Security & compliance
Security and compliance for ASC data
A system that does administrative work — not just reports on it — has to clear a higher bar. Perivanta is built for HIPAA-regulated environments, with business associate agreements, encryption, access controls, audit logging, granular automation authority, and a SOC 2 Type II roadmap ahead of general availability.
How we handle PHI
Business associate agreements
We operate under BAAs with the centers we work with. PHI handling responsibilities are contractual before any data moves.
Encryption everywhere
Data is encrypted in transit (TLS 1.2+) and at rest. Keys are managed through hardened cloud key-management services.
Least-privilege access
Role-based access controls on every surface, for our customers and for our own team. Production access is limited, logged, and reviewed.
Audit logging
Access to systems handling PHI is logged and auditable — who touched what, when, and why is answerable, not assumed.
Data minimization
We ingest what the platform needs to do its job and no more. De-identified or limited data sets are used wherever the work allows.
Tenant isolation
Each center’s data is logically isolated. One customer’s data is never used to answer another customer’s question without explicit agreement.
How we build AI that acts in a clinical business
Authority is granted, never assumed
Automation runs within explicit, per-action policies your center configures — observe, draft, approve, or autopilot with exceptions. Consequential actions like financial waivers, appeals, write-offs, and payer attestations stay with authorized people, and clinical judgment is never automated.
Every action is evidenced and reversible
What the system did, why it did it, and which source evidence it relied on is recorded and reviewable — and a person can always intervene, correct, or take an action type back to supervised mode.
Customer-controlled data use
Customer data is used to serve that customer. Any broader use — benchmarking, model improvement — happens only under terms agreed in writing, with de-identification appropriate to the use.
Our compliance roadmap
Current status:
- NowHIPAA-aligned architecture and operations: BAAs, encryption, access controls, audit logging, and workforce security practices as described above.
- RoadmapSOC 2 Type II examination ahead of general availability. We’ll publish the report’s availability here when it’s complete.
Security questions, disclosure reports, or diligence requests: hello@perivantahealth.com. We respond to security reports as a priority.
Design partner program
Help build the system that does the work
We are selecting a small group of founding centers to shape the platform. Design partners get early access, direct input on the roadmap, and founding-partner terms.