Skip to content
Security and compliance

Security and compliance

Revelrex handles protected health information on behalf of practices. This page describes the controls we operate. Statements here are limited to what our documentation supports; contact us for current attestation details and scope.

HIPAA

Revelrex is HIPAA compliant and maintains a HIPAA compliance program that is reviewed continuously.

Revelrex is HIPAA compliant and SOC 2 compliant. Ask us for the current scope of our compliance documentation before relying on it for your own audits.

SOC 2

Revelrex is SOC 2 compliant. Contact us for the current status and scope.

We describe scope and status only as our report or attestation supports.

HIPAA compliance program

Revelrex operates as a business associate under HIPAA. We maintain policies for privacy, security and breach notification, sign a Business Associate Agreement with every practice where PHI is involved, and review our program continuously.

SOC 2

Revelrex is SOC 2 compliant. Contact us for the current status and the scope of any report or attestation.

Security governance

Named security and compliance owners, documented policies reviewed at least annually, and risk assessments that drive the control set.

Access controls

Least-privilege roles for staff and clients, multi-factor authentication for privileged accounts, session controls, failed-login protection and immediate disablement on departure.

Workforce security and training

Background-checked staff, HIPAA and security training at hire and annually, and role-specific training for anyone who touches practice systems.

Data protection

Encryption in transit and at rest. System-access information provided by practices is encrypted with a per-installation key, masked on screen, and every reveal is recorded in the audit log.

Incident response

A documented incident response plan with defined roles, client notification procedures aligned to the BAA, and post-incident review.

Vendor management

Sub-processors and vendors are reviewed before use, and business associate agreements are obtained where required.

Privacy practices

We collect only the information needed for the engagement, retain it according to the agreement, and return or destroy it at termination as the BAA requires.

How secure access works

System access you provide is treated as a secret, not a note

  1. 1

    Delegated accounts first

    We ask practices to create individual Revelrex user accounts in their EMR and clearinghouse rather than sharing a provider's personal login. You can revoke them any time.

  2. 2

    Encrypted at rest

    Where a credential must be stored, it is encrypted with a key unique to the installation and never appears in email or notifications.

  3. 3

    Masked on screen, revealed on purpose

    Values are masked by default. A reveal requires the right permission and is written to the audit log with who, when and from where.

  4. 4

    Revoked when no longer needed

    Practices and Revelrex can revoke or delete access records the moment an engagement changes.

Security contact

Security questions, vulnerability reports or requests for compliance documentation: contact our security team.

security@revelrex.com

Please do not send protected health information by email. Existing clients can use the support desk in their dashboard.

Need our compliance documentation for your vendor review?

We provide our policies summary, BAA template and current attestation information to prospective clients under NDA where required.