For the most sensitive records

Every default is the strict one. What the practice can prove to an auditor is what the software enforces, and nothing about a patient leaves the practice’s boundary.

Read the BAA

What the practice can prove

Role-based access

Every user is a role: owner, lead dietitian, clinician, coordinator, patient. The record shows each role only what its work needs, and the database enforces it, not the screen.

Consent-stamped recordings

A visit is recorded only after the patient consents, and the consent is stamped on the recording. Payer calls are recorded and kept for thirty days with their transcripts.

PHI stays inside the boundary

Nothing from a patient’s record is used to train a model, ours or anyone else’s. The model interprets the visit and the call; the practice holds the record.

MFA on every provider account

Multi-factor authentication for every provider sign-in. Sessions expire, and the audit log records who opened what and when.

Hosted in the United States

Data is hosted in the United States, encrypted with AES-256 at rest and TLS in transit, backed up in region, and purged on the practice’s retention schedule.

The BAA, signed at sign-up

The business associate agreement is signed when the practice signs up, before a single record exists. The sub-processors we rely on are listed on the terms page.

Built for the most sensitive records

Every default is the strict one. What the practice can prove to an auditor is what the software enforces: the BAA, the audit log, encryption at rest and in transit, retention and purge, and a boxed model that interprets but never holds the record.

Read the BAA
HIPAAPROTECTED

HIPAA

Details
BAASIGNED AT SIGN-UP
EncryptedAES-256, TLS

Encryption

Details
Audit logAPPEND ONLY

Audit log

Details
Retentionand purgeON SCHEDULE

Retention and purge

Details
BoxedmodelNEVER HOLDS

Boxed model

Details

How it holds

The controls are not a policy document. They are the way the software is built: the role decides what a screen can show, the log records every read, the model is boxed, and the recording is the receipt. What follows is what a practice owner, or an auditor, asks us first.

Book a demo

The architecture behind the guarantees.

Everything above is a promise, and a promise is worth what the proof behind it is worth. Aureum is auro’s constantly auditing architecture. It re-checks every assertion the practice makes against what the practice can actually prove, continuously rather than when someone asks: the claim against the signed note it was coded from, the note against the visit that produced it, the code against the payer rule in force on the date of service, the benefit on a claim against the recording and the reference number behind it, the ledger against the bank. Every action auro takes carries a receipt saying what it saw, what it chose, under whose authority and what happened next, and where Aureum cannot prove something it flags it rather than asserting it.

See how Aureum works →

What the AI actually sees.

Watch a record cross the membrane. Identity is stripped at the boundary; only the clinical facts move through.

The record
  • Name
  • DOB
  • Phone
  • A1c7.4%, trending down
  • GoalLower fasting glucose
PHI sanitizer
The model receives
  • Subjectpatient_4821
  • A1c7.4%, trending down
  • GoalLower fasting glucose

Name, DOB, and contact never left the database.