Skip to main content

Security & compliance

Security designed around the PHI boundary

One River's application and data services operate within private US cloud environments covered by Business Associate Agreements. The public internet reaches only the protected application edge — not the databases, audio storage, or PHI-processing services.

Current verification status

US data residency

Application processing, clinical storage, audio, transcripts, and audit evidence remain in US cloud regions. PHI remains hosted in the US.

Business Associate Agreements

AWS and AI-provider services operate under Business Associate Agreements covering PHI processed on behalf of customer practices.

Encryption

TLS 1.2+ in transit and AES-256 at rest, with centrally managed keys.

Model training

Customer PHI is not used to train shared or foundation models.

Architecture

How data moves through the PHI boundary.

A simplified view of the production path — without network addresses, ports, or internal implementation detail.

  1. 1

    EHR + encounter audio

    Clinical encounter input enters the protected boundary from the practice EHR and optional audio capture.

  2. 2

    Protected US cloud boundary

    WAF → private application → encrypted storage. The public internet reaches only the protected application edge.

  3. 3

    US-pinned AI processing under BAA

    Enterprise AI services process data in US regions under Business Associate Agreements.

  4. 4

    Structured output returned to the EHR

    Documentation, coding recommendations, and claim-ready structure flow back to the EHR for human review.

EHR + encounter audio → Protected US cloud boundary (WAF → private application → encrypted storage) → US-pinned AI processing under BAA → Structured output returned to the EHR

Data security

Controls around the PHI boundary.

US-hosted PHI boundary

Application processing, clinical storage, audio, transcripts, and audit evidence remain in US cloud regions. PHI remains hosted in the US.

Private data plane

Databases, storage, and secrets are not directly reachable from the public internet. Traffic passes through a managed WAF and a protected application edge.

Encryption and key management

TLS 1.2+ in transit, AES-256 at rest, and centrally managed keys.

Controlled workforce access

MFA, approved secure connectivity, least-privilege roles, and session logging.

Continuous monitoring

Cloud activity, network traffic, configuration, vulnerabilities, and threat signals are monitored continuously.

Audit evidence

Activity is centrally logged with protected long-term retention for investigations and audit support.

AI and clinical governance

How coding stays human-accountable.

Human review before billing

Coders review and approve recommendations before any billing action is taken.

Evidence-backed recommendations

Every recommendation cites the documentation that supports it.

No unattended billing

One River never bills unattended — human-in-the-loop is required by design.

Code-to-documentation traceability

Each code carries a citation back to the note and the rule that allowed it.

Model evaluation and regression testing

Model and rule changes are evaluated against regression suites before release.

Escalation of uncertain outputs

Uncertain or low-confidence outputs are escalated for human review rather than auto-applied.

AI and your data

AI that works for you — not on your data.

One River uses US-region-pinned enterprise AI services operating under Business Associate Agreements. Customer PHI is transmitted through encrypted connections and is not used to train shared or foundation models.

Assessment data handling

How assessment data is handled.

Charts are never uploaded through the public revenue-assessment form. After we confirm the assessment, One River provides approved secure-transfer instructions. De-identified data is preferred; PHI is accepted only under an executed BAA and approved workflow. Assessment data is access-restricted, encrypted, and deleted according to the agreed retention period.

Retention duration for assessment transfers: TODO: confirm with engineering

Secure development

Security from code to production.

One River scans application code, software dependencies, and production container images before deployment. Infrastructure is reproducibly deployed through reviewed code, and deployment systems use short-lived credentials rather than permanent cloud keys.

Compliance documentation

Request our security package.

Certifications and reports are available under NDA. Tell us which documents your security or procurement team needs and we will follow up within one business day.

Prefer email? hello@oneriver.ai

Let's talk

Make billing our problem. Not yours.

Every encounter becomes a clean record, accurate codes, and a paid claim — on the EHR you already run.