Last updated July 10, 2026.
Implemented safeguards
The application uses encryption at rest, customer tenant scoping, role-based access, approval-gated payer actions, and execution records that preserve the reviewer, manifest, rail, attempt state, and evidence.
How PHI is protected
- Encrypted. PHI is encrypted at rest and in transit.
- Scoped. PHI is isolated to your practice's tenant and never pooled across customers.
- Human-approved. Payer-facing actions require an authorized reviewer to approve the prepared manifest before execution.
- Minimized. We collect and process only the PHI needed to do the work.
- Reviewable. Approved executions preserve the reviewer, payload hash, rail, attempt state, and terminal evidence.
Business Associate Agreement
The agreement used by onboarding is published at /baa. That route renders the exact canonical markdown and displays its source version and SHA-256 hash. Review the agreement itself for the controlling terms.
The network and PHI
The Upstream Data API is a separate non-PHI contract. Its published schemas use payer policy references, codes, counts, aggregates, and model signals rather than patient-level clinical records. Sandbox responses are explicitly synthetic.
Reporting a concern
If you believe PHI has been handled improperly, tell us right away at security@upstream.cx so we can investigate and respond.