Trust & security

A real audit trail, not a marketing badge.

SOC 2 Type II compliant as of November 2024. Audit scope: Cloud Infrastructure & Data Handling.

ISO 27001 is in progress with target completion in Q4 2026.

AuthQuire extracts evidence, drafts packets, and maps payer requirements automatically, but final clinical approval, payer submission, and appeal decisions require human action.

Audit trail and reviewer approval artifacts for authorization review.
Scope

What AuthQuire does — and does not do.

What AuthQuire does
  • Reads charts, orders, and prior imaging your team grants access to.
  • Maps payer criteria to source evidence and flags missing items.
  • Assembles versioned, source-cited packets ready for staff review.
  • Drafts appeal letters and peer-to-peer briefs from chart evidence.
  • Logs every read, change, approval, and export.
What AuthQuire does not do
  • Submit to payers automatically — staff approves and submits.
  • Replace human authority: final clinical approval, payer submission, and appeal decisions require human action.
  • Make clinical or medical-necessity decisions.
  • Issue determinations or guarantee authorization outcomes.
  • Move PHI to systems outside the customer-approved boundary.
  • Train shared models on customer PHI.
Controls

How PHI is handled.

  • BAA available

    Business Associate Agreement signed with every customer handling PHI. Part of standard onboarding.

  • PHI access controls

    Roles include Admin, Reviewer, Read-Only (Billing), and System Auditor. MFA is mandatory for all user tiers, with Okta and Azure AD SSO support.

  • Encryption

    AES-256 at rest and TLS 1.2+ in transit. US-only data residency in AWS us-east-1.

  • Audit logs

    Audit logs cover data access events, PA packet modifications, and export events.

  • Human approval

    No packet leaves a workspace without a named reviewer's approval. Recorded on the receipt.

  • Subprocessors

    AWS (us-east-1) for hosting, Snowflake for analytics, and SendGrid for transactional email. Subprocessors handling PHI sign BAAs.

Human approval

Every packet has a named reviewer.

No packet leaves AuthQuire without a recorded approval. The receipt below is the kind of trail your compliance team and payer auditors actually want to see.

Reviewer receipt · exampleApproved
  • ReadChart pulled from connected EHR intake10:14
  • MatchPayer criteria mapped (4 / 4 met)10:15
  • EditReviewer added ROM measurements snippet10:17
  • ApproveSarah M., reviewer — packet v310:18
  • ExportPacket exported for staff submission10:19
Safeguards

What we claim — stated plainly.

Safeguards & boundaries
  • SOC 2 Type II

    SOC 2 Type II compliant as of November 2024. Audit scope: Cloud Infrastructure & Data Handling.

  • ISO 27001

    ISO 27001 is in progress with target completion in Q4 2026.

  • Encryption & residency

    AES-256 at rest and TLS 1.2+ in transit. US-only data residency in AWS us-east-1.

  • Model policy

    Customer data is not used for global model training. Anonymized dataset improvements are opt-in only.

  • BAA-supported workflows

    AuthQuire executes a Business Associate Agreement with customers handling PHI before PHI moves into the workspace.

  • No HIPAA certification

    HIPAA does not issue certifications, so AuthQuire never describes itself as HIPAA certified. Security questionnaires are answered directly.

  • Human authority boundary

    AuthQuire extracts evidence, drafts packets, and maps payer requirements automatically, but final clinical approval, payer submission, and appeal decisions require human action.

  • Confidence & escalation

    Confidence scores below 0.85 trigger mandatory human review. Reviewers can override AI-mapped evidence; original extraction remains in version history.

  • Retention & deletion

    Clinical data retention is 7 years where required by HIPAA/state mandates; audit logs are retained for 3 years. Permanent erasure via cryptographic wipe upon contract termination with a 30-day recovery window.

Response

Incident response and security contact.

Incident response

Documented playbook covering detection, containment, customer notification, and remediation. Critical breach notifications are targeted within 24 hours; operational disruption notifications within 48 hours.

  • Detect
  • Contain
  • Notify
Security contact

Reach the AuthQuire security team for BAAs, vulnerability disclosures, or compliance questions:

security@authquire.com