Security that survives the security review.
Two data paths, kept distinct.
Claims work needs PHI; model learning does not. Neurex keeps the two claims separate because blending them is how a security review goes sideways.
Ask any vendor two questions. What touches PHI, and under what agreement? What does the model learn from, and for whom? Our answers: operational work runs on PHI under executed BAAs, and learning runs on de-identified, tenant-scoped data.
Coding, denial prevention, appeals, and recovery run on protected health information, governed by Business Associate Agreements with every covered entity.
The engine learns from de-identified data, scoped to your tenant: isolated and governed. Your payer patterns train decisions for you.
blending these two claims is how vendors overstate; we don’t
HIPAA-aligned, under executed BAAs.
Neurex operates HIPAA-compliant processes under executed Business Associate Agreements with covered entities. The panel below maps to the HIPAA Security Rule safeguard families; detailed control documentation is available in diligence.
Administrative Safeguards
- Security management processes
- Workforce training and management
- Information access controls
- Security incident procedures
- Contingency planning
- Business Associate Agreements
Physical Safeguards
- Secure cloud hosting
- Facility access controls
- Workstation security policies
- Device and media controls
- Geographic redundancy
- Disaster recovery procedures
Technical Safeguards
- Access controls and authentication
- Encryption at rest and in transit
- Audit controls and logging
- Integrity controls
- Transmission security
- Automatic log-off
Breach Notification
- Incident detection systems
- Breach notification procedures
- Risk assessment processes
- Mitigation protocols
- Documentation requirements
- Regulatory reporting
Encryption and resilience, stated exactly.
TLS 1.2+ in transit. AES-256 at rest. Multi-region Azure disaster recovery. We publish what the record supports, and nothing it doesn't.
SOC 2 Type II readiness.
A security program with controls mapped to the five Trust Service Criteria. We say readiness deliberately: precision in trust claims is the point of a trust page.
Security
This criterion covers protection against unauthorized access, both logical and physical, across systems and data.
Availability
This criterion covers whether systems are available for operation as committed, including resilience and recovery.
Processing Integrity
This criterion covers whether processing is complete, valid, accurate, timely, and authorized.
Confidentiality
This criterion covers how information designated confidential is protected through its lifecycle.
Privacy
This criterion covers how personal information is collected, used, retained, disclosed, and disposed of.
Trust principle 1 / 5
Security
This criterion covers protection against unauthorized access, both logical and physical, across systems and data.
Autonomous never means unaccountable.
The engine's governance is published, measured, and auditable: oversight on consequential actions, evidence on every output, and outcomes validated against real payer decisions.
- Fairness
- Transparency
- Oversight
- Accountability
Human oversight
A human stays in the loop on consequential actions. Approval workflows gate appeals and consequential changes before anything files.
Evidence-linked outputs
Recommendations carry their evidence: policy citations, clinical criteria references, and documentation excerpts a reviewer can check.
Audit-ready trails
Decisions, reviews, and outcomes are logged end to end, so compliance teams can reconstruct any action after the fact.
Measured governance
False-positive rate and reviewer flip rate are measured monthly, per payer and category. A flip rate above 30% auto-elevates the category for human review.
Tenant-scoped learning
Model learning uses de-identified data scoped to your tenant: isolated and governed, never pooled into an open model.
Outcome validation
Predictions are scored against real payer remittance outcomes, and deviation triggers retraining. The system answers to ground truth.
What security reviewers ask
Exact answers, in the same words we use in diligence.
Neurex operates HIPAA-compliant processes under executed Business Associate Agreements with covered entities. There is no official HIPAA certification for vendors, so we state our alignment precisely and back it with BAAs, documented safeguards, and audit-ready trails.
Neurex maintains SOC 2 Type II readiness: a security program with controls mapped to the five Trust Service Criteria. We say readiness deliberately, and we share documentation with your security team on request.
No. The two data paths are kept distinct. Operational claims work processes PHI under executed BAAs. Model learning uses de-identified, tenant-scoped data: isolated and governed, and scoped to your tenant.
TLS 1.2+ for data in transit and AES-256 at rest, with multi-region Azure disaster recovery.
No. A human stays in the loop on consequential actions, approval workflows gate appeals before anything files, and every decision carries an audit-ready trail. Model governance is measured monthly: false-positive rate and reviewer flip rate per payer and category, with noisy categories auto-elevated for human review.
Bring us your security questionnaire.
Our team will walk your security and compliance reviewers through controls, data flows, and documentation.
PHI under executed BAAs · De-identified, tenant-scoped model learning