Email InquirySchedule Meeting
Security & Compliance

How we protect your data — offshore, transparently

HIPAA-compliant architecture, US data residency, and a BAA before anything moves. Here's exactly how, with nothing rounded up.

HIPAA-compliant architecture BAA available US data residency

Data residency

PHI stays in US-based systems. Our India-based team accesses it only through virtual desktops with copy, download, print, and USB transfer disabled — by policy and by technology, not just by rule. Every session is logged, so access to a record is always attributable to a specific person at a specific time.

BAAs

We sign a Business Associate Agreement with every client before any PHI moves — ours or yours. The same requirement extends down our vendor chain: every subcontractor who could touch PHI signs a BAA too, and we maintain a register of every agreement in force.

HIPAA program

Written privacy, security, and breach-notification policies (POL-01 through POL-14) govern how we operate. We run an annual security risk assessment, require workforce HIPAA training with signed attestations, and maintain an incident response plan that notifies affected clients within the timelines set in your BAA.

Offshore restrictions

Some states restrict offshore handling of Medicaid or other state-program data — Florida, Wisconsin, Texas, Arizona, Ohio, Missouri, and New Jersey among them. We screen every engagement’s state and payer mix up front and carve out any restricted book of business before work begins, not after you ask.

AI governance

Our AI never generates a billing code, a dollar amount, or a date of service. Deterministic software parses payer data first; AI assists with drafting and triage; a human reviews anything ambiguous. Every automated action is attributed and logged with the model version that produced it.

Roadmap

We are targeting SOC 2 Type I after our first client cohort, and our ISO 27001 program is underway in India. Neither is complete today — we’re telling you where we’re headed, not claiming a certification we don’t hold.

Request our Security One-Pager and Offshore FAQ

A written summary of everything on this page — architecture, BAAs, offshore screening, and our certification roadmap — for your compliance or legal review.

Request via Contact Form

Cookie preferences

With your permission, we use analytics and advertising services, including business visitor identification. Essential Only keeps these services off. Read our privacy policy.