Built for HIPAA
from day one.

Solace RCM processes protected health information (PHI) on behalf of EMS billing teams. Every component of our stack — infrastructure, AI providers, storage, hosting — is covered by a signed Business Associate Agreement before any pilot customer uploads data.

HIPAA
AES-256 at rest
Full audit log
Customer-managed KMS
NEMSIS 3.5 input
BAA included

How we protect PHI.

Six controls across infrastructure, AI providers, and application layer. Auditable, documented, and contractually bounded by signed BAAs.

Encryption at rest

All PHI is encrypted at rest using AES-256 with a customer-managed AWS KMS key. We do not operate without KMS-encrypted storage.

  • AES-256 server-side encryption on S3
  • Customer-managed KMS keys (CMK), rotated annually
  • Encryption at the database column level for sensitive identifiers
  • TLS 1.3 in transit across all internal hops

Business Associate Agreements

Every vendor that touches PHI signs a BAA before we go live. Customers sign a BAA with Solace RCM on day one. No exceptions.

  • AWS BAA — covers S3, KMS, Bedrock fallback
  • OpenAI BAA — covers GPT-4.1 narrative generation with Zero Data Retention
  • Vercel Enterprise / Neon / Clerk BAAs filed before pilot launch

Audit log retention

Every draft, edit, accept, reject, and export is logged with actor, timestamp, and IP. Logs are immutable and retained for 6-7 years depending on tier.

  • Per-action: who, what, when, from where
  • Append-only storage with cryptographic hash chaining
  • Exportable as CSV/JSON for compliance officers
  • 6 years on Starter, 7 years on Growth/Scale

Access controls

Role-based access with least privilege. Billers see only the claims assigned to them. Agency admins manage seat assignments. We log every privileged action.

  • Role-based: agency admin, biller, viewer
  • SSO available (SAML/OIDC) on Growth+
  • MFA enforced on all admin accounts
  • Session timeout after 15 minutes idle

Data residency

All production data stays in US-East-1. AI inference for OpenAI primary is routed through the US region. Bedrock fallback is US-only by default.

  • S3 bucket: us-east-1
  • Database: us-east-1 (Neon, migrating to RDS)
  • OpenAI GPT-4.1 calls pinned to US region
  • AWS Bedrock inference in us-east-1

AI provider governance

OpenAI is our primary narrative-generation provider under a signed BAA with Zero Data Retention enabled. AWS Bedrock-Claude is the fallback for reliability — both covered.

  • OpenAI Zero Data Retention (ZDR) — no prompt retention, no abuse monitoring
  • Model-router abstraction: PHI guard + provider fallback
  • No training of AI models on customer PHI
  • Mock model for development, demos, and CI — never touches real PHI

Who's covered, and what's pending.

Status as of July 2026. Pilot customers receive a live BAA status dashboard inside the app.

Provider What it covers Status
AWS S3 (PHI storage) + KMS (encryption keys) + Bedrock (Claude fallback) Filed
OpenAI GPT-4.1 + GPT-4.1-mini API with Zero Data Retention Pre-pilot
Vercel Application hosting (Enterprise tier required for HIPAA) Pre-pilot
Neon Postgres hosting (Launch+ tier required for BAA) Pre-pilot
Clerk Authentication (Pro tier required for BAA) Pre-pilot
Stripe Payment processing (BAA available on standard plan) At pilot signup

If something goes wrong.

Standard HIPAA breach-notification timelines. Documented runbook. Tested annually.

Detection

Automated alerting via Sentry (errors), AWS GuardDuty (infrastructure), and custom audit-log anomaly detection. On-call engineer paged within 15 minutes of a confirmed PHI-touching event.

Containment

Affected credentials rotated, access tokens revoked, instance isolated. PHI access frozen until forensics complete. Customer admin notified within 4 hours of containment.

Notification

HIPAA Breach Notification Rule: affected customers and HHS notified within 60 days. Solace RCM commits to 24-hour preliminary notification to the agency admin for any confirmed PHI exposure.

Postmortem

Written postmortem shared with affected customers within 14 days. Root cause, blast radius, customer impact, and corrective actions. No NDAs required to read our postmortems.

Compliance review packet?

For compliance officers and security teams evaluating Solace RCM: we send a one-page BAA summary, the AI governance addendum, and the data-flow diagram. No sales call required.