HIPAA and security
Averis works with protected health information at scale. These are the commitments that make that safe for you and defensible for your counsel.
Last updated 9 August 2026
Our role
When we analyze claims data for a provider, Averis acts as a business associate under HIPAA. We execute a Business Associate Agreement before any protected health information moves, and that agreement controls where it differs from this page. Where we work at the direction of outside counsel, we can be engaged so the work is positioned for privilege; your counsel decides that structure.
Minimum necessary
We request only the data needed to test the allegation: the audit period, the cited population, and the documentation that supports it. We do not request records outside the scope, and we say so in writing when a request would exceed it.
How data reaches us
- Encrypted transfer over SFTP or a client-controlled secure share. Never email attachments, never the website.
- Access credentials are issued per person, per engagement, and revoked at close.
- Every transfer is logged, and every file is hashed on receipt so the manifest in your findings packet is verifiable.
Safeguards
- Technical. Encryption in transit (TLS 1.2+) and at rest (AES-256), role-based least-privilege access, multi-factor authentication, logged and reviewed access to engagement data, network segregation between engagements.
- Administrative. Workforce HIPAA training at hire and annually, background checks, written incident response plan, annual risk analysis, documented subprocessor review.
- Physical. Processing in access-controlled facilities operated by our infrastructure providers, with no PHI on local or removable media.
Subprocessors
Any vendor with potential access to protected health information is under a written business associate or equivalent agreement and is reviewed before use. A current subprocessor list is available on request.
Retention and return
Engagement data lives only as long as the engagement and the retention period your agreement sets. At close, we return or destroy it at your direction and provide written certification of destruction.
Breach notification
If we discover a breach of unsecured protected health information, we notify the covered entity without unreasonable delay and within the period the Business Associate Agreement requires, with the facts we have and the facts we are still establishing. We do not wait for a complete picture to tell you something happened.
Documentation for your file
On request we provide the executed BAA, our security overview, the subprocessor list, evidence of workforce training, and the source manifest for your matter. Compliance and internal audit teams should have what they need without a follow-up.
Contact
Security and privacy inquiries, and requests for a Business Associate Agreement before you send anything, go to info@averisanalytics.com.