HIPAA & BAA

Compliance isn't a checkbox. It's in the architecture.

A signed Business Associate Agreement on every plan, PHI-first architecture, and a scope of work that never touches your data beyond the operations you asked us to run. This is the page your compliance officer wants to see before approving a purchase.

Our commitments

What the BAA covers

Five commitments to every clinic on every paid plan. No asterisks, no add-ons, no surprise gaps.

BAA included on every paid plan

Every Starter, Growth, and Scale subscription includes a signed Business Associate Agreement from day one. There is no upsell, no premium tier required, no separate legal negotiation. The BAA covers the full RevCycle.ai platform: storage, processing, and any integrations configured during your onboarding.

Data encrypted in transit and at rest

Protected Health Information is encrypted at rest and in transit using industry-standard cryptographic controls. Each clinic operates in a logically isolated tenant — your records are never co-mingled with another clinic's, and isolation is enforced at the data layer, not just the application layer.

Full audit logging on every read and write

Every access and mutation of PHI is logged with the actor, the record, the time, and the action. Access history is demonstrable on demand for compliance review, not reconstructed after the fact. Logs are retained per HIPAA-prescribed timelines.

Operational-PHI-only scope

RevCycle.ai processes only the PHI necessary for revenue-cycle operations: scheduling, intake, claims, payments, and reporting. We do not sell your data. We do not advertise against it. We do not share it with third parties beyond the integrations you explicitly enable.

HIPAA-prescribed breach notification

In the event of an unauthorised disclosure of unsecured PHI, RevCycle.ai notifies the Covered Entity within the timelines prescribed by the HIPAA Breach Notification Rule (within 60 days). Internal incident-response procedures are tested on a defined schedule to ensure the notification, containment, and remediation chain holds under real conditions.

Honest disclosure

What we haven't claimed

RevCycle.ai does not yethold a SOC 2 Type II report or a HITRUST certification. A formal audit is on our roadmap — when the report is complete and honest, we'll publish it here.

In the meantime, what this page covers are commitments we doback today: a signed BAA, encryption, audit logging, operational-only PHI scope, and the breach-notification chain. If a specific control framework your clinic requires isn't on this page, please ask us on the setup call — we will tell you plainly whether we meet it.

Next steps

Ready to read the BAA in full?

Pick a plan to see the BAA acceptance flow, or revisit the answers to the most common buyer questions.