Corevia is deployed on SOC 2 Type 2 and HITRUST-certified infrastructure under a Business Associate Agreement, with HIPAA and HITECH safeguards implemented in the platform itself. What follows is how the system is actually built — the isolation model, where PHI is allowed to go, and what we can hand your security team when they ask.
Every control below is enforced where it cannot be talked around — in the data layer and on the server — rather than in application code that a future feature might forget to call.
Each brand is a separate clinical project with its own access policies. Isolation is enforced at the data layer, not by a filter in application code, so a missing WHERE clause cannot leak one tenant's patients into another's view.
AI documentation and the clinical assistant run inside Corevia's own cloud account under a Business Associate Agreement. No third-party model provider receives patient data, and nothing is used to train anyone's model.
Every PHI access, clinical decision and prescription is recorded and attributed to a named clinician — never to a service account. No role in the system, including administrators, may alter or delete an audit entry.
Access is scoped by role and by the specific practice or network membership a user holds. The server decides what a request may return; the browser only renders what it was given.
TLS for everything on the wire, encryption at rest for the clinical record, documents and backups, with keys held in a managed key service rather than in application configuration.
The record is standards-based by construction. There is no proprietary schema to escape from, so an exit, a migration or a second system is an export — not a rebuild.
Security review is a normal part of onboarding, not an obstacle. These are the documents and descriptions we can provide, in the form they actually exist in today.
A written account of the HIPAA and HITECH safeguards implemented, the certifications held by the underlying infrastructure, and what is and is not in scope for Corevia itself.
Every vendor that touches the environment, what it does, whether it can see PHI, and the agreement in place with it.
Our standard BAA, executed before any production data exists, and the BAAs we hold with the infrastructure providers beneath us.
Where PHI is created, stored, processed and transmitted; which components sit inside the boundary; and where the boundary ends.
Roles, memberships, the policies attached to each, how access is granted and revoked, and how administrative access is separated from clinical access.
How an incident is detected, triaged, escalated and communicated, and the notification obligations we take on as a business associate.
Our testing cadence and scope, how findings are tracked and remediated, and how dependencies and infrastructure are patched.
Backup and restore design, recovery objectives, and what a clinical team is expected to do while a degraded service is being restored.
We will not send you a certification we do not hold or an audit report that does not exist. Where something is in progress, we say so and tell you what stage it is at.
Safety controls that depend on someone remembering them are not controls. These are enforced server-side, on every request, for every brand.
Screened against the patient's complete active medication list and documented allergies before a prescription can be signed.
Government-ID verification at intake, with deeper assurance automatically required for hormone therapy and controlled-substance programs.
Signed notes become append-only. Corrections are addenda with their own authorship and timestamp — the record cannot be quietly rewritten.
License status, expiry and state coverage are checked when a chart is opened, not only when a physician is onboarded.
A failed or retried sign-off can never issue a second prescription — every issuance is keyed and deduplicated at the source.
The chart shows every medication the patient is on across programs and prescribers, so interaction checking never runs on a partial list.
Yes — as a matter of course, and before any production patient data exists. We also hold BAAs with the infrastructure and cloud providers beneath us, including for the environment the AI features run in.
In a dedicated AWS environment in the United States. Patient data does not leave that environment, and there is no offshore processing of PHI.
No. The ambient scribe and the clinical assistant run inside Corevia's own cloud account under a Business Associate Agreement. No third-party model provider receives PHI, and no patient data is used to train an external model.
Yes, under NDA, to prospective clients in active diligence. Ask during the security review and we will route it to your team with the remediation status attached.
We'll answer it honestly, including the questions where the answer is "not yet".