Security · Updated October 6, 2026

Useful data. Clear boundaries.

FeeBase is a reimbursement reference tool. Here’s what belongs in it, how access is limited, and how to report a concern.

Keep patient information out

Lookups need procedure codes, practice locations, dates, and calculation settings. They do not need patient names, dates of birth, member IDs, medical records, or claim documents. Do not send protected health information through our forms or email.

FeeBase is not offered as a system for storing patient records. Do not assume a business associate agreement or a HIPAA compliance commitment applies to your use of the public service.

Access and abuse controls

Contact messages and access requests are available through restricted administrative screens. The application checks authentication and administrative permission before returning these records. Public submissions and lookup endpoints use rate limits to reduce abuse.

If you have an account, protect your credentials and notify us if you suspect unauthorized access. No online service can promise that every incident will be prevented.

Diagnostics with limited inputs

We use service diagnostics to investigate errors and performance. Browser replay, when enabled, is configured to mask text and form inputs and exclude account and administrative screens. These controls do not make it appropriate to enter confidential patient data.

Read the privacy policy

Report a security concern

Email us with “FeeBase security” in the subject. Include the affected page, what happened, and steps to reproduce using your own account or non-sensitive sample data. Do not send passwords, access tokens, or other people’s records.

[email protected]

Please avoid disruptive testing, accessing someone else’s data, or publishing sensitive details while we investigate. This reporting channel does not authorize security testing or establish a bug-bounty program.