How We Protect Your Data - Plain English

We believe every provider deserves to trust their tools. Security is foundational to that trust. Here is exactly how we safeguard your information:

  • Your data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
  • Access is role-based - only your authorized personnel can reach your data, and only for what they need.
  • We sign a BAA before processing any Protected Health Information.
  • The free audit requires zero PHI - no patient names, dates of birth, or Social Security numbers needed.
  • Your data is portable - export or delete it anytime from your account settings.

Infrastructure Security

All data stored in apruvl is encrypted at rest using AES-256, the same standard trusted by governments and financial institutions worldwide. Every connection to our platform is protected by TLS 1.2 or higher, ensuring your data remains secure in transit.

Our infrastructure is hosted on platforms that maintain signed Business Associate Agreements, providing HIPAA-compliant environments purpose-built for healthcare data. We conduct regular security assessments and maintain documented incident response procedures to ensure continuous protection.

Access Controls

We follow the principle of minimum necessary access. Every team member at apruvl has role-based access controls that limit data visibility to only what is required for their specific responsibilities.

  • Role-based access - Permissions are assigned by role, reviewed regularly, and updated as responsibilities change.
  • Minimum necessary access - No one sees more data than their role requires.
  • Audit logging - All access to Protected Health Information is logged, monitored, and subject to regular review.
  • Multi-factor authentication - Required for all administrative and user access.

Business Associate Agreements

We execute a Business Associate Agreement (BAA) before processing any Protected Health Information. This is a binding commitment that holds us accountable to HIPAA's Privacy and Security Rules - and it is something we take seriously, every day.

Our BAA covers all aspects of data handling, including storage, processing, transmission, and disposal of PHI. If you need a BAA, reach out and we will have one ready for you.

De-identification

When we use claims data to improve our platform, we first strip it of every identifier that could connect it to a person or practice. Our de-identification process follows the Safe Harbor method defined in 45 CFR 164.514(b)(2), which requires the removal of all 18 HIPAA-defined identifiers:

  • Names, geographic data, dates (except year), phone numbers, fax numbers
  • Email addresses, Social Security numbers, medical record numbers
  • Health plan beneficiary numbers, account numbers, certificate/license numbers
  • Vehicle identifiers, device identifiers, web URLs
  • IP addresses, biometric identifiers, full-face photographs
  • Any other unique identifying number, characteristic, or code

Once de-identified, this data can never be traced back to any individual or practice. We never attempt to re-identify de-identified data.

The Free Audit - Built for Privacy

Our free claims audit was designed from the ground up to respect your privacy. It requires zero Protected Health Information:

  • No patient names needed
  • No dates of birth needed
  • No Social Security numbers needed

If your claims file includes patient IDs, they are one-way hashed using SHA-256 on receipt. The original values are never stored in plain text. You get a complete revenue recovery analysis without ever sharing sensitive patient data.

Data Portability

Your data belongs to you. You can export all of your data in standard, machine-readable formats at any time from your account settings. If you prefer, you can request a full deletion of your data - we honor all deletion requests within 30 days.

There are no hoops, no waiting periods, and no retention games. Full data portability is a right, and we treat it that way.

Contact

If you have questions about our security practices, need a BAA, or want to discuss your organization's specific requirements, we are here to help.

Phone: (813) 982-8800

Address: apruvl, inc., 1111 Oakfield Dr, Ste 115E-1644, Brandon, FL 33511

Send us a message