Skip to content

Security and compliance

Careful with patient data, by default.

Our practices on every engagement. We claim no certifications we do not hold.

01Security and compliance

Careful with patient data.

Our practices on every engagement. We claim no certifications we do not hold.

  • BAA before any PHI

    Plus a Part 2 agreement for SUD records.

  • Minimum necessary data

    Only the fields a task needs.

  • Encryption and MFA

    In transit, at rest, named users.

  • Specialist review

    Every appeal, before it is sent.

  • No portal scraping

    Clearinghouse and payer APIs only.

  • Payer-side only

    We never contact patients.

  • AI under a BAA

    Your data never trains a model.

  • No referral payments

    None paid, none accepted.

Agreements before data

We start with de-identified reports. Before any protected health information changes hands we sign a business associate agreement (BAA). For substance use disorder records we also sign an agreement that covers 42 CFR Part 2.

Want to check your own readiness? Use our free Part 2 and BAA checklist.

Minimum necessary, by design

Each task gets only the fields it needs. A claim-status check does not need clinical notes. An appeal draft needs the pages that support it, not the whole chart.

Official connections only

We connect through your clearinghouse and payer APIs. We do not run bots on payer portals or scrape screens. Where a payer only accepts portal submissions, a credentialed person submits and the confirmation is logged.

AI with a human in charge

AI tools run only under a BAA, and your data never trains a model. Agents sort and draft. A specialist checks every statement against the chart and approves every appeal before it is sent. Codes are never changed to fit an appeal.

This page describes our practices. It is not legal advice; your counsel should review any agreement before you sign it.

Next step

Book a denial review.

Twenty minutes. No patient data needed.

Or email hello@skygathering.com