Intelligent Healthcare

Security & PHI

Your 835s are PHI. We treat them that way from the first byte.

Remittance files carry protected health information, so handling them is the whole job — not an afterthought. Here is exactly how your data is protected, in plain terms, before you send us anything.

Agreement firstBefore any file moves

A Business Associate Agreement is signed before a single file is transferred — we operate as your business associate under HIPAA, with the obligations that carries. A mutual NDA is available alongside it. No BAA, no data.

Encrypted in transitHow files travel

Files move as password-protected, AES-256 encrypted archives or through your own secure file-share — never as plain email attachments. The password travels on a separate channel from the file.

Minimum necessaryPHI-minimized drafting

Appeal letters are drafted with the least PHI necessary to make the case. De-identified data is used wherever the argument doesn't require identifiers, in line with the HIPAA minimum-necessary standard.

A human decidesNothing files itself

Every appeal is reviewed and approved by a named person on your staff before it is filed. Each filed packet carries a Certification of Human Review recording who approved it and when — the software never submits to a payer on its own.

Full audit trailAccountable by design

Every action — ingest, draft, edit, approval, filing, recovery match — is logged and attributable. Access is authenticated and role-scoped, and the record is available to you.

Your data, returnedOn request or at termination

Your files and PHI remain yours. On request or when an engagement ends, data is returned or securely destroyed per the BAA — we don't retain what we no longer need.

Where we stand today — stated plainly.

  • BAA executed before any data transfer
  • AES-256 encryption for files at rest and in transit
  • Appeal drafting runs offline against your files by default
  • Human approval gate on 100% of filed appeals
  • Attributable audit log across the whole pipeline
  • SOC 2 Type I preparation underway

We describe our posture honestly and won't claim certifications we don't yet hold. Ask us anything specific — we'd rather answer a hard security question now than after you've sent a file.

Straight answers

Do you sign a BAA?

Yes — always, and before any file moves. We can send our template for your counsel to review, or work from yours.

Where does our data live, and who can see it?

Your files are processed for the purpose of the analysis and appeals only, under access that is authenticated and role-scoped. We apply the minimum-necessary standard, and we return or destroy your data on request or at the end of the engagement.

Does an AI read our patients' records?

The denial analysis and drafting run deterministically against the structured remittance data and the documentation you provide. Drafting is PHI-minimized, and no appeal is filed without a named human on your staff approving it first.

What if we want to stop?

Your data is returned or securely destroyed per the BAA, and you keep every report and letter already produced. There's no lock-in — the pilot is designed to prove itself or end cleanly.

Have a security question before you send anything? Good — ask it first.

Email us a security question