How we handle
protected health information.
OutcomeEdge's security posture in plain prose: encryption in transit, encryption at rest, least-privilege access controls, and BAA-on-request for the RCM engagements that touch protected health information. The inputs we receive are scoped — bookkeeping and revenue-cycle actions only — and our subprocessors are limited to the database, the email proxy, and an optional AI triage helper that is off by default.
Posture
Four controls, applied across every engagement.
The same baseline applies whether you sign us for SaaS bookkeeping or for RCM work that touches patient data. The controls below are what we ship on day one.
FAQ
The five questions healthcare prospects ask first.
Storage location, who can access, BAA availability, breach notification, and which subprocessors are in scope — answered in plain prose, the same way we answer them on kickoff calls.
Application data lives in a managed Postgres instance that ships with the deployed app, hosted in the regional footprint selected at deploy time. Backups are encrypted at rest, retained on a short rotation, and never exported to a separate warehouse, BI tool, or third-party analytics tag.
Ready to scope the engagement?
Start with the intake form.
Drop your stack and your next milestone into the intake form — we'll come back within 24 hours with the SOW, the engagement letter, and a $2,400 first month for SaaS bookkeeping, with a full refund if the close isn't right.