Security and Implementation

How Unifhi handles your data.

Unifhi supports HIPAA-compliant implementations and operates on protected health information as a business associate. We sign a BAA before any implementation that touches PHI.

This page states the controls that are in place today.

Protected health information

PHI is governed before an implementation starts.

Business associate agreement

We execute a BAA with the covered entity or business associate before implementation. The agreement governs permitted use, disclosure, safeguards, subcontractors, breach notification, and return or destruction of data.

Minimum necessary

Implementations are scoped to the data the configured workflow requires. A prior authorization readiness check does not need the whole chart, and the interface is defined around what the rule set actually evaluates.

PHI stays out of this website

The forms on this site are not a channel for patient data. Every form says so. Inquiries go to an endpoint separate from any production environment.

Controls

Controls in place.

HIPAA-compliant implementations

Implementations are built to meet HIPAA requirements for handling protected health information, governed by the BAA and the safeguards below.

Encryption

Data is encrypted in transit and at rest.

Role-based access control

Access is granted by role. Permissions are scoped to the systems, workflows, and data a person needs for their function, and are reviewed as roles change.

Defined retention

Retention is defined per engagement and documented in the agreement rather than left open-ended. Data is returned or destroyed at the end of the relationship on the terms the BAA sets.

Traceability

Source data, requirement version, rule result, workflow action, reviewer decision, and outcome stay connected. The same lineage that makes a result explainable also makes access and change reviewable.

Operating model

The operating model is part of the control set.

AI assists with extraction, structuring, and configuration. Your experts review and approve that configuration before it runs. Deterministic rules then execute approved checks the same way every time, and judgment calls route to qualified staff.

That separation is why a result can be explained after the fact: which requirement version applied, what the rule returned, who decided, and why.

Unifhi does not approve care, determine medical necessity, decide coverage, or make coding or dispensing decisions.

Integration

Connecting to your systems.

Unifhi works through the interfaces available in your environment. Methods can include HL7 v2, FHIR, X12, CDA, REST APIs, SFTP, and flat files. The combination is determined during implementation.

Unifhi supplements the systems you already run. Your EHR remains the clinical system of record. Payer systems continue to return requirements and decisions.

Security and implementation questions

Will you sign a BAA?

Yes. We execute a BAA before any implementation that touches protected health information.

Is data encrypted?

Yes, in transit and at rest.

Who can access our data?

Access is role-based and scoped to the workflow. Permissions are reviewed as roles change, and access is traceable.

How long do you keep our data?

Retention is defined per engagement and set out in the agreement. Data is returned or destroyed at the end of the relationship on the terms the BAA specifies.

Does Unifhi make clinical or coverage decisions?

No. It organizes requirements, retrieves the relevant record, and applies approved objective checks. Interpretation, judgment, attestation, and exceptions stay with your qualified staff.

Can we review the configuration before it runs?

Yes. That is the intended model. Requirements are versioned configuration your experts review, test, and approve before production, and the prior version is preserved.

Are your implementations HIPAA compliant?

Yes. Implementations are built to meet HIPAA requirements for handling protected health information. We sign a BAA before any implementation that touches PHI, and the safeguards on this page apply to it. HIPAA has no certifying body, so this is a compliance posture we attest to and evidence, not a certificate.

Start with a scoped implementation.

A bounded first workflow keeps the data footprint small while both sides validate the requirements, the interfaces, and the operating model. Tell us the workflow and the systems involved and we will map what data is actually needed.

Tell us about your workflow.

Please do not include protected health information in this form.