HIPAA Privacy and Security Rule compliance
Our RCM operations are designed and audited to comply with all applicable HIPAA Privacy and Security Rule requirements, including appropriate use and disclosure of PHI, minimum necessary standards, and safeguards for electronic health information.
Responsible AI and regulatory alignment
The use of AI on our platform is governed by applicable regulatory guidance and emerging industry standards for AI in healthcare. We are committed to ensuring that any AI-assisted capabilities used in RCM workflows are transparent and explainable and do not compromise patient privacy or data integrity.
PCI DSS compliance via certified clearinghouses and SAQ
Patient payment transactions are routed through PCI DSS-certified clearinghouses and payment partners, ensuring that cardholder data is handled by rigorously validated third-party infrastructure. We also maintain annual compliance as a service provider by completing a PCI DSS Self-Assessment Questionnaire, which validates that our processes, controls, and vendor relationships meet the full scope of PCI DSS requirements applicable to our role in the payment chain.
Privacy by design and patient rights
Privacy principles are embedded throughout our RCM platform's development lifecycle. We support healthcare providers in honoring patient rights under HIPAA — including the rights to access, amend, and restrict the use of their health and financial information
Independent audits and certifications
We undergo regular independent security assessments, including SOC 1 Type II audits, SOC 2 Type II audits, ISO 27001:2022, and HIPAA compliance reviews, to provide our healthcare clients with third-party validation of our controls and a transparent record of our compliance posture.