Safety.
OptimIQ runs on protected health information and revenue decisions. The way we handle both is the product.
The most sensitive data and the most consequential decisions in the system.
A claim is a record of someone's body. A prior authorization is a gate between a patient and care. A risk score becomes a budget. Mistakes here aren't bugs — they're harm. OptimIQ exists to take this work off practices, run it cleaner than they could alone, and make every step auditable.
Five principles that shape every system we build.
Privacy, auditability, and clinical oversight aren't bolted on after launch. They are the architecture.
Privacy by design
PHI is minimized at every layer. Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Role-based access scopes every system to the smallest viable surface — we never train external models on customer PHI.
Auditability
Every code change, every claim decision, every recommendation is timestamped, attributable, and traceable to the underlying record. Audit packets for RAC, ZPIC, and payer review are a download, not a project.
Clinical oversight
AI suggests. Specialty-trained humans decide on anything that touches a coded diagnosis, a denied appeal, or a documentation gap. Clinical judgment is never delegated to a model.
Operational resilience
Payer rules change weekly, CMS rules change quarterly. We track the changes operators don’t have time to, push them into the rule engine, and roll back fast when something regresses.
Provider partnership
Documentation prompts, query rates, and feedback loops are tuned with provider time in mind. We exist to remove operational drag, not add another pop-up to the EHR.
How we prevent, detect, respond, and improve.
Prevent
We minimize PHI at the source, segment data by customer tenant, gate access by role, and review every model and workflow against a written threat model before it touches production.
Detect
Anomalous PHI access, unusual denial patterns, payer-policy regressions, and audit-trail gaps are surfaced in real time. Customers see their own audit feed in their dashboard.
Respond
Incident response targets: 1 hour to acknowledge, 24 hours to root cause, 72 hours to written customer notification for any event affecting PHI. Breach notification follows HHS § 164.404.
Improve
Every incident closes with a postmortem. Customer-facing postmortems for material events are published to the Trust Center within 30 days.
Enterprise-grade security at scale.
Operations leaders sign the contract. Compliance, security, and IT have to live with it. OptimIQ is built so all three can.
- BAA on file by default
- Audit logs across every PHI access
- Single sign-on with SAML 2.0 and OIDC
- Role-based access controls and least-privilege defaults
- Encryption at rest and in transit
- US-only data residency for in-scope customers
US data residency
In-scope customer data stays in US regions.
HIPAA-aligned controls
Controls mapped to HIPAA Security Rule.
Zero-retention model mode
Inference without storing model inputs.
SOC 2-style control mapping
Controls tracked against a SOC 2 catalog.
Trust Center
Every control. Every subprocessor. Every recent event.
Public, dated, kept current — the strongest signal we can give that these controls are operating today.
Visit the Trust CenterSubprocessors
The third parties we use to operate the platform.
Each subprocessor is under a BAA where PHI is in scope. Customers are notified 30 days before any change.
View subprocessor listSaw something wrong?
Security researchers, customers, and members of the public can report a concern directly to our security team. We respond within one business day.
Talk to the people who built it.
Demos are run by the physicians and revenue cycle leads on our team, not a sales engineer reading a script.

