HIPAA-compliant architecture, US data residency, and a BAA before anything moves. Here's exactly how, with nothing rounded up.
PHI stays in US-based systems. Our India-based team accesses it only through virtual desktops with copy, download, print, and USB transfer disabled — by policy and by technology, not just by rule. Every session is logged, so access to a record is always attributable to a specific person at a specific time.
We sign a Business Associate Agreement with every client before any PHI moves — ours or yours. The same requirement extends down our vendor chain: every subcontractor who could touch PHI signs a BAA too, and we maintain a register of every agreement in force.
Written privacy, security, and breach-notification policies (POL-01 through POL-14) govern how we operate. We run an annual security risk assessment, require workforce HIPAA training with signed attestations, and maintain an incident response plan that notifies affected clients within the timelines set in your BAA.
Some states restrict offshore handling of Medicaid or other state-program data — Florida, Wisconsin, Texas, Arizona, Ohio, Missouri, and New Jersey among them. We screen every engagement’s state and payer mix up front and carve out any restricted book of business before work begins, not after you ask.
Our AI never generates a billing code, a dollar amount, or a date of service. Deterministic software parses payer data first; AI assists with drafting and triage; a human reviews anything ambiguous. Every automated action is attributed and logged with the model version that produced it.
We are targeting SOC 2 Type I after our first client cohort, and our ISO 27001 program is underway in India. Neither is complete today — we’re telling you where we’re headed, not claiming a certification we don’t hold.
A written summary of everything on this page — architecture, BAAs, offshore screening, and our certification roadmap — for your compliance or legal review.
Request via Contact FormWith your permission, we use analytics and advertising services, including business visitor identification. Essential Only keeps these services off. Read our privacy policy.