Our commitment
ABA AuditShield acts as a Business Associate to ABA agencies that use our platform to review, score, and correct clinical documentation. We sign a Business Associate Agreement (BAA) with every customer who will use the platform with Protected Health Information.
Technical safeguards
TLS 1.2+ in transit. AES-256 at rest across all databases, backups, and object storage.
Row-Level Security on every PHI table. Role-based access (Owner, Compliance, Clinical Director, Clinician, Billing).
Every PHI view, export, and change is recorded with actor, timestamp, and IP. Logs cannot be edited or deleted.
Leaked-password detection (HIBP), brute-force lockout, 15-minute idle auto-logout, and SSO/MFA support.
Hosted on SOC 2 Type II infrastructure in HIPAA-eligible regions. Daily encrypted backups with point-in-time recovery.
Agency tenants are strictly isolated. Internal staff cannot view PHI without an approved, logged break-glass request.
Documented incident response plan. We notify covered entities of any confirmed breach within 24 hours.
We execute BAAs with every customer that handles PHI and with every subprocessor in our supply chain.
Administrative safeguards
- Designated Security Officer and Privacy Officer.
- Annual HIPAA workforce training with documented completion.
- Documented risk analysis and risk-management plan reviewed annually.
- Background checks and confidentiality agreements for all workforce members with potential PHI access.
- Sanction policy for HIPAA policy violations.
- Documented sub-processor due diligence and BAA on file for every vendor.
Physical safeguards
Production systems run on cloud infrastructure that maintains SOC 2 Type II and ISO 27001 attestations and operates HIPAA-eligible services. Physical access to data center facilities is controlled by the underlying cloud provider. ABA AuditShield workforce members do not have physical access to production servers.
Audit logging
Every PHI access, modification, export, and authentication event is recorded in an append-only audit log. Logs are retained for at least six years as required by 45 CFR §164.316(b)(2). Owners and Compliance roles can review and export the log directly from the application.
Reporting a vulnerability
To report a suspected security vulnerability or privacy concern, email security@abaauditshield.com. We acknowledge reports within one business day.