Trust & Security at Accurecord
Security and compliance are foundational to how we handle Protected Health Information — not bolted on.
Accurecord handles Protected Health Information (PHI) for medical coding only on behalf of healthcare organizations, and only under a Business Associate Agreement executed with that organization. Our self-serve tools and the free API tier are reference-only and are not for PHI. Security and compliance are foundational, not bolted on.
Compliance status
| Framework | Status |
|---|---|
| HIPAA | Compliant — BAA available before any PHI is processed |
| SOC 2 Type II | In progress — observation window underway (target Q4 2026) |
| HITRUST | On roadmap |
How we protect PHI
- Encrypted at rest — AES-256-GCM on PHI in our owned tables; secrets in Azure Key Vault.
- Encrypted in transit — TLS 1.2+ everywhere; HSTS, strict CSP, and security headers on every response.
- Covered by BAA, and minimized — PHI processed by an LLM subprocessor is covered by an executed Business Associate Agreement with zero data retention and no training on your data. Shaped identifiers are additionally minimized before any LLM call as defence in depth; names written into prose are not removed.
- BAA-gated — PHI features are disabled until a Business Associate Agreement is signed.
- Fully audited — every PHI access is written to a HIPAA Accounting-of-Disclosures ledger (45 CFR §164.528) and is customer-exportable (CSV / FHIR AuditEvent).
- Access controlled — per-organization tenancy, hashed API keys with tiered access, enterprise SSO (OIDC, SAML), SCIM provisioning, and automatic blocking of credential-stuffing IPs.
Subprocessors
All subprocessors and their level of PHI access are listed below. See our full subprocessor list for data categories, processing regions, and each vendor's trust documentation.
| Subprocessor | Purpose | PHI access |
|---|---|---|
| Microsoft Azure | Hosting (Container Apps, PostgreSQL, Key Vault) | Yes — BAA signed |
| OpenAI | LLM coding inference under BAA (zero retention, no training) | Limited — BAA signed, zero-retention |
| Anthropic | LLM coding inference under BAA (zero retention, no training) | Limited — BAA signed, zero-retention |
| Azure OpenAI Service | LLM coding inference — planned, not yet in use (no earlier than 8 Oct 2026) | None today — BAA signed; zero retention approved by Microsoft 7 Sep 2026 (prompts and completions not stored, no human review, no training) |
| Cloudflare | CDN, DNS, DDoS protection, edge WAF | No — transit metadata only |
| Stripe | Billing | No |
| Twilio Verify | SMS one-time passcodes (account verification) | No |
| Google / Microsoft OAuth | Federated sign-in | No |
Subscribe for subprocessor-change notifications: [email protected].
Documents
- Privacy Policy · Terms of Service · DPA · SLA — accurecord.io/privacy, /terms, /dpa, /sla
- Request a BAA: [email protected]
- Request our SOC 2 report / security questionnaire (under NDA): [email protected]
Report a vulnerability
Email [email protected]. We acknowledge reports within 2 business days and do not pursue good-faith researchers who follow coordinated disclosure.