Security / Compliance
Independently audited against the standards healthcare demands, and built for the teams that can't afford to get this wrong.
Compliant with the most rigorous safety and security standards. Built for the world's leading healthcare teams.
We safeguard protected health information with HIPAA-compliant processes, policies, and technical controls, backed by a formal compliance program and a signed BAA before any PHI is exchanged.

Independently audited controls covering security, availability, and confidentiality, with annual third-party penetration testing and continuous vulnerability scanning.
Every model provider we use operates under a BAA and a zero-retention agreement. Your data is never used to train anyone's model.
Request access to our trust center below.
Request access to our trust center below.

In healthcare, governance is not optional. It is the entire game. Without visibility, controls, and accountability, AI adoption either stalls or creates unacceptable risk. Cofactor embeds governance directly into the platform, so every interaction, workflow, and model output is observable, auditable, and controllable over time.
Every model provider we work with operates under a BAA and a zero-retention agreement. Data is de-identified before it is used to improve the system, and a person reviews the work before it goes out. Leaders get enterprise-wide oversight into how AI is used and how it performs, which makes AI something executives can confidently expand rather than cautiously contain.

Single sign-on with your existing identity provider, with MFA enforced through your own policy. Role-based access is managed inside Cofactor, every user has a unique ID, and there are no shared or generic accounts. Every action is logged and traceable to an individual.

Integrate once. Power everything. Cofactor connects to your core systems, including EHRs, data warehouses, claims, and operational sources, through a single secure integration. That one connection becomes the backbone for everything that follows, so as your AI footprint grows, your integration burden does not.
Data is stored onshore in the US and encrypted at rest with AES-256 and in transit with TLS 1.2 or higher. Connections use allowlisted static IPs, and no deprecated ciphers are permitted. Nothing you send us is used to train a model. Agents built in Studio run inside a governed environment with the same access controls and audit logging as everything else we deploy, so building something new never means working around your security posture.
Yes. Cofactor is HIPAA Type II audited, with BAAs in place covering all data handling, including with our AI model providers. Our compliance program includes regular risk assessments, documented policies and procedures, and ongoing employee training.
We limit PHI storage to what's strictly necessary, encrypt all data at rest and in transit, and enforce role-based access controls with full audit logging on every access event. Sensitive data is de-identified before it's used to improve our AI models, and we maintain BAAs with our AI model providers to ensure zero-retention, HIPAA-compliant use outside our environment.
We collect only what's needed to process denials and generate appeals: patient demographics, clinical and treatment records, coding information, claims and remittance data, denial letters, and payer details. Data collection is scoped to the minimum necessary for the service, in line with HIPAA's minimum-necessary standard.
Data retention follows your organization's preferences and applicable regulatory requirements. Automated purging policies apply to PHI beyond what's needed for active use, and upon contract termination, your data is returned or securely destroyed according to your instructions.
All data is encrypted using AES-256 (or higher) at rest and TLS/HTTPS in transit. This applies across our platform, including data moving to and from EMRs and clearinghouses.
Access is role-based and scoped to job function, with periodic access reviews. Integrations use secure, standards-based authentication (OAuth2 for FHIR, encrypted SFTP with IP allowlisting for file transfers), so only authorized systems and personnel can interact with sensitive data.
We maintain a documented incident response plan covering threat containment, notification of affected parties, and cooperation with regulatory bodies as required. Breach notifications follow HIPAA's required timeline. We conduct a post-incident review after any event to strengthen safeguards going forward.
Cofactor is a cloud-based SaaS platform, built to scale with your organization's denial volume without adding infrastructure burden on your team. Integration is designed to fit into your existing systems rather than require changes to them -- see our Integrations page for details on setup and supported systems.
Our models go through a multi-stage evaluation process combining automated testing with subject matter expert review, on an ongoing evaluation cycle. We test before every release, monitor for drift, and maintain the ability to roll back model updates. Human-in-the-loop review remains part of the workflow before any output is finalized.
Compliance is built into our development and operations lifecycle, not treated as a one-time certification. This includes regular third-party audits (SOC 2 Type II, HIPAA Type II), internal risk assessments, and ongoing monitoring of regulatory requirements. Our corporate website also adheres to GDPR data handling practices.
We integrate with major EMRs including Epic, Cerner, and Meditech via FHIR APIs, with Athena and HL7v2 support available depending on your organization's setup. On the claims side, we connect with SFTP-enabled clearinghouses such as Availity, Change, Waystar, and Quadax. Full technical details are on our Integrations page.