Security & Compliance
Built for HIPAA
from day one.
Solace RCM processes protected health information (PHI) on behalf of EMS billing teams. Every component of our stack — infrastructure, AI providers, storage, hosting — is covered by a signed Business Associate Agreement before any pilot customer uploads data.
Security Architecture
How we protect PHI.
Six controls across infrastructure, AI providers, and application layer. Auditable, documented, and contractually bounded by signed BAAs.
Encryption at rest
All PHI is encrypted at rest using AES-256 with a customer-managed AWS KMS key. We do not operate without KMS-encrypted storage.
- AES-256 server-side encryption on S3
- Customer-managed KMS keys (CMK), rotated annually
- Encryption at the database column level for sensitive identifiers
- TLS 1.3 in transit across all internal hops
Business Associate Agreements
Every vendor that touches PHI signs a BAA before we go live. Customers sign a BAA with Solace RCM on day one. No exceptions.
- AWS BAA — covers S3, KMS, Bedrock fallback
- OpenAI BAA — covers GPT-4.1 narrative generation with Zero Data Retention
- Vercel Enterprise / Neon / Clerk BAAs filed before pilot launch
Audit log retention
Every draft, edit, accept, reject, and export is logged with actor, timestamp, and IP. Logs are immutable and retained for 6-7 years depending on tier.
- Per-action: who, what, when, from where
- Append-only storage with cryptographic hash chaining
- Exportable as CSV/JSON for compliance officers
- 6 years on Starter, 7 years on Growth/Scale
Access controls
Role-based access with least privilege. Billers see only the claims assigned to them. Agency admins manage seat assignments. We log every privileged action.
- Role-based: agency admin, biller, viewer
- SSO available (SAML/OIDC) on Growth+
- MFA enforced on all admin accounts
- Session timeout after 15 minutes idle
Data residency
All production data stays in US-East-1. AI inference for OpenAI primary is routed through the US region. Bedrock fallback is US-only by default.
- S3 bucket: us-east-1
- Database: us-east-1 (Neon, migrating to RDS)
- OpenAI GPT-4.1 calls pinned to US region
- AWS Bedrock inference in us-east-1
AI provider governance
OpenAI is our primary narrative-generation provider under a signed BAA with Zero Data Retention enabled. AWS Bedrock-Claude is the fallback for reliability — both covered.
- OpenAI Zero Data Retention (ZDR) — no prompt retention, no abuse monitoring
- Model-router abstraction: PHI guard + provider fallback
- No training of AI models on customer PHI
- Mock model for development, demos, and CI — never touches real PHI
BAA Status
Who's covered, and what's pending.
Status as of July 2026. Pilot customers receive a live BAA status dashboard inside the app.
| Provider | What it covers | Status |
|---|---|---|
| AWS | S3 (PHI storage) + KMS (encryption keys) + Bedrock (Claude fallback) | Filed |
| OpenAI | GPT-4.1 + GPT-4.1-mini API with Zero Data Retention | Pre-pilot |
| Vercel | Application hosting (Enterprise tier required for HIPAA) | Pre-pilot |
| Neon | Postgres hosting (Launch+ tier required for BAA) | Pre-pilot |
| Clerk | Authentication (Pro tier required for BAA) | Pre-pilot |
| Stripe | Payment processing (BAA available on standard plan) | At pilot signup |
Incident Response
If something goes wrong.
Standard HIPAA breach-notification timelines. Documented runbook. Tested annually.
Detection
Automated alerting via Sentry (errors), AWS GuardDuty (infrastructure), and custom audit-log anomaly detection. On-call engineer paged within 15 minutes of a confirmed PHI-touching event.
Containment
Affected credentials rotated, access tokens revoked, instance isolated. PHI access frozen until forensics complete. Customer admin notified within 4 hours of containment.
Notification
HIPAA Breach Notification Rule: affected customers and HHS notified within 60 days. Solace RCM commits to 24-hour preliminary notification to the agency admin for any confirmed PHI exposure.
Postmortem
Written postmortem shared with affected customers within 14 days. Root cause, blast radius, customer impact, and corrective actions. No NDAs required to read our postmortems.
Compliance review packet?
For compliance officers and security teams evaluating Solace RCM: we send a one-page BAA summary, the AI governance addendum, and the data-flow diagram. No sales call required.
security@solacercm.com