Skip to content
Security and privacy

Patient data handled the way you would want yours handled.

You are trusting us with the most sensitive records a practice holds. Here is how we keep it: scoped access, human approval, and a posture we can explain plainly.

How does Upstream keep patient data safe?

Upstream encrypts application records at rest, scopes records and integrations to the customer, and requires a reviewer to approve payer-facing actions. Execution records keep the approved manifest, rail, attempt state, and evidence connected for later review.

Scoped to your practice

Application records and integration credentials stay customer-scoped. Upstream Data uses a separate non-PHI API contract.

Approved by your people

The platform prepares payer-facing work, but an authorized reviewer decides whether the proposed action can run.

Stated honestly

We describe the controls and posture we actually have. No inflated certification language, no soft claims hiding hard edges.

Posture you can check, not promises you have to trust.

PHI encrypted and scoped to your practice

Application records are encrypted at rest and tenant-scoped. The Upstream Data API is a separate non-PHI contract for payer policies, codes, aggregates, and model signals.

Payer-facing work requires approval

The platform prepares the action manifest. A reviewer sees the destination, payload posture, evidence, and unknowns before a payer-facing execution is approved.

Execution records preserve accountability

Approved work is linked to its reviewer, manifest, payload hash, rail, attempt state, and terminal evidence so operators can reconstruct what happened.

Least-privilege access

Application roles and integration credentials are scoped to the customer and workflow that needs them. Access review is part of onboarding and security review.

Connected rails are capability-checked

A tenant rail is used only when its credentials, destination, and recent verification support the approved action. Otherwise the case stays blocked or moves to an assigned human path.

Contracts and controls are reviewable

The canonical BAA, DPA, privacy notice, subprocessors list, and security controls are available for review. We do not present SOC 2 or HITRUST certification we do not hold.

What we say, and what we will not say.

Security language in this industry is full of claims that sound airtight and mean little. We skip them. We state the controls we run and the posture we hold today. If a certification is an audit that happens over time, we tell you where we are in it, not that we have finished. Ask a hard question, get the real answer.

If your team needs to review our practices in detail before you move forward, reach out and we will walk you through them.

Security, answered plainly.

How does Upstream handle HIPAA?
We publish the safeguards implemented in the product and provide the canonical Business Associate Agreement for review. The controls include encryption at rest, tenant scoping, approval-gated payer actions, and execution records. This is a controls statement, not a certification claim.
Where does our PHI live?
Application records are encrypted at rest and tenant-scoped. The separate Upstream Data API contract excludes patient-level fields.
Does the platform ever act without us?
Payer-facing actions require an authorized reviewer to approve the prepared manifest. If the configured rail cannot support the action, the case remains blocked or moves to an assigned human path.
What does the data network contain?
The public contract uses payer policy references, procedure and diagnosis codes, anonymized aggregates, and model signals. It does not define patient-level fields, and contribution-gated network results can be withheld.
Can we review your security practices before signing?
Yes. Reach out and we will walk your team through our controls and posture in detail, and answer the hard questions directly.

Have your team review us.

Bring your security and compliance questions. We will give you straight answers and walk you through the controls in place. No commitment.