Scope and roles
AuthQuire ("we", "us") provides software that prepares, organizes, and tracks prior-authorization packets and appeals. For PHI processed through the workspace, our customer (the covered entity or business associate that uses AuthQuire) is the data controller; AuthQuire acts as a business associate.
For non-PHI marketing, billing, and account information collected directly from visitors and customer administrators, AuthQuire acts as the controller.
PHI handling
AuthQuire handles PHI only under appropriate customer agreements and permissions. Before PHI moves into the workspace, AuthQuire and the customer execute a Business Associate Agreement (BAA) that defines safeguards, breach notification, and audit obligations.
- AES-256 at rest and TLS 1.2+ in transit, with US-only data residency in AWS us-east-1.
- Access is role-based, least-privilege, and recorded in the audit trail.
- PHI is used only to deliver the authorization services contracted for.
- Customer data is not used for global model training. Anonymized dataset improvements are opt-in only.
Account data
When an administrator creates an AuthQuire workspace, we collect name, work email, organization, role, and authentication metadata (sign-in events, IP addresses for session safety, device fingerprint hashes). This data identifies and protects user accounts.
Uploads, packets, and AI-assisted output
Reviewers upload clinical notes, imaging reports, payer policies, and related documentation to assemble packets. AuthQuire's evidence review feature highlights relevant excerpts and drafts language for reviewer approval. Reviewers retain editorial control: nothing leaves the workspace without a recorded human approval.
Audit logs
Audit logs cover data access events, PA packet modifications, and export events, each recorded with actor, timestamp, and context. Audit logs are retained for 3 years.
Communications
We send transactional emails (account, security, billing, and packet-status notifications) to administrators and reviewers. We do not auto-subscribe contacts to marketing. Marketing-style updates, if any, require explicit opt-in.
Subprocessors
AuthQuire uses AWS (us-east-1) for hosting, Snowflake for analytics, and SendGrid for transactional email. All subprocessors handling PHI sign BAAs. Notification of subprocessor changes is available on request at security@authquire.com.
Retention and deletion
Clinical data retention is 7 years where required by HIPAA/state mandates; audit logs are retained for 3 years. Permanent erasure via cryptographic wipe upon contract termination with a 30-day recovery window.
Your rights
Individuals exercising rights under HIPAA, GDPR, CCPA, or similar regimes should contact their covered entity (typically the clinic or RCM operator) first. AuthQuire will support customers in responding to verified requests. For direct inquiries about AuthQuire-controlled data (marketing, billing), email privacy@authquire.com.
Business Associate Agreement
AuthQuire signs BAAs with customers handling PHI. Request a BAA review to begin the process.
Security contact
Report a vulnerability, request a BAA, or ask a privacy question at security@authquire.com.