heillerRevenue Cycle Management

Security

Verifiable. Not asserted.

Anyone can put a padlock icon on a website. What follows is the evidence behind ours — the controls, who they are audited by, where protected health information physically lives, and what happens on the worst day.

Framework
HIPAA · SOC 2
Encryption
AES-256 · TLS 1.2+
Tenancy
Key-isolated
Breach notice
24 hours

What we are actually audited against

Note the difference between certified and aligned. We keep them separate because conflating the two is the most common overclaim in healthcare vendor security, and you will find out either way during diligence.

  • HIPAA

    Compliant

    Administrative, physical and technical safeguards under the Security Rule, plus Privacy Rule obligations as a Business Associate.

    We execute a Business Associate Agreement with every covered entity before any protected health information is transmitted. Workforce training is completed at onboarding and refreshed annually.

  • SOC 2

    Type II

    Independent audit of security, availability and confidentiality controls across an observation window.

    The report is available under NDA. Ask for the current one rather than the summary — a Type II is only meaningful alongside its exceptions, and we would rather walk you through ours than have you discover them at procurement.

  • HITRUST CSF

    Aligned

    Controls mapped to the HITRUST Common Security Framework. Not currently certified.

    We map to the framework because most of our customers are assessed against it and a shared control language shortens their diligence. We do not claim certification, and we will say so in writing.

  • ISO/IEC 27001

    Aligned

    Information security management system modelled on the standard. Not currently certified.

    Our ISMS follows the Annex A control set. Certification is on the roadmap; until an accredited body has issued a certificate, this page will keep saying "aligned".

Where your data actually goes

Not “are you encrypted” — everyone says yes — but where PHI physically lives, who can reach it, and when it is destroyed.

  1. 01

    Arrival

    PHI reaches us over TLS 1.2+ through an SFTP endpoint, a clearinghouse integration, or a direct EHR connection. Nothing is accepted over email, and attachments sent to a person rather than a system are quarantined and reported, not processed.

  2. 02

    Isolation

    Each customer is a separate logical tenant with its own encryption key. There is no shared table with a customer_id column — a query that crosses a tenant boundary does not have a path to run, rather than being blocked by a filter someone could forget.

  3. 03

    Processing

    Work happens inside the environment. Analysts operate through a brokered virtual desktop with clipboard, printing and local storage disabled, so PHI never lands on an endpoint — including in an office we control.

  4. 04

    At rest

    AES-256 on every volume, snapshot and backup. Keys are held in a managed KMS with rotation, and are separable per tenant so a customer can be cryptographically severed from the platform on request.

  5. 05

    Retention and destruction

    Retention is set per contract, defaulting to the shorter of your policy and the statutory minimum. On termination we return your data in an agreed format and then destroy it, including backups, and issue a written certificate of destruction.

The six control families

Encryption
AES-256 at rest, TLS 1.3 in transit. Keys rotated on a fixed schedule and never co-located with the data they protect.
HIPAA Compliance
Executed BAAs, an annually reviewed Security Risk Analysis, and a documented breach-notification runbook.
Audit Trails
Every read and write against PHI is written to an append-only ledger with actor, purpose and timestamp.
Secure Cloud
Isolated tenancy, private networking, and infrastructure defined in code so drift is impossible to introduce quietly.
Access Control
Role-based, least-privilege access with mandatory MFA and quarterly entitlement reviews.
Continuity
Point-in-time recovery, geographically separated replicas, and restore drills that are actually run.

Who else can reach it

The full list. We give notice before adding to it, and you can object.

Subprocessors, purpose, hosting region and BAA status
SubprocessorPurposeRegionBAA
Cloud infrastructure providerCompute, storage and managed database hostingUnited StatesExecuted
ClearinghouseClaim submission and remittance routingUnited StatesExecuted
Observability platformApplication logs and performance monitoringUnited StatesExecuted — PHI excluded by configuration
Transactional email providerSystem notifications to named staff usersUnited StatesExecuted — no PHI in message bodies

What happens on the worst day.

These windows are commitments, not intentions. The point of publishing them is that you can hold us to them.

  • SEV-1

    24h

    Confirmed unauthorised access to, or acquisition of, PHI.

  • SEV-2

    72h

    Suspected exposure, or a control failure that could have permitted access.

  • SEV-3

    5d

    Service disruption or degradation with no indication of data exposure.

Found something?

If you believe you have found a vulnerability, tell us before you tell anyone else and we will work the problem with you. We do not pursue legal action against researchers who act in good faith, stay within their own test data, and give us reasonable time to remediate.

sushanth3306@gmail.com

Request the full security packet

SOC 2 Type II report, penetration test summary, policy set, BAA template and completed CAIQ. Under NDA, usually the same business day.

Request the packet