Security & Zero-PHI evidence
We never see your patients' data, and you can prove it
Hypex receives PHI to do the work, as a Business Associate under HIPAA, and destroys it on a clock. What never happens: PHI reaching our database, our model, or a stored letter. That is an architectural fact you can test, not a promise.
Patient records kept: 0Vault lifetime: 24 hours, hard limitBreach notice deadline: 60 daysConformance checks: public
PHI never reaches our database
Raw identifiers live in a 24-hour self-destructing vault only while a claim is being worked, then they are gone. What we retain afterward is exactly what billing requires: payer, codes, amounts, dates. Never a name, date of birth, medical record number, or address. Your biller re-attaches identity at the payer portal or fax step, which stays on your side.
The model never sees PHI
Multiple independent filters strip names, locations, ID numbers, and other identifiers from everything that persists. If a filter cannot run, the pipeline stops rather than risk exposure. Nothing is stored until it passes inspection.
Every decision is verifiable
From intake to payment, every action on every claim is permanently recorded. Records are tamper-evident: any alteration is visible and alertable. Your team can inspect the complete history at any time.
You can test us, not trust us
Our zero-PHI conformance suite is public. It fires fake identifier-shaped data at our live system and verifies nothing comes back out. Your team runs it (today, next quarter, unannounced) and attaches the results to your security review.
Data flow
Where PHI touches, and for how long
1 · Arrives
T+0Your denial file or feed arrives. Raw identifiers exist only long enough to be removed.
2 · De-identifies
secondsNames, dates of birth, and record numbers are stripped automatically. Only billing codes and amounts continue.
3 · Works & purges
minutesAll the work (root cause, drafting, your review) happens with no patient data present. Identifiers are destroyed as soon as they are no longer needed.
4 · Nothing persists
guaranteedThere is no patient-data archive to breach, subpoena, or misplace. What was not destroyed in use was never kept.
Procurement checklist
Control commitments
The table your IT/security team asks for. Every row is enforced in code, not policy documents.
Data residency
Isolated dedicated infrastructure behind Cloudflare's global edge: single-tenant by deployment, not shared cloud. Dedicated US-region deployment available for enterprise clients.
enforced in deployment configEncryption
TLS 1.2+ in transit; encrypted at rest for the vault and letter storage.
TLS + at-rest encryptionPHI retention
Identifiers sit in a 24-hour self-destructing vault only while we work a claim, then are destroyed. Letters are drafted de-identified from codes, amounts, and dates; identity re-attaches only at your own submission step.
auto-destructionAudit
Every action is permanently recorded in a tamper-evident history. Any alteration breaks the record visibly. Audit events are exportable as CSV on demand.
tamper-evidentAccess control
Every client's data is fully isolated from every other's. Team members see only what their role requires; system access is locked down and monitored.
isolation + least privilegeBreach response
Breach-response runbook with a 24-hour escalation line. Covered entities are notified without unreasonable delay, and no later than 60 calendar days after discovery, per 45 CFR 164.410 and the BAA.
45 CFR 164.410BAA
Business Associate Agreement executed with each customer before any PHI is processed: ours (8 elements per 164.504(e)) or yours, which we review and sign.
45 CFR 164.504(e)Model data path
AI features never receive patient identifiers. If the safety filter cannot run, the feature stops rather than risk exposure. No patient data is ever used for training.
fail-closed boundarySubmission safety
Every outbound claim is checked for completeness before sending, and the same appeal can never be submitted twice.
validation gatesBreach response procedure
If something goes wrong
Documented runbook enforced by our incident-response system.
Detection
Our monitoring alerts on any unauthorized read of vault or database objects, and the vault self-destructs on a 24-hour clock regardless.
Containment
Affected container is frozen and rotated; all service tokens in scope are revoked automatically.
Assessment
Forensics team determines whether any PHI was exposed. Because identifiers are destroyed at ingestion, scope is typically zero.
Notification
Covered entities are notified without unreasonable delay, and no later than 60 calendar days after discovery, per 45 CFR 164.410.
Remediation & report
Root cause fixed, written report delivered, and a post-incident review published internally. A copy is provided to affected customers on request.
Verify it yourself
Run the conformance suite against us
Our zero-PHI conformance suite is public. It fires synthetic identifier-shaped probes at a running Hypex instance and asserts nothing leaks back, then checks the de-identification engine and the fail-closed boundary gate directly. Your security team can run it against our production instance today, and re-run it quarterly, unannounced.
Clone the suite
One link, no credentials, no setup call. Built to run without us in the room.
Point it at us
One flag: --base-url https://api.hypexrcm.com. Black-box probes run immediately.
Read the verdict
A PASS/FAIL report with per-check detail, safe to attach to your security review.
What we are not (yet), and exactly what changes it
- SOC 2 Type II: examination in progress. The controls it tests run in production today; we provide the control matrix above and the audit timeline on request.
- Penetration test: scheduled before any hospital-direct production go-live. Micro-RCM and clinic deployments run on the same hardened stack meanwhile.
- US entity: formed when the first client requires it (it is revenue-gated, not calendar-gated). Until then the BAA is signed by the registered entity with a W-8BEN on file.