The regulatory and risk environment you operate in — and where the platform sits inside it.

Most vendor compliance pages are a wall of logos. This one names the credential, states its current status, and separates what the software does from what remains your organization's obligation. If a line here matters to your contract, ask us for the underlying document — we will send it.

Note. This page is a description of product capability and compliance posture. It is not legal advice, and it does not transfer any regulatory obligation from your organization to Clovai. Your counsel and compliance officer remain responsible for determining what applies to you.

Each one, with its actual status

A certification is issued for a specific product version by a specific body, for a specific period. We list ours that way, because that is the only way the statement is useful to your compliance officer.

Held today
In progress
On the roadmap
Built into the product
In progress
ONC Health IT Certification (CEHRT)
ONC-Authorized Certification Body · 45 CFR Part 170

Certification is granted per product version against named criteria and listed publicly on the CHPL. Ask us for the certificate and CHPL identifier that applies to the version and contract term you are buying — and put it in the agreement.

Built into the product
HIPAA Security & Privacy Rule controls
45 CFR Parts 160 & 164 · self-assessed against NIST SP 800-66

Access control, unique user identification, automatic logoff, encryption in transit and at rest, immutable audit controls, integrity controls and transmission security. A Business Associate Agreement is executed before any PHI is loaded.

In progress
SOC 2 Type II
Independent CPA firm · AICPA Trust Services Criteria

Security, Availability and Confidentiality criteria over an observation window. The report is shared under NDA. Ask for the observation period, the scope and any exceptions noted — a report with no exceptions and a two-month window is not the same as a clean twelve-month one.

On the roadmap
HITRUST CSF certification
HITRUST Alliance

Frequently required by health systems and larger payers as a condition of vendor onboarding. On the roadmap; not held today. If your procurement process requires it, tell us during evaluation so we can talk about timing honestly.

In progress
EPCS certification
Third-party auditor · DEA 21 CFR Part 1311

Electronic prescribing of controlled substances requires an independent audit or certification of the application before it can be used for Schedule II–V prescribing. Confirm the current certification and its date before enabling EPCS for your providers.

In progress
e-Prescribing network certification
Surescripts · NCPDP SCRIPT

Network certification for new prescriptions, renewals, medication history, formulary and benefit, and real-time prescription benefit. Required to route prescriptions to retail and mail-order pharmacies.

Built into the product
Accessibility — WCAG 2.1 AA
Self-assessed · relevant to ACA §1557 and Section 508

Patient-facing surfaces are built to WCAG 2.1 AA. A VPAT can be provided for procurement. Federally funded organizations frequently need this in writing — ask early rather than at contract signature.

On the roadmap
National network participation
TEFCA / QHIN · Carequality · CommonWell

Query-based exchange with other organizations through a national framework. On the roadmap. Today, exchange runs through direct FHIR R4 APIs, C-CDA document exchange and Direct secure messaging.

Built into the product
PCI DSS — via tokenized processing
Card data handled by a PCI DSS Level 1 processor

Clovai never stores primary account numbers. Card entry is tokenized by the payment processor, which reduces your PCI scope. Your merchant agreement and your own PCI obligations remain yours.

If a credential you require is not listed as held today, we will tell you that in the evaluation rather than at implementation. A vendor who is vague about certification status during the sales cycle will be vague about it during your audit.

What applies to an ambulatory operation, and how the platform handles it

Grouped the way a compliance officer thinks about it, not the way a feature list is organized.

🔐

Privacy & data protection

HIPAA Privacy Rule
Minimum necessary & patient rights

Role-based access scoped to the minimum necessary, patient access and amendment requests tracked to the statutory deadline, accounting of disclosures, and restriction requests recorded against the record.

HIPAA Security Rule
Administrative, physical & technical safeguards

Unique user identification, MFA, automatic logoff, emergency access procedure, immutable audit controls, integrity verification and encryption in transit and at rest.

HITECH Breach Rule
Breach detection & notification support

Access-log analytics to identify impermissible access, plus the reporting needed to meet the 60-day individual notification and annual HHS reporting obligations.

42 CFR Part 2
Substance use disorder records

Segmented consent and disclosure controls for SUD treatment records, which carry stricter re-disclosure rules than general PHI.

State privacy law
State-specific rights & consent

Configurable consent capture and data-subject request handling for states with additional requirements beyond HIPAA.

Part 2 / minor consent
Adolescent & sensitive-service confidentiality

Configurable proxy access rules so a parent portal account does not expose services a minor consented to independently under state law.

🔌

Interoperability & data rights

Cures Act
Information blocking

Electronic health information is made available without special effort, delay or fee. Access, exchange and use are not conditioned on staying a customer.

USCDI
Standardized data classes

Data captured and exposed in the standardized classes and elements that define the U.S. Core Data for Interoperability.

FHIR R4
Patient and population APIs

Standards-based single-patient and multi-patient API access, including for third-party apps the patient authorizes.

C-CDA / Direct
Document exchange

Consolidated CDA generation and consumption, plus Direct secure messaging for referrals and transitions of care.

Public health
ELR, eCR, IIS and syndromic reporting

Electronic lab reporting, electronic case reporting, immunization registry submission and syndromic surveillance where your jurisdiction requires it.

Data portability
Your right to leave

A complete, structured export of your organization's data on demand, at any time, at no charge — written into the agreement rather than promised on a page.

🩺

Clinical & prescribing

DEA 21 CFR 1311
EPCS two-factor requirements

Identity proofing, two-factor authentication, logical access controls and the auditable record DEA requires for electronic controlled-substance prescribing.

State PDMP
Prescription monitoring queries

PDMP query at the point of prescribing, with the check recorded in the encounter — many states mandate the query and the documentation of it.

CLIA
Waived and moderate-complexity testing

In-office test ordering and resulting with the CLIA certificate number carried onto the claim, plus QC documentation for the tests you perform.

Clinical decision support
Interaction, allergy and duplicate checks

Fired at order entry rather than after signature, with override reasons captured — the override record is what an audit asks for.

Telehealth
Modality, POS and licensure

Place of service 02/10 and modifiers applied automatically; provider licensure tracked by state with warnings when a scheduled visit falls outside an active license.

Patient safety
Results acknowledgment

Closed-loop acknowledgment so an abnormal result cannot sit unreviewed — one of the most common sources of ambulatory malpractice exposure.

💵

Revenue cycle & payment integrity

HIPAA X12 5010
Standard transactions

270/271, 276/277, 278, 834, 837P/837I and 835 in the mandated formats and versions.

NCCI
Correct coding edits

Procedure-to-procedure and medically-unlikely edits applied before submission, with the modifier logic that determines whether a bypass is legitimate.

LCD / NCD
Medical necessity

Local and national coverage determinations checked against the diagnosis and procedure combination before the claim leaves.

No Surprises Act
Good Faith Estimates

Generated within statutory timelines for self-pay and uninsured patients, with delivery tracked and retained as evidence.

False Claims Act
Documentation-to-claim integrity

Charges derived from the signed documentation, level-of-service support surfaced at coding, and an audit trail linking every claim line to what was documented and by whom.

MACRA / MIPS
Quality program reporting

Quality, Promoting Interoperability and Improvement Activities measures computed continuously with numerator and denominator detail.

💊

Pharmacy & supply chain

DSCSA
Transaction data & traceability

T3 capture, matching and six-year retention, saleable-return verification, and a documented suspect/illegitimate product workflow.

DEA
Controlled substance accountability

Perpetual inventory by NDC, witnessed waste with reason codes, biennial inventory support and Form 222 / CSOS electronic ordering.

340B
Program integrity

Encounter-level eligibility, NDC accumulation, split billing, replenishment tracking and duplicate-discount prevention with a HRSA-audit-shaped trail.

USP <797> / <800>
Compounding & hazardous drugs

Documentation support for compounding logs and hazardous drug handling where your operation performs them.

FDA / recalls
Recall response

Lot-to-patient traceability so a recall is answered by naming affected patients rather than estimating a date range.

Cold chain
Storage conditions

Continuous temperature monitoring with excursion alerts and retained logs — what a surveyor asks to see, produced as a report.

🪪

Workforce & program integrity

OIG / SAM
Exclusion screening

Monthly screening of employees, contracted providers and vendors against the LEIE and SAM, with the search evidence retained — federal guidance expects monthly, and the penalty runs per claim.

Credentialing
Primary source verification

Licenses, DEA registrations, board certification, malpractice coverage and CAQH attestations tracked to expiration with documented verification.

Payer enrollment
Enrollment & revalidation

Status by provider, NPI and payer, including effective dates — so services are not rendered under a provider who is not yet enrolled.

OSHA
Workplace safety training

Bloodborne pathogens, hazard communication and workplace violence prevention training assigned by role with signed attestations.

FLSA / ACA
Employment compliance

Overtime calculated on actual worked hours, exempt/non-exempt classification tracking, and ACA applicable-large-employer and 1095-C reporting computed year-round.

Compliance program
The seven elements

Policy acknowledgment, training records, reporting mechanism logs and corrective action documentation — the artifacts an effective compliance program has to be able to produce.

Six exposures, and what actually reduces each one

Written the way your compliance committee would write it: the question being asked, where the loss actually occurs, the controls, and the evidence you would produce if someone asked you to prove it.

💸

Revenue & reimbursement risk

"How much of what we earned are we failing to collect, and why?"
Exposure

Denials that are never reworked, claims that pass a payer's timely-filing limit, services rendered without a required prior authorization, payments below the contracted rate absorbed as "contractual adjustment," and patient balances that age past collectability. Most of this is invisible until it is written off — the loss looks like a rounding line rather than a failure.

Controls in the platform
  • Eligibility verified at booking and again before the date of service
  • Authorization requirement checked by payer and procedure code before the service
  • NCCI, MUE, LCD/NCD and payer-specific edits applied before submission
  • Contract-rate variance detected on every remittance line
  • Timely-filing countdown per payer with escalation before the deadline
  • Denial worklists grouped by CARC/RARC root cause, ranked by recoverable dollars
Evidence you can produce

Clean claim rate, first-pass yield, denial rate by root cause, net collection rate, A/R aging by payer, and underpayment variance — all reportable by period, provider and site.

⚖️

Regulatory & audit risk

"If a payer or the OIG audits us tomorrow, can we defend what we billed?"
Exposure

False Claims Act liability for services that documentation does not support, RAC/TPE/UPIC audits and the extrapolated repayments that follow, level-of-service and medical-necessity challenges, and Stark and Anti-Kickback exposure in referral and compensation arrangements. The costly part is rarely the individual claim — it is the extrapolation across a sample.

Controls in the platform
  • Charges derived from the signed documentation, not entered separately
  • Level-of-service support surfaced at the point of coding
  • Immutable audit trail linking each claim line to the documentation and the author
  • Addenda preserved rather than overwritten, with time and attribution
  • Provider compensation and referral data reportable for arrangement review
  • Audit response packages assembled from the record on request
Evidence you can produce

A complete encounter package — note, orders, results, coding rationale, authorization, and the full revision history with attribution — produced as an export rather than reconstructed by hand.

🔐

Privacy & cybersecurity risk

"What happens to patient care and to our liability if we are compromised?"
Exposure

Ransomware with clinical downtime, impermissible access by insiders, breach notification duties within 60 days, OCR enforcement and state attorney general actions, and third-party compromise through a vendor with access to your environment. Healthcare remains among the most targeted sectors, and ambulatory organizations are targeted precisely because they are assumed to be less defended.

Controls in the platform
  • Tenant isolation, encryption in transit and at rest, and key separation
  • MFA and role-based least privilege by module, action and site
  • Immutable access logs with analytics to detect impermissible access
  • Tested backups with geographic redundancy
  • Documented downtime and read-only continuity procedures
  • Subcontractor BAAs and periodic vendor reassessment
Evidence you can produce

Access logs per user and per record, the security assessment and penetration test summaries, restore test records, and the executed BAA with its subcontractor schedule.

🩺

Clinical & patient safety risk

"What could hurt a patient, and would we find out in time?"
Exposure

Medication errors and missed interactions or allergies, abnormal results that nobody acknowledges, referrals that never close, care gaps in chronic and preventive management, and documentation that will not withstand review if the case becomes a claim. Failure to follow up on an abnormal result is one of the most common ambulatory malpractice allegations.

Controls in the platform
  • Interaction, allergy and duplicate-therapy checking at order entry with override reasons captured
  • Closed-loop results acknowledgment — abnormal results cannot silently expire
  • Referral loop closure with an aging report on what has gone unanswered
  • Care-gap registries by condition and panel
  • Structured documentation with full revision attribution
Evidence you can produce

Results acknowledgment turnaround, unclosed referral aging, care-gap closure rates, and override reason reporting by provider.

🪪

Workforce & credentialing risk

"Is every person billing under a valid credential, today?"
Exposure

An expired state license, a lapsed DEA registration, a missed payer revalidation, or an employed or contracted individual on the OIG exclusion list. Any one of these makes already-rendered services retroactively unbillable — and in the exclusion case, exposes the organization to civil monetary penalties on every claim the excluded person touched, plus repayment.

Controls in the platform
  • Every credential tracked to expiration with escalating alerts months in advance
  • Monthly OIG LEIE and SAM screening across employees, contracted providers and vendors
  • Screening evidence retained with search date, result and reviewer
  • Payer enrollment and revalidation status visible by provider, NPI and payer
  • Primary source verification documented with source and date
Evidence you can produce

The credentialing file per provider, the monthly screening log with retained results, and an enrollment status report by NPI and payer.

🔓

Interoperability & vendor lock-in risk

"Do we control our own data, or does our vendor?"
Exposure

Information-blocking exposure when patients or their apps cannot get electronic health information, referral partners who cannot receive records, and the renewal conversation where the cost of leaving is deliberately higher than the cost of staying. Lock-in is not an accident of architecture; in this market it is frequently a commercial strategy.

Controls in the platform
  • FHIR R4 API access to USCDI data for patients and the apps they authorize
  • C-CDA document exchange and Direct secure messaging for transitions of care
  • Closed-loop referral exchange with partners
  • Complete structured export of your data on demand, at no charge, written into the agreement
  • No fee for access, exchange or use that would constitute information blocking
Evidence you can produce

API access logs, export records, and the data-portability clause in your service agreement — the one you should read before you sign, not after.

Security posture

Healthcare is the most attacked sector. We build like it.

Ransomware against a practice is not an IT incident — it is a clinical safety event, a HIPAA breach and a revenue interruption at the same time. These are the controls behind the platform.

Tenant isolation

Every customer runs in a logically isolated tenant with its own data boundary. There is no shared table where one organization's query could reach another's records.

Encryption

TLS 1.2+ in transit and AES-256 at rest, including backups. Key management is separated from application access.

Identity & access

Unique named accounts, MFA, role-based least privilege scoped by module, action and site, automatic session timeout, and SSO/SAML on the higher tiers.

Audit logging

Immutable, tamper-evident logs of every read and write to PHI, retained and searchable — this is both a HIPAA requirement and your first tool in a breach investigation.

Backup & recovery

Automated backups with geographic redundancy and periodically tested restores. A backup that has never been restored is a hypothesis, not a control.

Vulnerability management

Dependency scanning, patch management on a defined cadence, and periodic third-party penetration testing with findings tracked to closure.

Vendor & subcontractor risk

Subcontractors that touch PHI are under BAAs, assessed before onboarding and reviewed periodically. Your BAA names them.

Downtime procedures

Documented read-only access and downtime workflows, because "the system is unavailable" cannot mean "the clinic stops seeing patients."

AI governance

PHI stays inside your tenant and never trains models shared across customers. AI-assisted actions require human approval and are fully attributed in the audit log.

What is ours, and what stays yours

No software makes an organization compliant. A vendor who implies otherwise is selling you a false sense of coverage that will not survive contact with an auditor. Here is the honest split.

Area Clovai is responsible for Your organization is responsible for
HIPAA Safeguards on the platform, BAA execution, breach notification to you as required, and subcontractor management. Your policies and procedures, workforce training and sanctions, your risk analysis, physical safeguards at your sites, and notification to individuals and HHS.
Access control Role-based permissions, MFA, session controls and audit logging capability. Deciding who gets which role, reviewing access periodically, and removing access when someone leaves — the same day.
Coding & billing Edits, scrubbing, standard transactions, and an audit trail linking claims to documentation. The accuracy of clinical documentation and code selection. The claim is submitted under your NPI and your certification.
Credentialing Tracking, alerting and screening automation with retained evidence. Acting on the alerts, performing and attesting to verification, and the credentialing decision itself.
Clinical decisions Decision support, alerts and AI-drafted suggestions, all requiring human approval. Every clinical judgment. Decision support is an input to a licensed clinician, never a substitute for one.
Controlled substances EPCS technical controls, PDMP integration, perpetual inventory and the auditable record. Your DEA registration, prescribing decisions, physical security of stock, and biennial inventory execution.
340B Eligibility logic, accumulation, split billing and audit trail. Covered entity status, contract pharmacy arrangements, policies, and HRSA audit response.
Business continuity Platform availability, backups, tested restores and status communication. Your downtime procedures, staff training on them, and the clinical decision about continuing to see patients during an outage.

Your records are yours. That should not be a differentiator, but it is.

The Cures Act made information blocking unlawful. It did not make every vendor cooperative. These commitments are in the service agreement, not just on this page.

Complete export, any time, no charge

A full structured export of your clinical, financial and operational data on demand — whether you are staying or leaving. No exit fee, no "data extraction project," no per-record charge.

Standards-based APIs

FHIR R4 single- and multi-patient access to USCDI data, available to your patients and the third-party applications they authorize, without special effort or delay.

No blocking practices

We do not condition access, exchange or use of electronic health information on remaining a customer, and we do not charge fees that would constitute information blocking.

Document exchange

C-CDA generation and consumption plus Direct secure messaging, so transitions of care actually carry the record with them.

Your integrations survive us

Documented, versioned APIs with deprecation notice periods. If we change something you built on, you find out with time to react, not in a release note after the fact.

Transparent uptime

Availability commitments defined in the agreement with a status page and incident history — including the incidents that did not go well.

What happens on the worst day

The measure of a platform is not whether it has an incident. It is what your practice can still do while one is happening, and how quickly you learn about it.

Detection & escalation

Monitoring with defined severity levels and escalation paths. Security incidents that may involve PHI trigger the notification process defined in your BAA.

Notification to you

Communication within the timeframes your BAA specifies, with the information you need to meet your own 60-day individual notification obligation — not a summary weeks later.

Clinical continuity

Read-only access and documented downtime workflows so patients can still be seen and documentation can be reconciled afterward.

Revenue continuity

Claims queue and submit once service is restored. Timely-filing exposure is tracked through the incident rather than discovered after it.

Recovery objectives

RTO and RPO defined in the agreement, with restores tested rather than assumed.

Post-incident review

A written root cause and corrective action summary shared with affected customers. If it happened once and nothing changed, it will happen again.

Documents available under NDA

Procurement, compliance and IT security teams should not have to take a website's word for it. Ask, and we will send these.

Request the compliance package →
Business Associate Agreement template with subcontractor schedule
SOC 2 Type II report (once issued) with scope and observation period
Security architecture and data flow overview
HIPAA Security Rule control mapping (NIST SP 800-66 aligned)
Penetration test executive summary
ONC certification records and CHPL identifiers, by product version
Disaster recovery plan with RTO/RPO and restore test results
Accessibility conformance report (VPAT)
Subprocessor list and vendor risk assessment summary
Standard service agreement including data portability and uptime terms

Bring your compliance officer to the demo.

Seriously. The questions they ask are the ones worth answering, and we would rather answer them now than at implementation.