Hypex

Security & Zero-PHI evidence

We never see your patients' data, and you can prove it

Hypex receives PHI to do the work - as a Business Associate under HIPAA - and destroys it on a clock. What never happens: PHI reaching our database, our model, or a stored letter. That is an architectural fact you can test, not a promise.

Patient records kept

0

Data destruction

within minutes

Breach notice deadline

60 days

Conformance checks

public

PHI never reaches our database

Raw identifiers are destroyed within minutes of use - automatically. What we retain afterward is exactly what billing requires: payer, codes, amounts, dates. Never a name, date of birth, medical record number, or address.

The model never sees PHI

Multiple independent filters strip names, locations, ID numbers, and other identifiers from everything that persists. If a filter cannot run, the pipeline stops rather than risk exposure. Nothing is stored until it passes inspection.

Every decision is verifiable

From intake to payment, every action on every claim is permanently recorded. Records are tamper-evident: any alteration is visible and alertable. Your team can inspect the complete history at any time.

You can test us, not trust us

Our zero-PHI conformance suite is public. It fires fake identifier-shaped data at our live system and verifies nothing comes back out. Your team runs it - today, next quarter, unannounced - and attaches the results to your security review.

Data flow

Where PHI touches, and for how long

1 · Arrives

T+0

Your denial file or feed arrives. Raw identifiers exist only long enough to be removed.

2 · De-identifies

seconds

Names, dates of birth, and record numbers are stripped automatically. Only billing codes and amounts continue.

3 · Works & purges

minutes

All the work - root cause, drafting, your review - happens with no patient data present. Identifiers are destroyed as soon as they are no longer needed.

4 · Nothing persists

guaranteed

There is no patient-data archive to breach, subpoena, or misplace. What was not destroyed in use was never kept.

Procurement checklist

Control commitments

The table your IT/security team asks for. Every row is enforced in code, not policy documents.

Data residency

Hosted in a US data center (Kansas City, MO) behind Cloudflare. PHI never leaves US infrastructure.

Encryption

TLS 1.2+ in transit; encrypted at rest for the vault and letter storage.

PHI retention

Patient identifiers self-destruct within minutes of use, and never persist anywhere. The deadline is enforced by the system itself.

Audit

Every action is permanently recorded in a tamper-evident history. Any alteration breaks the record visibly. Export anything, any time.

Access control

Every client’s data is fully isolated from every other’s. Team members see only what their role requires; system access is locked down and monitored.

Breach response

Notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery, per 45 CFR 164.410 and the BAA.

BAA

Business Associate Agreement executed with each customer before any PHI is processed - ours (8 elements per 164.504(e)) or yours, which we review and sign.

Model data path

AI features never receive patient identifiers - if the safety filter cannot run, the feature stops rather than risk exposure. No patient data is ever used for training.

Submission safety

Every outbound claim is checked for completeness before sending, and the same appeal can never be submitted twice.

Verify it yourself

Run the conformance suite against us

Our zero-PHI conformance suite is public. It fires synthetic identifier-shaped probes at a running Hypex instance and asserts nothing leaks back, then checks the de-identification engine and the fail-closed boundary gate directly. Your security team can run it against our production instance today - and re-run it quarterly, unannounced.

1

Clone the suite

One link, no credentials, no setup call - built to run without us in the room.

2

Point it at us

One flag: --base-url https://api.hypexrcm.com. Black-box probes run immediately.

3

Read the verdict

A PASS/FAIL report with per-check detail, safe to attach to your security review.

Get the suite link Re-run it whenever you like. A failing check is a reportable bug.

What we are not (yet) - and exactly what changes it

  • SOC 2 Type II: examination in progress. The controls it tests run in production today; we provide the control matrix above and the audit timeline on request.
  • Penetration test: scheduled before any hospital-direct production go-live. Micro-RCM and clinic deployments run on the same hardened stack meanwhile.
  • US entity: formed when the first client requires it (it is revenue-gated, not calendar-gated). Until then the BAA is signed by the registered sole proprietorship with a W-8BEN on file.
Read the objections we get from CFOs →