Security & trust

What we protect, and what we will put in writing.

Resova iQ handles protected health information for licensed practices. This page states what is in place today, in language your compliance reviewer can check. Where something is a capability rather than a certification, we say so.

Security at a glance

Encryption

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Keys are managed through a dedicated key-management service.

BAAs, and HIPAA-aligned workflows

We enter into Business Associate Agreements with covered entities. We describe our workflows as HIPAA-aligned; we do not claim a HIPAA certification, because no such certification exists.

Access control

Role-based access with least-privilege defaults, support for single sign-on and multi-factor authentication, and audit logging of sensitive actions.

Where AI is involved

The controls that matter when a model is in the loop.

Generative models can produce incorrect output. We do not rely on trusting them.

A person signs, always

Clinical notes remain provider-signed. Claims submit only under the approvals configured in your account. The platform will not auto-sign a note or submit a claim on its own, and that is enforced in the architecture rather than by a setting.

Model output is verified, not trusted

Facts extracted from payer contracts carry a quote and a character location in the source document, derived by code rather than supplied by the model. Extractions that cannot be verified against the source cannot be accepted at all.

Deterministic checks run after generation

Coding and claim validation are rule-based, not model judgment. Prompts and model versions are tracked, and changes pass regression evaluation before they are promoted.

Every override is attributable

Exceptions are recorded in an append-only ledger with the person who made the decision, the reason they entered, the rule version in force and the full context. An exception never silently rewrites the underlying facts.

Our approach

Security is built into how we design, build and operate Resova iQ rather than added afterward. We apply administrative, technical and physical safeguards designed to protect the confidentiality, integrity and availability of the data entrusted to us, and we review those controls on an ongoing basis.

Infrastructure and hosting

  • Hosted with established cloud providers that maintain recognized compliance programs such as SOC 2 and ISO 27001. These are our hosting provider's certifications, not ours — Resova iQ does not currently hold its own SOC 2 attestation.
  • Network segmentation, firewalls and security groups isolate sensitive workloads.
  • Continuous monitoring, centralized logging and alerting on anomalous activity.
  • Encrypted, regularly tested backups with documented recovery procedures.

Data protection

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Secrets and keys managed through a dedicated key-management service.
  • Data minimization — we collect and retain what the service requires.
  • Logical separation of customer data with tenancy controls enforced at the data layer.
  • Historical state is retained so records can be reconstructed as they stood on a given date, which is what makes an audit answerable.

Access and authentication

  • Role-based access with least-privilege defaults.
  • Support for single sign-on and multi-factor authentication.
  • Audit logging of sensitive actions, retained for review.
  • Internal access is granted on a need-to-know basis and revoked on departure.

Application security

  • Secure development lifecycle with peer code review.
  • Automated dependency and vulnerability scanning in our pipelines.
  • Periodic penetration testing with remediation tracking.
  • Separate development, staging and production environments.

Compliance and HIPAA

We support HIPAA-aligned workflows and enter into Business Associate Agreements with covered entities. The services are designed so that protected health information is handled under the safeguards required by the HIPAA Security Rule. We will never auto-submit a claim or auto-sign a clinical note outside the approvals you configure.

Our compliance program operates with in-house health-law counsel — BAAs, payer contract terms, and state telehealth requirements are reviewed by a healthcare attorney, not a checklist.

Your data is yours

Notes, transcripts and records belong to your practice. They are structured, portable and exportable, and nothing about the platform is designed to make leaving difficult. Where a Business Associate Agreement is in place, it governs protected health information and controls over any conflicting term elsewhere.

Incident response

We maintain an incident-response plan covering detection, containment, investigation and notification, and we will meet the notification obligations set out in our agreements and by law.

Business continuity

Backups are encrypted and tested, and recovery procedures are documented so service can be restored within defined objectives.

Your responsibilities

Security is shared. Practices are responsible for managing their own users and roles, enforcing sensible authentication, configuring approval controls appropriately, and reviewing clinical and billing output before relying on it.

Reporting a vulnerability

If you believe you have found a security issue, email inquire@resovaiq.com with enough detail to reproduce it. We ask for responsible disclosure and will acknowledge your report.

Due diligence

Need this in a questionnaire?

Send us your security review or BAA template and we will work through it directly rather than pointing you back at this page.