliance with domestic regulatory requirements and to support our clients’ data residency expectations. This approach helps minimize cross-border risk and reinforces our commitment to data privacy and security.
What personal information does SpendMend collect?
SpendMend only collects personal information that is necessary to deliver our services, and we take a data minimization approach to ensure we gather no more than required. Depending on the specific service, we typically do not collect Protected Health Information (PHI). However, if PHI is encountered during the data collection process, it is reviewed and redacted to protect individual privacy. All data is securely stored using strong encryption and access controls, and we retain it only for the duration allowed by our contractual agreements. Our practices are designed to uphold data confidentiality, meet regulatory standards, and support our clients’ compliance obligations.
Where can I find the SpendMend Privacy Page?
The SpendMend Privacy Page can be accessed from the “About Us” page. https://spendmend.com/about-us/
The Privacy Policy: https://spendmend.com/spendmend-privacy-policy/
The California Consumer Privacy Act page: https://spendmend.com/california-consumer-privacy-act/
Security
Do you support Single Sign-On (SSO)?
Yes, SpendMend supports Single Sign-On (SSO) and can integrate with a client’s Identity Provider (IdP) using the SAML 2.0 protocol. This allows organizations to manage user authentication centrally, enhancing security and simplifying access management. By supporting SSO, we help reduce password fatigue, improve user experience, and align with enterprise security policies and compliance requirements.
Do you encrypt data at rest and in transit?
Yes, SpendMend encrypts all data both at rest and in transit. We use industry-standard encryption protocols, including AES-256 for data at rest and TLS 1.2 or higher for data in transit. These encryption measures help ensure the confidentiality and integrity of sensitive information throughout its lifecycle, aligning with best practices and regulatory requirements for data protection.
How quickly do you patch critical vulnerabilities?
SpendMend follows a risk-based vulnerability management process to ensure timely remediation of security issues. All vulnerabilities are prioritized and typically patched depending on severity and potential impact. We continuously monitor for threats using automated tools and industry threat intelligence feeds, and we work closely with our infrastructure and development teams to deploy fixes swiftly while minimizing disruption. This rapid response helps protect our systems and data and demonstrates our proactive approach to maintaining a secure environment.
What’s your incident notification policy?
SpendMend has a documented incident management policy that outlines clear procedures for detection, communication, escalation, and resolution of security incidents. In the event of a data breach or security event, we follow a structured breach management process that includes prompt internal investigation, containment, and notification to affected stakeholders in accordance with applicable laws and contractual obligations. To ensure readiness, we conduct regular tabletop exercises that simulate various incident scenarios, allowing our teams to test and refine our response protocols. This proactive approach ensures that we can respond quickly and effectively to protect our systems, data, and clients.
Miscellaneous
What compliance and monitoring is in place?
SpendMend maintains a comprehensive compliance and monitoring program designed to protect sensitive data and support regulatory requirements. We operate with mature internal controls, including annual security training for all employees, regular user access reviews, and continuous evaluation of our security posture. Additionally, SpendMend holds an annual HITRUST i1 certification, which validates that we meet a robust set of security and privacy controls aligned with leading frameworks such as NIST and HIPAA. This certification, combined with our internal monitoring practices, demonstrates our ongoing commitment to safeguarding information and ensuring operational resilience.
How does SpendMend security posture reduce your risk?
SpendMend’s security posture is designed to significantly reduce risk for our clients by combining strong technical safeguards, rigorous compliance practices, and a culture of security awareness. We host our solutions in secure U.S.-based Azure or AWS environments and implement robust controls such as AES-256 encryption, TLS 1.2+, Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Role-Based Access Control (RBAC) to tightly govern access to data. Our annual HITRUST i1 certification demonstrates adherence to leading security standards, while independent penetration testing and continuous monitoring of access and system activity ensure threats are identified and addressed proactively. By aligning with regulatory expectations and industry best practices, we help our clients minimize third-party risk and reduce the burden of vendor security due diligence.
Why hospitals and GPOs choose SpendMend?
Hospitals and Group Purchasing Organizations (GPOs) choose SpendMend because of our deep expertise in healthcare financial optimization, our proven track record of delivering measurable value, and our unwavering commitment to data security and compliance. We understand the unique operational, regulatory, and privacy challenges faced by healthcare organizations and tailor our solutions to meet those needs. Our secure, U.S.-based platform is backed by industry-recognized certifications such as HITRUST i1, and we maintain strict safeguards for Protected Health Information (PHI), including encryption, redaction processes, and HIPAA-aligned practices. Beyond technology, clients value our collaborative approach, our transparency during security and compliance reviews, and the confidence that comes from partnering with a vendor who understands the critical importance of trust in healthcare.
