Skip to content

Compliance pack

BAA inventory, HIPAA SRA technical controls, audit-hash construction, and infrastructure topology — everything a BD legal or compliance counsel typically asks for in early diligence. Full source documents available on request.

Download the single-PDF Compliance Pack

Always-current version. Generated from the canonical source documents in our launch-prep repo at build time.

Download Compliance Pack (PDF) →

BAA matrix

VendorScopeStatus
AWS (Textract + S3 + Lightsail)Document OCR, encrypted offsite backups, public TLS gatewaySigned 2026-05-08
Google WorkspaceOperator mailbox + admin emailSigned 2026-05-12
PauboxTransactional email (HIPAA Email API)Signed 2026-05-16
StripePayments (PHI-free)Conduit exception
CloudflareDNS only — proxy disabledN/A

Drug-agnostic recommendation hash

Every appeal-letter generation records a SHA-256 hash of the (insurer, drug class, denial reason, ICD-10, clinical evidence) tuple that drove the recommendation. The hash is constructed before any pharma-funding-source attribution is applied, so the audit trail demonstrates that appeal logic is funding-source-independent.

Operational implementation of the Personal Services Safe Harbor "fair market value, no marketing influence" requirement: the same hash for the same clinical situation, regardless of who subsidized the appeal.

What we'll provide on request

Contact: [email protected] · Michael John Ryan, Privacy Officer, DenialHelp, LLC.

Back to Partners home