Security & Privacy

Responsible use of the CMS Nexus website and sePractical responsibilities for protecting business information.rvices.

Website and account access

Use the secure sign-in address supplied during onboarding. The general website form is not an account sign-in screen and should never receive passwords, payment-card details, or sensitive regulated records. Our website code keeps the Software and Marketing inquiry paths distinct.

Shared responsibility

Businesses should assign individual user access, apply appropriate permissions, review access when roles change, and protect devices and credentials. Customers remain responsible for the information they choose to process and the authorizations needed to do so.

Integration review

Before activating an integration, confirm its purpose, permissions, data fields, account owner, and removal process. Feature availability and security requirements depend on the selected services and configuration. Discuss specialized data-handling requirements before importing data.

No unverified certifications

This page does not claim SOC 2, HIPAA, ISO, or other certification or regulatory suitability for CMS Nexus. Ask for relevant evidence and contractual commitments when a specific standard matters to your organization.

Reporting a concern

Use your established support channel or the contact page to describe a suspected security issue, including the affected page and general behavior. Do not include credentials or unnecessary personal information. Do not access another person’s data, disrupt service, or continue exploitation to demonstrate a concern.

Related policies

The Privacy Policy describes website information handling. The Acceptable Use Policy covers authorized behavior. Contracted service security, retention, recovery, and support requirements should be stated in the applicable agreement.