Nemira
Pricing
Sign inSign upBook a demo
Sign inSign up
Nemira

The clinic OS for cash-pay practices. Charting, scheduling, packages, payments, and patient financing in one place.

✦HIPAA-eligible
Platform
  • Charting & SOAP
  • Scheduling
  • Payments & invoicing
  • Packages & memberships
  • Patient financing
  • SMS & broadcasts
  • Reporting & QuickBooks
For
  • Chiropractic
  • Medspa & Aesthetics
  • Dental
  • Wellness & IV
Resources
  • Pricing
  • Our promises
  • Refund policy
  • Security
  • Integrations
  • Customer stories
  • FAQ
Company
  • About
  • Contact
  • Sign in
  • Create account
  • Privacy
  • Terms

Nemira is a software platform for cash-pay clinics. It does not provide medical advice. Treatment outcomes vary by provider, procedure, and individual case.

Financing offers shown in the platform are estimates and do not represent loan approvals. Actual rates, terms, and approvals are subject to lender review and applicable law.

© 2026 NEMIRA

Security

Built for the data your patients trust you with.

HIPAA-eligible infrastructure, encrypted data at rest and in transit, audit logs on every clinical action. Built with HIPAA-aware workflows for the security reviews that come with real revenue.

Encryption and storage

Patient data, encrypted by default.

Patient data is encrypted at rest across the database, file storage, and backups with AWS-managed AES-256, and in transit with TLS 1.3. Stored third-party credentials, like payment and accounting tokens, get an additional layer of application-side encryption and are never exposed to the browser.
  • Encrypted at rest in Aurora Postgres (AWS-managed AES-256)
  • TLS 1.3 in transit
  • Card details tokenized by Stripe, never stored on Nemira
  • Private file uploads in Amazon S3, encrypted at rest
patients.row · production
Encrypted
patient.full_name
0xA8 92 4F 17 . . .
Encrypted at rest
patient.dob
0x21 7B 9C 03 . . .
Encrypted at rest
patient.email
0xC4 11 8D 2A . . .
Encrypted at rest
note.soap.body
0x9F 6E 04 BB . . .
Encrypted at rest
payment.last4
**** **** **** 4242
Tokenized via Stripe
Encrypted at rest in AWS · AWS-managed keys Verified

Audit log

Every clinical action, recorded.

Every action that touches a patient record writes an audit log entry. Sign-offs, edits, exports, logins, and force-edits all leave a trail. PII is auto-scrubbed from metadata before write.
  • Every clinical action recorded
  • PII auto-scrubbed in metadata
  • Filterable and exportable
  • Retained at least 13 months
Audit log entry
2026-05-12 09:14:02 UTC
actionappointment.note_signed
actorDr. K. Walters (provider_user · 0x7C2A)
entitypatient.note · note_id 0x91FF
ip71.204.18.42
user_agentNemira iOS 1.4.2 · iPhone 15 Pro
metadata{ template: 'chiro_v2', duration_ms: 84120, redacted: true }
PII auto-scrubbed before write Retained 7y

Infrastructure

HIPAA-eligible infrastructure, top to bottom.

BAA status shown by vendor for every sub-processor that touches PHI. SOC 2 Type II audit planned. Technical safeguards documented and reviewed every quarter.
  • AWS and Fly.io BAAs executed, covering all PHI storage and compute
  • SOC 2 Type II audit planned
  • HIPAA technical safeguards documented
  • BAA available on Growth and Enterprise
HIPAA

Eligible

SOC 2

Type II · planned

BAA

Available on Growth+

US-only

Data residency

Posture

Six controls that matter at security review.

AES-256 encryption

At rest across the database, file storage, and backups, with AWS-managed keys.

TLS 1.3 in transit

All client and inter-service traffic uses modern TLS only.

Audit logs

Every clinical action recorded. PII scrubbed. Retained 13 months.

Role-based access

Provider, practitioner, front desk, admin. Permissions enforced server-side.

SSO

SAML and OIDC support shipping Q4 on the Enterprise tier.

2FA support

TOTP and recovery codes available today. WebAuthn next.

Sub-processors

The full list, who touches what.

No hidden vendors. Every party that handles PHI is named here, with the role they play and BAA status shown by vendor.

Sub-processorRoleRegionBAA
Amazon Web ServicesDatabase (Aurora), storage (S3), email (SES), AI (Bedrock + Transcribe)US (us-east-2)Executed
Fly.ioApplication hosting and computeUS (iad)Executed
TelnyxSMS and 10DLC messagingUSPending
StripeCard payments and Connect payoutsUSNot required
Intuit QuickBooksAccounting sync (invoices, payments)USNot required
SentryError monitoring (PII scrubbed)USNot required
UpstashRate limiting (IPs and counters)USNot required

✦ Patient data never leaves US borders by default

Executed = signed BAA. Pending = BAA in process; patient SMS goes live once it is signed. Not required = the vendor does not receive PHI.

Compliance

Security review coming up?

We respond to security questionnaires and BAA requests inside one business day. Most clinics clear review on the first pass.

Request a BAASee trust center