Compliance and security

Compliance handled. Data protected.

Membership plans come with state and federal rules, and patient data comes with serious responsibility. Clerri builds both into the platform, from DMPO licensure to HIPAA, PCI DSS, and SOC 2, so your team can stay focused on patient care.

The regulatory landscape

Why membership compliance is hard to do alone

Running a membership plan means meeting real regulatory obligations. We built the platform with compliance and security at its core, so your practice does not carry that burden by itself.

Varying state laws

36 states regulate Discount Medical Plan Organizations (DMPOs), and the rules differ from state to state. For practices operating in more than one state, that patchwork gets confusing fast.

Consumer protection

State rules exist to make sure members receive the benefits they pay for. Falling short can bring legal and financial penalties and put your reputation and revenue at risk.

Federal oversight

Beyond state law, practices also answer to federal requirements such as HIPAA, which governs how patient data is stored, shared, and protected.

Handled for you

How Clerri protects your practice

Compliance is not an add-on or an afterthought. It is how the platform is built.

Compliant in all 50 states

Clerri membership plans are built to comply with applicable laws in every state, including DMPO licensure in all 36 states that require it.

Dedicated expertise

Our compliance team monitors the regulatory landscape continuously, so the platform and your plan keep pace with the latest legal requirements.

Built-in safeguards

Plan agreements, marketing materials, and member communications come ready-made and compliant, so you are not researching regulations or drafting legal language yourself.

Standards we meet

Licensed, attested, and audited

Clerri membership plans are built to meet state and federal requirements, and the platform is held to recognized security standards.

Visit the Clerri Trust Center
  • DPO
  • DMPO
  • Knox-Keene
  • HIPAA
  • PCI
  • SOC 2
The stakes

Patient data is a target

Data breaches are a growing threat across healthcare. A single incident can erode patient trust, bring heavy fines, and disrupt your practice. Protecting personal, financial, and health information is our top priority.

Rising cyberattacks

Healthcare operations are a prime target for cybercriminals, and attacks keep climbing. Enterprise-grade security helps protect your practice and your patients.

HIPAA and PCI DSS

Practices are responsible for patient health information under HIPAA and for payment data under PCI DSS. The platform is built to both standards.

Severe consequences

A single breach can mean heavy financial penalties, lasting reputational damage, and the cost of covering fraudulent charges.

Our commitment

Security that runs all day, every day

Protection is layered into the platform, from encryption to monitoring to the infrastructure underneath.

End-to-end encryption

Data is encrypted in transit and at rest, so information moving through or stored in our systems stays unreadable to unauthorized parties.

Continuous monitoring

A full-time Security Officer, real-time security monitoring, threat detection, and regular vulnerability assessments catch new threats early.

Secure infrastructure

Firewalls, intrusion detection, and secure networks safeguard your data. Clerri holds SOC 2 Type I attestation, with Type II scheduled to conclude in July 2026.

Questions

Compliance and security FAQs

Is Clerri compliant in my state?

Clerri membership plans are built to comply with applicable laws in all 50 states. That includes DMPO licensure in all 36 states that regulate Discount Medical Plan Organizations, plus frameworks like Knox-Keene where they apply.

What does Clerri handle for us?

Clerri provides compliant plan agreements, marketing materials, and member communications, and our compliance team monitors the regulatory landscape continuously so your plan keeps pace with the latest legal requirements. You are not researching membership regulations or drafting legal language yourself.

What security standards does the platform meet?

The platform is built to HIPAA and PCI DSS standards, protects data in transit and at rest with end-to-end encryption, and holds SOC 2 Type I attestation, with Type II scheduled to conclude in July 2026.

Who watches for new threats?

Clerri employs a full-time Security Officer and runs real-time security monitoring, threat detection, and regular vulnerability assessments, so new threats are addressed proactively rather than after the fact.

Compliance you never have to think about.

See how Clerri builds regulatory compliance and enterprise-grade security into the membership platform. Request a 15-minute walkthrough, no obligation.

Request a 15-minute walkthrough
Compliant in all 50 statesHIPAA and PCI DSS standardsSOC 2 attested

Membership plans are not insurance.