Security & trust
What we protect, and what we will put in writing.
Resova iQ handles protected health information for licensed practices. This page states what is in place today, in language your compliance reviewer can check. Where something is a capability rather than a certification, we say so.
Security at a glance
Encryption
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Keys are managed through a dedicated key-management service.
BAAs, and HIPAA-aligned workflows
We enter into Business Associate Agreements with covered entities. We describe our workflows as HIPAA-aligned; we do not claim a HIPAA certification, because no such certification exists.
Access control
Role-based access with least-privilege defaults, support for single sign-on and multi-factor authentication, and audit logging of sensitive actions.
Where AI is involved
The controls that matter when a model is in the loop.
Generative models can produce incorrect output. We do not rely on trusting them.
A person signs, always
Clinical notes remain provider-signed. Claims submit only under the approvals configured in your account. The platform will not auto-sign a note or submit a claim on its own, and that is enforced in the architecture rather than by a setting.
Model output is verified, not trusted
Facts extracted from payer contracts carry a quote and a character location in the source document, derived by code rather than supplied by the model. Extractions that cannot be verified against the source cannot be accepted at all.
Deterministic checks run after generation
Coding and claim validation are rule-based, not model judgment. Prompts and model versions are tracked, and changes pass regression evaluation before they are promoted.
Every override is attributable
Exceptions are recorded in an append-only ledger with the person who made the decision, the reason they entered, the rule version in force and the full context. An exception never silently rewrites the underlying facts.
Our approach
Security is built into how we design, build and operate Resova iQ rather than added afterward. We apply administrative, technical and physical safeguards designed to protect the confidentiality, integrity and availability of the data entrusted to us, and we review those controls on an ongoing basis.
Infrastructure and hosting
- Hosted with established cloud providers that maintain recognized compliance programs such as SOC 2 and ISO 27001. These are our hosting provider's certifications, not ours — Resova iQ does not currently hold its own SOC 2 attestation.
- Network segmentation, firewalls and security groups isolate sensitive workloads.
- Continuous monitoring, centralized logging and alerting on anomalous activity.
- Encrypted, regularly tested backups with documented recovery procedures.
Data protection
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Secrets and keys managed through a dedicated key-management service.
- Data minimization — we collect and retain what the service requires.
- Logical separation of customer data with tenancy controls enforced at the data layer.
- Historical state is retained so records can be reconstructed as they stood on a given date, which is what makes an audit answerable.
Access and authentication
- Role-based access with least-privilege defaults.
- Support for single sign-on and multi-factor authentication.
- Audit logging of sensitive actions, retained for review.
- Internal access is granted on a need-to-know basis and revoked on departure.
Application security
- Secure development lifecycle with peer code review.
- Automated dependency and vulnerability scanning in our pipelines.
- Periodic penetration testing with remediation tracking.
- Separate development, staging and production environments.
Compliance and HIPAA
We support HIPAA-aligned workflows and enter into Business Associate Agreements with covered entities. The services are designed so that protected health information is handled under the safeguards required by the HIPAA Security Rule. We will never auto-submit a claim or auto-sign a clinical note outside the approvals you configure.
Our compliance program operates with in-house health-law counsel — BAAs, payer contract terms, and state telehealth requirements are reviewed by a healthcare attorney, not a checklist.
Your data is yours
Notes, transcripts and records belong to your practice. They are structured, portable and exportable, and nothing about the platform is designed to make leaving difficult. Where a Business Associate Agreement is in place, it governs protected health information and controls over any conflicting term elsewhere.
Incident response
We maintain an incident-response plan covering detection, containment, investigation and notification, and we will meet the notification obligations set out in our agreements and by law.
Business continuity
Backups are encrypted and tested, and recovery procedures are documented so service can be restored within defined objectives.
Your responsibilities
Security is shared. Practices are responsible for managing their own users and roles, enforcing sensible authentication, configuring approval controls appropriately, and reviewing clinical and billing output before relying on it.
Reporting a vulnerability
If you believe you have found a security issue, email inquire@resovaiq.com with enough detail to reproduce it. We ask for responsible disclosure and will acknowledge your report.
Due diligence
Need this in a questionnaire?
Send us your security review or BAA template and we will work through it directly rather than pointing you back at this page.