Skip to content
Compliance

Review the safeguards before PHI onboarding.

Upstream documents its implemented security controls and publishes the exact Business Associate Agreement used by onboarding. Review the controls, agreement, and current certification status directly.

What can a compliance reviewer verify?

Reviewers can inspect the product safeguards, canonical legal agreements, subprocessors, approval boundary, and execution records. Upstream does not claim SOC 2 or HITRUST certification. The BAA defines the parties' obligations and should be reviewed directly.

PHI encrypted and scoped

Application records are encrypted at rest and isolated by customer tenant. Integration credentials and access are scoped to the connected workflow.

Approval before payer-facing execution

An authorized reviewer sees the prepared manifest, evidence posture, destination, and unknowns before approving a payer-facing action.

Canonical BAA available for review

The public BAA route renders the exact canonical agreement used by the onboarding flow, with its source version and content hash visible.

Last updated July 10, 2026.

Implemented safeguards

The application uses encryption at rest, customer tenant scoping, role-based access, approval-gated payer actions, and execution records that preserve the reviewer, manifest, rail, attempt state, and evidence.

How PHI is protected

  • Encrypted. PHI is encrypted at rest and in transit.
  • Scoped. PHI is isolated to your practice's tenant and never pooled across customers.
  • Human-approved. Payer-facing actions require an authorized reviewer to approve the prepared manifest before execution.
  • Minimized. We collect and process only the PHI needed to do the work.
  • Reviewable. Approved executions preserve the reviewer, payload hash, rail, attempt state, and terminal evidence.

Business Associate Agreement

The agreement used by onboarding is published at /baa. That route renders the exact canonical markdown and displays its source version and SHA-256 hash. Review the agreement itself for the controlling terms.

The network and PHI

The Upstream Data API is a separate non-PHI contract. Its published schemas use payer policy references, codes, counts, aggregates, and model signals rather than patient-level clinical records. Sandbox responses are explicitly synthetic.

Reporting a concern

If you believe PHI has been handled improperly, tell us right away at security@upstream.cx so we can investigate and respond.

HIPAA, answered plainly.

Does Upstream sign a Business Associate Agreement?
The canonical Business Associate Agreement used in onboarding is available at /baa. Review that agreement directly for its scope, effective terms, safeguards, notice obligations, and termination provisions.
Where does protected health information live?
Application records are encrypted at rest and isolated by customer tenant. Access and integration credentials are scoped to the connected workflow.
Is Upstream SOC 2 or HITRUST certified?
No SOC 2 or HITRUST certification is claimed on this site. The security page describes the controls that are implemented today.
Does the Upstream Data network ever see PHI?
The Upstream Data API contract excludes patient-level fields. It uses payer policy references, codes, counts, anonymized aggregates, and model signals; sandbox responses are synthetic.
Can our team review your HIPAA posture before we sign?
Yes. Reach out and we will walk through the controls, the BAA, and the specifics of how PHI is handled in the platform.

Bring your compliance questions.

We will walk your team through the controls in place, the BAA, and where we are honest about what is still in progress. No commitment.