Business Associate Agreement
AuthQuire signs BAAs with customers handling PHI before any PHI moves into the workspace. Request a BAA review.
Encryption
- AES-256 at rest and TLS 1.2+ in transit.
- US-only data residency in AWS us-east-1.
- Key management: managed keys with access logging.
Audit logs
Audit logs cover data access events, PA packet modifications, and export events, each recorded with actor, timestamp, and context. Audit logs are visible to customer administrators inside the workspace and are retained for 3 years.
MFA and session safety
- MFA is mandatory for all user tiers.
- Okta and Azure AD SSO support.
- Sessions expire after a configurable idle period; suspicious sign-in events trigger re-authentication.
Access controls
Roles include Admin, Reviewer, Read-Only (Billing), and System Auditor. Access is role-based and least-privilege by default. Customer administrators provision and remove reviewer access; AuthQuire staff access to customer PHI is restricted to a small on-call group, requires a written support request, and is recorded in the audit trail.
Subprocessors
AuthQuire uses AWS (us-east-1) for hosting, Snowflake for analytics, and SendGrid for transactional email. Subprocessors handling PHI sign BAAs. A notification feed for subprocessor changes is available on request at security@authquire.com.
Incident response
AuthQuire maintains a documented incident response plan covering detection, triage, containment, eradication, and post-incident review. Critical breach notifications are targeted within 24 hours; operational disruption notifications within 48 hours, alongside HIPAA Breach Notification Rule obligations where applicable.
Security posture
SOC 2 Type II compliant as of November 2024. Audit scope: Cloud Infrastructure & Data Handling. ISO 27001 is in progress with target completion in Q4 2026.
- BAA-supported workflows: AuthQuire executes a BAA with customers handling PHI.
- HIPAA does not issue certifications, so AuthQuire never describes itself as HIPAA certified.
- Customer data is not used for global model training. Anonymized dataset improvements are opt-in only.
- Clinical data retention is 7 years where required by HIPAA/state mandates; audit logs are retained for 3 years.
- Permanent erasure via cryptographic wipe upon contract termination with a 30-day recovery window.
- Security questionnaires and control documentation are answered directly by our team.
- AuthQuire extracts evidence, drafts packets, and maps payer requirements automatically, but final clinical approval, payer submission, and appeal decisions require human action.
- Confidence scores below 0.85 trigger mandatory human review. Reviewers can override AI-mapped evidence; original extraction remains in version history.
Security contact
Vulnerability reports, BAA requests, and security questionnaires: security@authquire.com. Please include reproduction steps for any vulnerability report and allow our team a reasonable response window before public disclosure.