Built for PHI from the first line of code.

ClaimworksIQ is built to the safeguards of the HIPAA Security Rule and engineered to SOC 2 Type II control standards, with a formal audit scheduled. Your records are contractually barred from any foundation-model training set.

Every layer, documented.

HIPAA & HITECH

Signed BAA with every covered entity and business associate. Minimum-necessary access and a tamper-evident, hash-chained audit log.

Built to SOC 2 Type II

Engineered to SOC 2 Type II control standards for security, availability, and confidentiality. Formal audit scheduled.

Zero-training guarantee

Your records are never used to train foundation models. Contractual, not just operational.

US-only data residency

Primary and replica infrastructure hosted entirely in US regions. All data encrypted at rest using AES-256 with AWS-managed keys under BAA.

Encryption

AES-256 at rest with AWS-managed keys, and TLS in transit.

Access

Multi-factor authentication on every account, and role-based access scoped by matter.

Security questions we always get.

Do you sign a BAA before production use?
Yes, BAA execution is part of the signup flow for covered entities and business associates. No PHI moves without one on file.
Who has access to my records inside ClaimworksIQ?
Only the users you invite to each matter. Anyone who works on ClaimworksIQ reads PHI only with a documented operational need, and every access is logged.
Are my records used to train any model?
Never. Zero-training is contractual with every model provider we use.
What happens on account closure?
You export everything, matter binders, transcripts, citations, as paginated PDFs and JSON. After your stated retention window expires, records are deleted from active systems, with backup expiration following our documented retention policy.