Security & compliance
Security designed around the PHI boundary
One River's application and data services operate within private US cloud environments covered by Business Associate Agreements. The public internet reaches only the protected application edge — not the databases, audio storage, or PHI-processing services.
Current verification status
US data residency
Application processing, clinical storage, audio, transcripts, and audit evidence remain in US cloud regions. PHI remains hosted in the US.
Business Associate Agreements
AWS and AI-provider services operate under Business Associate Agreements covering PHI processed on behalf of customer practices.
Encryption
TLS 1.2+ in transit and AES-256 at rest, with centrally managed keys.
Model training
Customer PHI is not used to train shared or foundation models.
Architecture
How data moves through the PHI boundary.
A simplified view of the production path — without network addresses, ports, or internal implementation detail.
- 1
EHR + encounter audio
Clinical encounter input enters the protected boundary from the practice EHR and optional audio capture.
- 2
Protected US cloud boundary
WAF → private application → encrypted storage. The public internet reaches only the protected application edge.
- 3
US-pinned AI processing under BAA
Enterprise AI services process data in US regions under Business Associate Agreements.
- 4
Structured output returned to the EHR
Documentation, coding recommendations, and claim-ready structure flow back to the EHR for human review.
EHR + encounter audio → Protected US cloud boundary (WAF → private application → encrypted storage) → US-pinned AI processing under BAA → Structured output returned to the EHR
Data security
Controls around the PHI boundary.
US-hosted PHI boundary
Application processing, clinical storage, audio, transcripts, and audit evidence remain in US cloud regions. PHI remains hosted in the US.
Private data plane
Databases, storage, and secrets are not directly reachable from the public internet. Traffic passes through a managed WAF and a protected application edge.
Encryption and key management
TLS 1.2+ in transit, AES-256 at rest, and centrally managed keys.
Controlled workforce access
MFA, approved secure connectivity, least-privilege roles, and session logging.
Continuous monitoring
Cloud activity, network traffic, configuration, vulnerabilities, and threat signals are monitored continuously.
Audit evidence
Activity is centrally logged with protected long-term retention for investigations and audit support.
AI and clinical governance
How coding stays human-accountable.
Human review before billing
Coders review and approve recommendations before any billing action is taken.
Evidence-backed recommendations
Every recommendation cites the documentation that supports it.
No unattended billing
One River never bills unattended — human-in-the-loop is required by design.
Code-to-documentation traceability
Each code carries a citation back to the note and the rule that allowed it.
Model evaluation and regression testing
Model and rule changes are evaluated against regression suites before release.
Escalation of uncertain outputs
Uncertain or low-confidence outputs are escalated for human review rather than auto-applied.
AI and your data
AI that works for you — not on your data.
One River uses US-region-pinned enterprise AI services operating under Business Associate Agreements. Customer PHI is transmitted through encrypted connections and is not used to train shared or foundation models.
Assessment data handling
How assessment data is handled.
Charts are never uploaded through the public revenue-assessment form. After we confirm the assessment, One River provides approved secure-transfer instructions. De-identified data is preferred; PHI is accepted only under an executed BAA and approved workflow. Assessment data is access-restricted, encrypted, and deleted according to the agreed retention period.
Retention duration for assessment transfers: TODO: confirm with engineering
Secure development
Security from code to production.
One River scans application code, software dependencies, and production container images before deployment. Infrastructure is reproducibly deployed through reviewed code, and deployment systems use short-lived credentials rather than permanent cloud keys.
Compliance documentation
Request our security package.
Certifications and reports are available under NDA. Tell us which documents your security or procurement team needs and we will follow up within one business day.
Prefer email? hello@oneriver.ai
Let's talk
Make billing our problem. Not yours.
Every encounter becomes a clean record, accurate codes, and a paid claim — on the EHR you already run.