Security & Compliance

Your PHI, handled the way you'd handle it yourself

A coding partner touches your patients' most sensitive data. Here is exactly how we protect it, before you ever ask.

How We Protect Your Data

Built on standards, not promises

Signed BAA, Every Time

No chart moves before a HIPAA-compliant Business Associate Agreement is signed and in place.

Role-Based Access

Individual logins, no shared credentials, and access scoped to only the charts a coder is currently assigned.

Encrypted Transfer

Data in transit is encrypted end to end, whether through direct system access or secure file transfer.

Credentialed Coders Only

AAPC (CPC) and AHIMA (CCS) certified coders, background-screened before any PHI access is granted.

Activity Logging

Chart-level access is logged, so any engagement can be audited after the fact.

Incident Response

A defined process for timely notification if anything ever goes wrong, as required under your BAA.

Transparency

We tell you where and how your data is handled during contracting, not after

Security questions are the most common reason a coding outsourcing decision stalls, and the most common reason it should. Before you sign anything, we walk through exactly who touches your charts, what access they have, how long data is retained, and what happens if something goes wrong.

That conversation happens with you before the BAA is signed, not buried in a policy document afterward. If an answer does not satisfy your compliance team, we would rather lose the engagement than have you find out later.

Ask Us Anything First
100%
Engagements Under BAA
CPC
& CCS Certified Coders
1:1
Individual Coder Logins
24/7
Incident Response Path
Security FAQ

Questions your compliance team will ask

Do you sign a Business Associate Agreement (BAA)?

Yes. Every engagement starts with a signed BAA that meets HIPAA requirements before any chart or PHI is shared, covering our obligations as your business associate.

Where is our data processed, and does PHI leave the US?

Coding work is performed by our certified teams under the access controls and data-handling terms defined in your BAA and service agreement. We are transparent about delivery location during contracting so there are no surprises after you sign.

Do coders access our EHR or PM system directly, or do you receive extracted charts?

Both models are supported. Some clients grant restricted, role-based access to their own systems; others send de-identified or extracted chart data through a secure transfer method. We configure access to match your organization's security policy, not the other way around.

What access controls exist for individual coders?

Role-based access limited to the charts assigned to that coder, individual login credentials (no shared accounts), and activity logging. Coders do not have standing access to systems or charts outside their current assignment.

How is data transferred and stored?

All data in transit is encrypted. We do not retain PHI longer than required to complete and QA the coding engagement, and retention terms are defined in your service agreement.

What happens if there is a security incident?

We maintain a defined incident response process, including timely notification to you as required under your BAA and applicable breach notification rules, so you are never the last to know.

Are your coders certified, and are they background-checked?

Yes. Our coders hold AAPC (CPC) or AHIMA (CCS) credentials, and all staff handling PHI go through a confidentiality and security onboarding process before touching client data.

Have a question your compliance team needs answered?

Talk to us before you sign anything. We would rather answer every question up front.