ClaimParity is built for healthcare organizations that handle sensitive remittance data. Security and HIPAA compliance are not afterthoughts — they are foundational to how the platform is designed, hosted, and operated by Prometheus Technology Systems Corp.
Security at a glance
HIPAA-ready infrastructure
Hosted exclusively on Microsoft Azure, a HIPAA-eligible cloud platform. Prometheus Technology Systems Corp operates under a Business Associate Agreement (BAA) with Microsoft.
Encryption everywhere
All data is encrypted at rest using Azure SQL Transparent Data Encryption (AES-256) and in transit using TLS 1.2 or higher. No unencrypted data paths exist in the platform.
BAA available
We execute a Business Associate Agreement with every customer who uploads Protected Health Information. BAA requests are handled within one business day.
Tenant isolation
Every customer organization is a fully isolated tenant. Your data is never commingled with another organization's data at any layer of the application or database.
Secrets management
All credentials, connection strings, and API keys are stored in Azure Key Vault — never in application code or configuration files. Access is audited and role-scoped.
Data residency
All customer data is stored and processed in Microsoft Azure data centers located in the United States. No data is transferred outside the United States.
Infrastructure
ClaimParity runs entirely on Microsoft Azure. The following components form the production infrastructure:
Compliance posture
The following table summarizes ClaimParity's current compliance status and controls:
| Control / Requirement | Status | Notes |
|---|---|---|
| HIPAA Security Rule | Compliant | Administrative, physical, and technical safeguards implemented. Azure BAA in place. |
| HIPAA Privacy Rule | Compliant | PHI use limited to service delivery. No PHI used for training, advertising, or third-party sharing. |
| Business Associate Agreement | Available | BAA executed with Microsoft Azure. Customer BAAs available upon request — contact legal@claimparity.com. |
| Encryption at rest | Enabled | AES-256 via Azure SQL TDE and Azure Storage Service Encryption. |
| Encryption in transit | Enabled | TLS 1.2 minimum enforced. HTTP redirects to HTTPS on all endpoints. |
| Access controls | Implemented | Role-based access control within tenant. Multi-tenant isolation at database and application layers. |
| Audit logging | Enabled | Application-level audit trail for data access and analysis operations. Azure activity logs retained. |
| Data residency (US) | US only | All data stored and processed in Azure US regions. No cross-border data transfer. |
| Backup & recovery | Enabled | Azure SQL automated backups with 35-day point-in-time restore. Blob storage geo-redundant replication. |
| SOC 2 Type II | Planned | SOC 2 audit planned as customer base scales. Azure infrastructure is SOC 2 certified. |
| Penetration testing | Planned | Third-party penetration test scheduled prior to enterprise customer onboarding. |
Need a Business Associate Agreement?
We execute BAAs with every customer who uploads Protected Health Information to ClaimParity. Requests are typically fulfilled within one business day. Contact our legal team to get started.
How we handle your data
When you upload remittance files or contracted rate schedules to ClaimParity:
- Files are transmitted over TLS and stored in a private Azure Blob Storage container accessible only to your tenant
- Data is parsed and written to your isolated tenant partition in Azure SQL Database
- Analysis runs entirely within Prometheus-controlled infrastructure — no data is sent to third-party AI services in the current version of the platform
- Your data is never used to train models, improve other customers' results, or for any purpose other than providing the Service to you
- Upon account termination, your data is deleted within 90 days
- You may request deletion of your data at any time by contacting privacy@claimparity.com
Demo environment
The ClaimParity demo environment at app.claimparity.com/demo contains only synthetic, fictitious data generated for demonstration purposes. No real patient data, no real provider data, and no real remittance data is present in the demo environment. A BAA is not required to access the demo.
Questions?
For security assessments, vendor questionnaires, or BAA requests, contact us at legal@claimparity.com or visit our contact page. We respond to security inquiries within one business day.