Trust

Trust & Security at Accurecord

Security and compliance are foundational to how we handle Protected Health Information — not bolted on.

Accurecord handles Protected Health Information (PHI) for medical coding only on behalf of healthcare organizations, and only under a Business Associate Agreement executed with that organization. Our self-serve tools and the free API tier are reference-only and are not for PHI. Security and compliance are foundational, not bolted on.

Compliance status

Framework Status
HIPAA Compliant — BAA available before any PHI is processed
SOC 2 Type II In progress — observation window underway (target Q4 2026)
HITRUST On roadmap

How we protect PHI

  • Encrypted at rest — AES-256-GCM on PHI in our owned tables; secrets in Azure Key Vault.
  • Encrypted in transit — TLS 1.2+ everywhere; HSTS, strict CSP, and security headers on every response.
  • Covered by BAA, and minimized — PHI processed by an LLM subprocessor is covered by an executed Business Associate Agreement with zero data retention and no training on your data. Shaped identifiers are additionally minimized before any LLM call as defence in depth; names written into prose are not removed.
  • BAA-gated — PHI features are disabled until a Business Associate Agreement is signed.
  • Fully audited — every PHI access is written to a HIPAA Accounting-of-Disclosures ledger (45 CFR §164.528) and is customer-exportable (CSV / FHIR AuditEvent).
  • Access controlled — per-organization tenancy, hashed API keys with tiered access, enterprise SSO (OIDC, SAML), SCIM provisioning, and automatic blocking of credential-stuffing IPs.

Subprocessors

All subprocessors and their level of PHI access are listed below. See our full subprocessor list for data categories, processing regions, and each vendor's trust documentation.

Subprocessor Purpose PHI access
Microsoft Azure Hosting (Container Apps, PostgreSQL, Key Vault) Yes — BAA signed
OpenAI LLM coding inference under BAA (zero retention, no training) Limited — BAA signed, zero-retention
Anthropic LLM coding inference under BAA (zero retention, no training) Limited — BAA signed, zero-retention
Azure OpenAI Service LLM coding inference — planned, not yet in use (no earlier than 8 Oct 2026) None today — BAA signed; zero retention approved by Microsoft 7 Sep 2026 (prompts and completions not stored, no human review, no training)
Cloudflare CDN, DNS, DDoS protection, edge WAF No — transit metadata only
Stripe Billing No
Twilio Verify SMS one-time passcodes (account verification) No
Google / Microsoft OAuth Federated sign-in No

Subscribe for subprocessor-change notifications: [email protected].

Documents

Report a vulnerability

Email [email protected]. We acknowledge reports within 2 business days and do not pursue good-faith researchers who follow coordinated disclosure.