Hypex

Security & Zero-PHI evidence

We never see your patients' data, and you can prove it

Hypex receives PHI to do the work, as a Business Associate under HIPAA, and destroys it on a clock. What never happens: PHI reaching our database, our model, or a stored letter. That is an architectural fact you can test, not a promise.

Patient records kept: 0Vault lifetime: 24 hours, hard limitBreach notice deadline: 60 daysConformance checks: public

PHI never reaches our database

Raw identifiers live in a 24-hour self-destructing vault only while a claim is being worked, then they are gone. What we retain afterward is exactly what billing requires: payer, codes, amounts, dates. Never a name, date of birth, medical record number, or address. Your biller re-attaches identity at the payer portal or fax step, which stays on your side.

The model never sees PHI

Multiple independent filters strip names, locations, ID numbers, and other identifiers from everything that persists. If a filter cannot run, the pipeline stops rather than risk exposure. Nothing is stored until it passes inspection.

Every decision is verifiable

From intake to payment, every action on every claim is permanently recorded. Records are tamper-evident: any alteration is visible and alertable. Your team can inspect the complete history at any time.

You can test us, not trust us

Our zero-PHI conformance suite is public. It fires fake identifier-shaped data at our live system and verifies nothing comes back out. Your team runs it (today, next quarter, unannounced) and attaches the results to your security review.

Data flow

Where PHI touches, and for how long

1 · Arrives

T+0

Your denial file or feed arrives. Raw identifiers exist only long enough to be removed.

2 · De-identifies

seconds

Names, dates of birth, and record numbers are stripped automatically. Only billing codes and amounts continue.

3 · Works & purges

minutes

All the work (root cause, drafting, your review) happens with no patient data present. Identifiers are destroyed as soon as they are no longer needed.

4 · Nothing persists

guaranteed

There is no patient-data archive to breach, subpoena, or misplace. What was not destroyed in use was never kept.

Procurement checklist

Control commitments

The table your IT/security team asks for. Every row is enforced in code, not policy documents.

Data residency

Isolated dedicated infrastructure behind Cloudflare's global edge: single-tenant by deployment, not shared cloud. Dedicated US-region deployment available for enterprise clients.

Encryption

TLS 1.2+ in transit; encrypted at rest for the vault and letter storage.

PHI retention

Identifiers sit in a 24-hour self-destructing vault only while we work a claim, then are destroyed. Letters are drafted de-identified from codes, amounts, and dates; identity re-attaches only at your own submission step.

Audit

Every action is permanently recorded in a tamper-evident history. Any alteration breaks the record visibly. Audit events are exportable as CSV on demand.

Access control

Every client's data is fully isolated from every other's. Team members see only what their role requires; system access is locked down and monitored.

Breach response

Breach-response runbook with a 24-hour escalation line. Covered entities are notified without unreasonable delay, and no later than 60 calendar days after discovery, per 45 CFR 164.410 and the BAA.

BAA

Business Associate Agreement executed with each customer before any PHI is processed: ours (8 elements per 164.504(e)) or yours, which we review and sign.

Model data path

AI features never receive patient identifiers. If the safety filter cannot run, the feature stops rather than risk exposure. No patient data is ever used for training.

Submission safety

Every outbound claim is checked for completeness before sending, and the same appeal can never be submitted twice.

Breach response procedure

If something goes wrong

Documented runbook enforced by our incident-response system.

Detection

Our monitoring alerts on any unauthorized read of vault or database objects, and the vault self-destructs on a 24-hour clock regardless.

Containment

Affected container is frozen and rotated; all service tokens in scope are revoked automatically.

Assessment

Forensics team determines whether any PHI was exposed. Because identifiers are destroyed at ingestion, scope is typically zero.

Notification

Covered entities are notified without unreasonable delay, and no later than 60 calendar days after discovery, per 45 CFR 164.410.

Remediation & report

Root cause fixed, written report delivered, and a post-incident review published internally. A copy is provided to affected customers on request.

Verify it yourself

Run the conformance suite against us

Our zero-PHI conformance suite is public. It fires synthetic identifier-shaped probes at a running Hypex instance and asserts nothing leaks back, then checks the de-identification engine and the fail-closed boundary gate directly. Your security team can run it against our production instance today, and re-run it quarterly, unannounced.

1

Clone the suite

One link, no credentials, no setup call. Built to run without us in the room.

2

Point it at us

One flag: --base-url https://api.hypexrcm.com. Black-box probes run immediately.

3

Read the verdict

A PASS/FAIL report with per-check detail, safe to attach to your security review.

Get the suite link Re-run it whenever you like. A failing check is a reportable bug.

What we are not (yet), and exactly what changes it

  • SOC 2 Type II: examination in progress. The controls it tests run in production today; we provide the control matrix above and the audit timeline on request.
  • Penetration test: scheduled before any hospital-direct production go-live. Micro-RCM and clinic deployments run on the same hardened stack meanwhile.
  • US entity: formed when the first client requires it (it is revenue-gated, not calendar-gated). Until then the BAA is signed by the registered entity with a W-8BEN on file.
Read the objections we get from CFOs →