Business Associate Agreement

AuthQuire signs BAAs with customers handling PHI.

AuthQuire's prior-authorization workflows are BAA-supported. Before any PHI moves into the platform, we execute a Business Associate Agreement that defines safeguards, breach notification, and audit obligations. AuthQuire is SOC 2 Type II compliant as of November 2024, with an audit scope of Cloud Infrastructure & Data Handling.

What the AuthQuire BAA covers.

Safeguards

Administrative, physical, and technical safeguards covering PHI: AES-256 at rest and TLS 1.2+ in transit, US-only data residency in AWS us-east-1, role-based access, and a full audit trail.

Human approval

Every packet has a named reviewer. AuthQuire does not submit, decide, or auto-route without a recorded human approval.

Use limits

PHI is used only to deliver authorization services. We do not sell, share, or train models on customer PHI.

Breach response

Critical breach notifications are targeted within 24 hours; operational disruption notifications within 48 hours, handled under the terms of the executed BAA.

What we say — plainly.

BAA-supported workflows

AuthQuire's operational controls map to HIPAA's Privacy and Security Rules, and we execute BAAs as standard with customers handling PHI.

Not a HIPAA certification

HIPAA does not issue certifications. We do not claim "HIPAA certified" — any vendor that does should be treated with caution.

Retention and deletion

Clinical data retention is 7 years where required by HIPAA/state mandates; audit logs are retained for 3 years. Permanent erasure via cryptographic wipe upon contract termination with a 30-day recovery window.

Human authority boundary

AuthQuire extracts evidence, drafts packets, and maps payer requirements automatically, but final clinical approval, payer submission, and appeal decisions require human action.

How a BAA gets in place.

  1. Step 01
    Request review

    Submit the BAA form with your organization, role, and which workflows will touch PHI.

  2. Step 02
    Counsel exchange

    Our security team shares the AuthQuire BAA. Redlines are reviewed within a normal counsel cycle.

  3. Step 03
    Signed, then provisioned

    Once executed, your workspace is provisioned for PHI and an audit-trail review is scheduled.

Ready to request a BAA?
Our security team responds within one business day.