Skip to content

Security

What we hold, and what we deliberately do not.

Most tools in healthcare lead with a compliance badge. Here is the plain version instead, so you can check it against what the product actually does.

Why Quemra does not need a BAA

A Business Associate Agreement is required when a vendor creates, receives, maintains, or transmits protected health information on behalf of a covered entity. Quemra does none of those things. It works on the public federal provider registry and on outreach you write to other businesses. No patient information enters the system, so there is no protected health information for a BAA to govern.

That is a real answer, not a loophole. If your compliance officer asks, the accurate description is: a business contact directory and outreach tool, in the same category as a mailing list, that operates strictly on publicly published practice data.

If Quemra ever adds a feature that touches patient data, this page changes first and you will be told before it ships.

What Quemra stores

Public provider directory data
Names, practice addresses, specialties, and NPI numbers sourced from the federal NPPES registry, which is published by CMS and free for anyone to download. This is business contact information about practices, not information about patients.
Your account
Your email address and sign-in sessions. There is no password to store, because sign-in uses a one-time code sent to your inbox.
Your outreach
The messages you send through Quemra, their delivery and open status, and the pipeline stage and notes you attach to each provider.
Your mailbox connection
If you connect Gmail, the OAuth tokens that let Quemra send on your behalf. They are encrypted at rest with AES-256-GCM before they touch the database, and you can disconnect at any time from your account settings.
Your billing reference
A Stripe customer ID and subscription ID. Card numbers are entered on Stripe's own checkout and are never sent to or stored by Quemra.

What Quemra never touches

No patient or client records
Quemra has no concept of a patient. There is no field, table, or import path for client names, diagnoses, dates of service, insurance member IDs, or clinical notes. Please do not type patient information into provider notes; the product is not built to hold it.
No card numbers
Payment details are handled entirely by Stripe. Quemra never sees them.
No mailbox scraping
The Gmail connection is scoped to sending your outreach and reading replies to it. Quemra does not index or store the rest of your inbox.
No selling or sharing your lists
Your saved searches, pipeline, and notes are yours. They are not pooled, resold, or used to build a product for anyone else.

How outreach stays lawful

Every message sent through Quemra carries your practice’s physical mailing address and a working one-click opt-out, which is what CAN-SPAM requires of commercial email. Opt-outs are honored automatically and permanently: an address that unsubscribes is added to your suppression list and cannot be contacted again from your account, including by a later bulk send.

Subject lines must describe the message honestly. Quemra rejects templates that fake a reply thread with a leading “Re:” or “Fwd:”, because deceptive subject lines are exactly what state email statutes penalize.

Quemra will never offer a feature that pays, rewards, or gives anything of value to a referral source. Doing so is a crime under the federal Anti-Kickback Statute and under state all-payer laws. An introduction is marketing; a payment is a felony, and the line between them is not one we will blur.

Access and deletion

You can export your saved providers and pipeline at any time, and you can delete your account from your account data settings. Deletion removes your account, outreach history, saved searches, notes, and mailbox connection within 24 hours.

Full detail on retention and third-party processors is in the Privacy Policy. If something here is unclear or you need it in writing for a procurement review, ask and you will get a straight answer.