Skip to content
Clinician Standing

Data scope

We work with provider data. Patient records stay with you.

This page exists to end your security review in one reading rather than four rounds of questionnaire.

What we access

  • Credentialing files
  • Licensure records and board correspondence
  • Payer enrollment data
  • Certification and continuing education records
  • Business records: entity details, NPIs, tax identifiers, addresses

What we never access

  • Clinical systems and electronic health records
  • Patient records of any kind
  • Patient contact lists
  • Scheduling systems containing patient data

Why this matters to you

No business associate agreement is required for the core engagement, because the core engagement handles no protected health information. Your security review is short. The offshore question resolves in one sentence rather than a procurement cycle.

Delivery geography, disclosed

Work is performed by contracted teams in named countries, disclosed to you before the engagement begins and listed in your agreement. Where a state contract or payer agreement requires domestic handling, that work is routed to domestic staff and the routing is enforced at the access layer, not by policy.

Controls

  • Non-persistent virtual desktops, rebuilt at every session
  • No removable media
  • No clipboard passthrough
  • No local printing
  • Session logging
  • Geographic routing enforced at the access layer

Credentialing files are sensitive on their own terms

A credentialing file carries the clinician's Social Security number and date of birth. That is not protected health information, and we treat it at the same protection level anyway, because it triggers the breach notification statutes of all fifty states.

Start with a free roster audit

Every license, every expiry date, every Letter of Qualification clock, and your coverage gaps against the states you advertise. Two business days. You keep the output whether or not you work with us.