In short

Is AI fax triage HIPAA compliant?

Yes. AI fax triage can be HIPAA compliant when the vendor executes a Business Associate Agreement and applies appropriate administrative, physical and technical safeguards. Provenza processes protected health information under a signed BAA, with encryption in transit and at rest, role-based access control, and a complete audit trail for every document and every action taken on it. The BAA is executed before any PHI is transmitted, including during a free evaluation.

What HIPAA requires

The safeguards that actually matter here

A vendor saying "HIPAA compliant" means nothing on its own. These are the specific things to verify.

An executed BAA

Any vendor handling PHI on your behalf is a business associate and must sign one. If they will not, the conversation ends there.

Encryption in transit and at rest

PHI protected on the wire and in storage, with keys managed separately from the data.

Access controls

Role-based permissions so staff see only what their role requires, with every access recorded against a named identity.

Audit controls

A record of who accessed what, when, and what they did — retained and exportable.

Minimum necessary

Only the PHI required for the function is processed and exposed, not everything available.

Breach notification

A defined process and timeline, contractually committed rather than assumed.

Questions to ask any vendor

Including us

If a vendor cannot answer these plainly, that is your answer.

Will you sign a BAA before we send anything?

The correct answer is yes, and before a trial, not after. PHI should never move on a handshake.

Do you train models on our documents?

Ours is no. Customer documents produce your results and are not used to train shared models.

Where is PHI stored, and for how long?

You should set retention. Expiry should trigger a purge, and the purge itself should be logged.

Who at your company can see our data?

The answer should be a role, tightly scoped, with access logged — not "our engineers".

Are you SOC 2 compliant?

Yes. SOC 2 Type II compliant, with controls in operation. We say compliant, not certified, and mean exactly that.

What happens to our data if we leave?

You export, we purge, the purge is logged. No retention past your instruction.

Questions

Common questions

Is AI fax triage HIPAA compliant?

It can be, when the vendor executes a Business Associate Agreement and applies appropriate administrative, physical and technical safeguards. Provenza processes PHI under a signed BAA with encryption in transit and at rest, role-based access control and a complete audit trail.

Will Aurus sign a BAA before a trial?

Yes. The BAA is executed before any protected health information is transmitted, including during a free evaluation. No PHI moves without one in place.

Does Aurus train AI models on our patient documents?

No. Customer documents are processed to produce your results and are not used to train shared models.

Is Aurus SOC 2 compliant?

Yes. Aurus is SOC 2 Type II compliant: controls covering access management, change management, encryption and audit logging are in operation. We describe this as compliance, not certification.

How long is PHI retained?

You set the retention window. When it expires, documents and derived data are purged and the purge is logged.

What does the audit trail actually record?

Every document received, every automated decision and its basis, every human action, timestamped and attributable to a named identity, exportable for your auditors.

Related

Keep reading

Security & trust

Encryption, access control, retention, and honest compliance status.

AI fax triage

What the platform actually does with the documents.

FAQs

Everything else procurement usually asks.

The BAA comes first. Then the documents.

That order never changes, including for a free evaluation. Send the agreement back and we will start the same day.

7-day free trial · Card required before the trial ends · BAA before PHI