Our role

When we analyze claims data for a provider, Averis acts as a business associate under HIPAA. We execute a Business Associate Agreement before any protected health information moves, and that agreement controls where it differs from this page. Where we work at the direction of outside counsel, we can be engaged so the work is positioned for privilege; your counsel decides that structure.

Minimum necessary

We request only the data needed to test the allegation: the audit period, the cited population, and the documentation that supports it. We do not request records outside the scope, and we say so in writing when a request would exceed it.

How data reaches us

  • Encrypted transfer over SFTP or a client-controlled secure share. Never email attachments, never the website.
  • Access credentials are issued per person, per engagement, and revoked at close.
  • Every transfer is logged, and every file is hashed on receipt so the manifest in your findings packet is verifiable.

Safeguards

  • Technical. Encryption in transit (TLS 1.2+) and at rest (AES-256), role-based least-privilege access, multi-factor authentication, logged and reviewed access to engagement data, network segregation between engagements.
  • Administrative. Workforce HIPAA training at hire and annually, background checks, written incident response plan, annual risk analysis, documented subprocessor review.
  • Physical. Processing in access-controlled facilities operated by our infrastructure providers, with no PHI on local or removable media.

Subprocessors

Any vendor with potential access to protected health information is under a written business associate or equivalent agreement and is reviewed before use. A current subprocessor list is available on request.

Retention and return

Engagement data lives only as long as the engagement and the retention period your agreement sets. At close, we return or destroy it at your direction and provide written certification of destruction.

Breach notification

If we discover a breach of unsecured protected health information, we notify the covered entity without unreasonable delay and within the period the Business Associate Agreement requires, with the facts we have and the facts we are still establishing. We do not wait for a complete picture to tell you something happened.

Documentation for your file

On request we provide the executed BAA, our security overview, the subprocessor list, evidence of workforce training, and the source manifest for your matter. Compliance and internal audit teams should have what they need without a follow-up.

Contact

Security and privacy inquiries, and requests for a Business Associate Agreement before you send anything, go to info@averisanalytics.com.

Draft for counsel review. This document is a structural and editorial template written to the Averis brand voice. It is not legal advice and has not been reviewed by an attorney. Have counsel confirm every clause, jurisdiction, retention period, and statutory reference before publication.