AudienceRx

Security

PHI and identity

We do not ingest, process, or store PHI. Protected Health Information (individually identifiable health information, as defined under HIPAA) simply never enters the platform.

Targeting and attribution on this platform instead operate at the NPI level: NPI-level attribution, not patient-level. NPI (National Provider Identifier) is a public identifier issued by CMS (the Centers for Medicare & Medicaid Services); it identifies a provider, not a patient, and it is not PHI.

Audience and attribution outputs are de-identified: what the platform produces describes providers and delivery, not the individuals those providers treat.

Security posture

Infrastructure is AWS-hosted, with environment isolation as a standing design principle, not an afterthought.

Data is encrypted in transit and at rest, using managed keys rather than keys the platform generates or holds independently.

Access follows two related principles: role-based access control, so permissions are tied to what a role requires rather than granted broadly, and least-privilege cross-account access, so the same discipline holds at the infrastructure level between accounts, not only between individual users.

If a breach occurs, notification is contractual, within 72 hours: not a best-effort target, a commitment written into the agreement.

A security summary is available to clients annually, on request, so the posture described here can be checked against current practice rather than taken on faith from a webpage. To request one, get in touch.