ClaimworksIQ is built to the safeguards of the HIPAA Security Rule and engineered to SOC 2 Type II control standards, with a formal audit scheduled. Your records are contractually barred from any foundation-model training set.
Signed BAA with every covered entity and business associate. Minimum-necessary access and a tamper-evident, hash-chained audit log.
Engineered to SOC 2 Type II control standards for security, availability, and confidentiality. Formal audit scheduled.
Your records are never used to train foundation models. Contractual, not just operational.
Primary and replica infrastructure hosted entirely in US regions. All data encrypted at rest using AES-256 with AWS-managed keys under BAA.
AES-256 at rest with AWS-managed keys, and TLS in transit.
Multi-factor authentication on every account, and role-based access scoped by matter.