Security & Zero-PHI evidence
We never see your patients' data, and you can prove it
Hypex receives PHI to do the work - as a Business Associate under HIPAA - and destroys it on a clock. What never happens: PHI reaching our database, our model, or a stored letter. That is an architectural fact you can test, not a promise.
Patient records kept
0
Data destruction
within minutes
Breach notice deadline
60 days
Conformance checks
public
PHI never reaches our database
Raw identifiers are destroyed within minutes of use - automatically. What we retain afterward is exactly what billing requires: payer, codes, amounts, dates. Never a name, date of birth, medical record number, or address.
The model never sees PHI
Multiple independent filters strip names, locations, ID numbers, and other identifiers from everything that persists. If a filter cannot run, the pipeline stops rather than risk exposure. Nothing is stored until it passes inspection.
Every decision is verifiable
From intake to payment, every action on every claim is permanently recorded. Records are tamper-evident: any alteration is visible and alertable. Your team can inspect the complete history at any time.
You can test us, not trust us
Our zero-PHI conformance suite is public. It fires fake identifier-shaped data at our live system and verifies nothing comes back out. Your team runs it - today, next quarter, unannounced - and attaches the results to your security review.
Data flow
Where PHI touches, and for how long
1 · Arrives
T+0Your denial file or feed arrives. Raw identifiers exist only long enough to be removed.
2 · De-identifies
secondsNames, dates of birth, and record numbers are stripped automatically. Only billing codes and amounts continue.
3 · Works & purges
minutesAll the work - root cause, drafting, your review - happens with no patient data present. Identifiers are destroyed as soon as they are no longer needed.
4 · Nothing persists
guaranteedThere is no patient-data archive to breach, subpoena, or misplace. What was not destroyed in use was never kept.
Procurement checklist
Control commitments
The table your IT/security team asks for. Every row is enforced in code, not policy documents.
Data residency
Hosted in a US data center (Kansas City, MO) behind Cloudflare. PHI never leaves US infrastructure.
enforced in deployment configEncryption
TLS 1.2+ in transit; encrypted at rest for the vault and letter storage.
TLS + at-rest encryptionPHI retention
Patient identifiers self-destruct within minutes of use, and never persist anywhere. The deadline is enforced by the system itself.
auto-destructionAudit
Every action is permanently recorded in a tamper-evident history. Any alteration breaks the record visibly. Export anything, any time.
tamper-evidentAccess control
Every client’s data is fully isolated from every other’s. Team members see only what their role requires; system access is locked down and monitored.
isolation + least privilegeBreach response
Notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery, per 45 CFR 164.410 and the BAA.
45 CFR 164.410BAA
Business Associate Agreement executed with each customer before any PHI is processed - ours (8 elements per 164.504(e)) or yours, which we review and sign.
45 CFR 164.504(e)Model data path
AI features never receive patient identifiers - if the safety filter cannot run, the feature stops rather than risk exposure. No patient data is ever used for training.
fail-closed boundarySubmission safety
Every outbound claim is checked for completeness before sending, and the same appeal can never be submitted twice.
validation gatesVerify it yourself
Run the conformance suite against us
Our zero-PHI conformance suite is public. It fires synthetic identifier-shaped probes at a running Hypex instance and asserts nothing leaks back, then checks the de-identification engine and the fail-closed boundary gate directly. Your security team can run it against our production instance today - and re-run it quarterly, unannounced.
Clone the suite
One link, no credentials, no setup call - built to run without us in the room.
Point it at us
One flag: --base-url https://api.hypexrcm.com. Black-box probes run immediately.
Read the verdict
A PASS/FAIL report with per-check detail, safe to attach to your security review.
What we are not (yet) - and exactly what changes it
- SOC 2 Type II: examination in progress. The controls it tests run in production today; we provide the control matrix above and the audit timeline on request.
- Penetration test: scheduled before any hospital-direct production go-live. Micro-RCM and clinic deployments run on the same hardened stack meanwhile.
- US entity: formed when the first client requires it (it is revenue-gated, not calendar-gated). Until then the BAA is signed by the registered sole proprietorship with a W-8BEN on file.