Yes. AI fax triage can be HIPAA compliant when the vendor executes a Business Associate Agreement and applies appropriate administrative, physical and technical safeguards. Provenza processes protected health information under a signed BAA, with encryption in transit and at rest, role-based access control, and a complete audit trail for every document and every action taken on it. The BAA is executed before any PHI is transmitted, including during a free evaluation.
A vendor saying "HIPAA compliant" means nothing on its own. These are the specific things to verify.
Any vendor handling PHI on your behalf is a business associate and must sign one. If they will not, the conversation ends there.
PHI protected on the wire and in storage, with keys managed separately from the data.
Role-based permissions so staff see only what their role requires, with every access recorded against a named identity.
A record of who accessed what, when, and what they did — retained and exportable.
Only the PHI required for the function is processed and exposed, not everything available.
A defined process and timeline, contractually committed rather than assumed.
If a vendor cannot answer these plainly, that is your answer.
The correct answer is yes, and before a trial, not after. PHI should never move on a handshake.
Ours is no. Customer documents produce your results and are not used to train shared models.
You should set retention. Expiry should trigger a purge, and the purge itself should be logged.
The answer should be a role, tightly scoped, with access logged — not "our engineers".
Ours: SOC 2 aligned controls are operating, formal certification is in progress. We will not claim a certificate we do not hold.
You export, we purge, the purge is logged. No retention past your instruction.
It can be, when the vendor executes a Business Associate Agreement and applies appropriate administrative, physical and technical safeguards. Provenza processes PHI under a signed BAA with encryption in transit and at rest, role-based access control and a complete audit trail.
Yes. The BAA is executed before any protected health information is transmitted, including during a free evaluation. No PHI moves without one in place.
No. Customer documents are processed to produce your results and are not used to train shared models.
Aurus operates SOC 2 aligned controls covering access management, change management, encryption and audit logging. Formal certification is in progress, and we will publish the report date when the audit completes rather than implying certification we do not yet hold.
You set the retention window. When it expires, documents and derived data are purged and the purge is logged.
Every document received, every automated decision and its basis, every human action, timestamped and attributable to a named identity, exportable for your auditors.
Encryption, access control, retention, and honest certification status.
What the platform actually does with the documents.
Everything else procurement usually asks.
That order never changes, including for a free evaluation. Send the agreement back and we will start the same day.
Card required to start · BAA before PHI · Answer in one business day