AuthQuire signs BAAs with customers handling PHI.
AuthQuire's prior-authorization workflows are BAA-supported. Before any PHI moves into the platform, we execute a Business Associate Agreement that defines safeguards, breach notification, and audit obligations. AuthQuire is SOC 2 Type II compliant as of November 2024, with an audit scope of Cloud Infrastructure & Data Handling.
What the AuthQuire BAA covers.
Administrative, physical, and technical safeguards covering PHI: AES-256 at rest and TLS 1.2+ in transit, US-only data residency in AWS us-east-1, role-based access, and a full audit trail.
Every packet has a named reviewer. AuthQuire does not submit, decide, or auto-route without a recorded human approval.
PHI is used only to deliver authorization services. We do not sell, share, or train models on customer PHI.
Critical breach notifications are targeted within 24 hours; operational disruption notifications within 48 hours, handled under the terms of the executed BAA.
What we say — plainly.
AuthQuire's operational controls map to HIPAA's Privacy and Security Rules, and we execute BAAs as standard with customers handling PHI.
HIPAA does not issue certifications. We do not claim "HIPAA certified" — any vendor that does should be treated with caution.
Clinical data retention is 7 years where required by HIPAA/state mandates; audit logs are retained for 3 years. Permanent erasure via cryptographic wipe upon contract termination with a 30-day recovery window.
AuthQuire extracts evidence, drafts packets, and maps payer requirements automatically, but final clinical approval, payer submission, and appeal decisions require human action.
How a BAA gets in place.
- Step 01Request review
Submit the BAA form with your organization, role, and which workflows will touch PHI.
- Step 02Counsel exchange
Our security team shares the AuthQuire BAA. Redlines are reviewed within a normal counsel cycle.
- Step 03Signed, then provisioned
Once executed, your workspace is provisioned for PHI and an audit-trail review is scheduled.