Skip to content

Becker's IT + Revenue Cycle Conference, ChicagoView event

Security & trust

Security that survives the security review.

Neurex processes PHI under executed BAAs for operational claims work. Model learning uses de-identified, tenant-scoped data: isolated and governed, with a human in the loop on consequential actions.
HIPAA-alignedSOC 2 Type II readinessBAAs executed
HIPAA-alignedSOC 2 Type II readinessAudit-ready trailsBAAs executed
Data boundaries

Two data paths, kept distinct.

Claims work needs PHI; model learning does not. Neurex keeps the two claims separate because blending them is how a security review goes sideways.

Ask any vendor two questions. What touches PHI, and under what agreement? What does the model learn from, and for whom? Our answers: operational work runs on PHI under executed BAAs, and learning runs on de-identified, tenant-scoped data.

neurex · data boundarieskept distinct
Operational claims workPHI · under executed BAAs

Coding, denial prevention, appeals, and recovery run on protected health information, governed by Business Associate Agreements with every covered entity.

Model learningde-identified · tenant-scoped

The engine learns from de-identified data, scoped to your tenant: isolated and governed. Your payer patterns train decisions for you.

blending these two claims is how vendors overstate; we don’t

HIPAA alignment

HIPAA-aligned, under executed BAAs.

Neurex operates HIPAA-compliant processes under executed Business Associate Agreements with covered entities. The panel below maps to the HIPAA Security Rule safeguard families; detailed control documentation is available in diligence.

neurex · HIPAA safeguard families
mapped

Administrative Safeguards

  • Security management processes
  • Workforce training and management
  • Information access controls
  • Security incident procedures
  • Contingency planning
  • Business Associate Agreements

Physical Safeguards

  • Secure cloud hosting
  • Facility access controls
  • Workstation security policies
  • Device and media controls
  • Geographic redundancy
  • Disaster recovery procedures

Technical Safeguards

  • Access controls and authentication
  • Encryption at rest and in transit
  • Audit controls and logging
  • Integrity controls
  • Transmission security
  • Automatic log-off

Breach Notification

  • Incident detection systems
  • Breach notification procedures
  • Risk assessment processes
  • Mitigation protocols
  • Documentation requirements
  • Regulatory reporting
Architecture

Encryption and resilience, stated exactly.

TLS 1.2+ in transit. AES-256 at rest. Multi-region Azure disaster recovery. We publish what the record supports, and nothing it doesn't.

01Access & oversight
Isolated and governedHuman-in-the-loopAudit-ready trails
02Encryption
AES-256 at restTLS 1.2+ in transit
03Model boundary
Tenant-scoped learningDe-identified data
04Resilience
Multi-region Azure DRRedundancy
Trust Service Criteria

SOC 2 Type II readiness.

A security program with controls mapped to the five Trust Service Criteria. We say readiness deliberately: precision in trust claims is the point of a trust page.

Security

This criterion covers protection against unauthorized access, both logical and physical, across systems and data.

Availability

This criterion covers whether systems are available for operation as committed, including resilience and recovery.

Processing Integrity

This criterion covers whether processing is complete, valid, accurate, timely, and authorized.

Confidentiality

This criterion covers how information designated confidential is protected through its lifecycle.

Privacy

This criterion covers how personal information is collected, used, retained, disclosed, and disposed of.

SecurityAvailabilityIntegrityConfidentialityPrivacy

Trust principle 1 / 5

Security

This criterion covers protection against unauthorized access, both logical and physical, across systems and data.

AI governance

Autonomous never means unaccountable.

The engine's governance is published, measured, and auditable: oversight on consequential actions, evidence on every output, and outcomes validated against real payer decisions.

  1. Fairness
  2. Transparency
  3. Oversight
  4. Accountability
neurex · responsible AI
active

Human oversight

A human stays in the loop on consequential actions. Approval workflows gate appeals and consequential changes before anything files.

Evidence-linked outputs

Recommendations carry their evidence: policy citations, clinical criteria references, and documentation excerpts a reviewer can check.

Audit-ready trails

Decisions, reviews, and outcomes are logged end to end, so compliance teams can reconstruct any action after the fact.

Measured governance

False-positive rate and reviewer flip rate are measured monthly, per payer and category. A flip rate above 30% auto-elevates the category for human review.

Tenant-scoped learning

Model learning uses de-identified data scoped to your tenant: isolated and governed, never pooled into an open model.

Outcome validation

Predictions are scored against real payer remittance outcomes, and deviation triggers retraining. The system answers to ground truth.

Questions

What security reviewers ask

Exact answers, in the same words we use in diligence.

Security review

Bring us your security questionnaire.

Our team will walk your security and compliance reviewers through controls, data flows, and documentation.

PHI under executed BAAs · De-identified, tenant-scoped model learning

    Healthcare AI Security & Compliance | Neurex AI