Security and compliance
Revelrex handles protected health information on behalf of practices. This page describes the controls we operate. Statements here are limited to what our documentation supports; contact us for current attestation details and scope.
HIPAA
Revelrex is HIPAA compliant and maintains a HIPAA compliance program that is reviewed continuously.
Revelrex is HIPAA compliant and SOC 2 compliant. Ask us for the current scope of our compliance documentation before relying on it for your own audits.
SOC 2
Revelrex is SOC 2 compliant. Contact us for the current status and scope.
We describe scope and status only as our report or attestation supports.
HIPAA compliance program
Revelrex operates as a business associate under HIPAA. We maintain policies for privacy, security and breach notification, sign a Business Associate Agreement with every practice where PHI is involved, and review our program continuously.
SOC 2
Revelrex is SOC 2 compliant. Contact us for the current status and the scope of any report or attestation.
Security governance
Named security and compliance owners, documented policies reviewed at least annually, and risk assessments that drive the control set.
Access controls
Least-privilege roles for staff and clients, multi-factor authentication for privileged accounts, session controls, failed-login protection and immediate disablement on departure.
Workforce security and training
Background-checked staff, HIPAA and security training at hire and annually, and role-specific training for anyone who touches practice systems.
Data protection
Encryption in transit and at rest. System-access information provided by practices is encrypted with a per-installation key, masked on screen, and every reveal is recorded in the audit log.
Incident response
A documented incident response plan with defined roles, client notification procedures aligned to the BAA, and post-incident review.
Vendor management
Sub-processors and vendors are reviewed before use, and business associate agreements are obtained where required.
Privacy practices
We collect only the information needed for the engagement, retain it according to the agreement, and return or destroy it at termination as the BAA requires.
System access you provide is treated as a secret, not a note
- 1
Delegated accounts first
We ask practices to create individual Revelrex user accounts in their EMR and clearinghouse rather than sharing a provider's personal login. You can revoke them any time.
- 2
Encrypted at rest
Where a credential must be stored, it is encrypted with a key unique to the installation and never appears in email or notifications.
- 3
Masked on screen, revealed on purpose
Values are masked by default. A reveal requires the right permission and is written to the audit log with who, when and from where.
- 4
Revoked when no longer needed
Practices and Revelrex can revoke or delete access records the moment an engagement changes.
Security contact
Security questions, vulnerability reports or requests for compliance documentation: contact our security team.
security@revelrex.comPlease do not send protected health information by email. Existing clients can use the support desk in their dashboard.
Need our compliance documentation for your vendor review?
We provide our policies summary, BAA template and current attestation information to prospective clients under NDA where required.