Security & Data Handling

Who Touches Your Data, and Where It Goes.

We’re an outsourced, staffed billing team. This page explains exactly who handles your clients’ information, where it goes while we work, and how it’s protected.

Who Handles Your Data

We’re a remote team with staff in the US and internationally. The team is split in two, and only one side ever sees identifiable client data.

Tier 1

US-based staff

  • The only people who log into your systems: practice management, clearinghouse, and payer portals.
  • The only people who see identifiable data, download files, or submit claims.
  • Each person has their own login with only the access their role needs. No shared passwords.
  • They prepare each task by removing identifiers before it goes to Tier 2, and they apply the results.

Tier 2

International staff and AI tools

  • Never log into your systems and never receive identifiable data.
  • Work only on task data with identifiers removed: no names, member IDs, dates of birth, addresses, or claim numbers.
  • Each record carries an internal reference code. Only Tier 1 can match it back to the real claim.
  • They sort denials, spot patterns, check coding and payer rules, and draft fixes for Tier 1 to review.

HIPAA training for everyone

Both tiers are trained on HIPAA before working on any account, and every account has a named US point of contact.

Access removed when they’re done

When someone stops working on your account, their access is removed. You can see and revoke any of our logins at any time.

State rules come first

Where a state program or payer contract limits work outside the US, we follow it. See our state by state notes.

Where the Work Happens

Most work happens inside your systems. Some of it needs files. Here’s how both are handled.

Mostly inside your systems

Our US-based staff make corrections, resubmissions, and follow up in your practice management system, clearinghouse, and payer portals.

Sometimes we download files

Posting and triage often need files: ERAs and EOBs, aging and denial exports, authorization letters. Only US-based staff download them, and only what the task needs.

Company-managed laptops only

Downloaded files are only opened on laptops we manage, with encrypted drives, screen lock, and multi-factor sign-in.

Saved to BAA-covered storage

Working files are saved to cloud storage covered by a BAA. Never personal devices, personal email, or USB drives.

Deleted when the work is done

Files are deleted once the task is finished, or kept only as long as our agreement with you specifies.

Encrypted in transit and at rest

Data moving between systems and stored on our platforms is encrypted.

How We Send You Results

Summaries come by email. Anything with client data comes another way.

Email summaries, no client data

Counts, dollar amounts, denial reasons, and root causes found. Nothing that identifies a client.

Encrypted files for claim detail

On the Business plan, claim-level detail comes as an encrypted, password-protected ZIP attached to the email. It doesn’t expire, so you can keep it with your records. The password is shared with you separately, never in the same email.

Web portal on Enterprise

Enterprise clients get claim-level reporting and can make requests through a web portal. Either way, client data is never sent unencrypted.

Root Causes and AI

AI helps us find patterns faster. People make the corrections.

Identifiers removed for analysis

When we look for the patterns behind denials, we remove names and identifiers first wherever possible. Patterns don’t need names.

AI only under a BAA

We only use AI tools from vendors that have signed a BAA. No PHI is used to train AI models.

A person reviews every correction

No claim is corrected, voided, or appealed automatically. Someone on our team reviews each one before it’s submitted.

Agreements

The paperwork that backs all of the above.

BAA with every client

Signed before anyone on our team gets access to your systems or data. Included on every plan at no extra cost.

BAAs with our vendors

Every vendor that can touch PHI, including cloud storage, AI tools, and communication tools, is covered by its own signed BAA.

If something goes wrong

If there’s a security incident involving your data, we notify you as our BAA requires.

Available After Agreement

Documents your compliance team can review before we start.

  • Signed Business Associate Agreement. Executed before any access to your systems or data.
  • Software and vendor list. Every tool we use that touches your data, and what it’s used for.
  • Vendor SOC 2 reports. SOC 2 reports from the vendors on that list. Ravenswood doesn’t hold its own SOC 2 report.
  • Proof of insurance. Certificates for our professional liability, E&O, and general liability coverage, including coverage amounts.

Shared once a BAA or NDA is in place. Ask for any of it on your consultation call.

Security FAQ

Do you have staff outside the US?

Yes. We’re a remote team with staff in the US and internationally. Only US-based staff log into your systems or see identifiable data. International staff and AI tools work only on task data with identifiers removed, linked by internal reference codes that only our US team can match back. Where a state program or payer contract restricts work outside the US, we follow that rule.

Do you sign a Business Associate Agreement?

Yes. We sign a BAA with every client before anyone on our team gets access to your systems or data. It’s included on every plan at no extra cost.

Do you ever download our data?

Yes, sometimes. Most of our work happens inside your practice management system, clearinghouse, and payer portals. Some tasks need files: ERAs and EOBs for posting, aging and denial exports for triage, authorization letters for unit checks. When we download, it’s only what the task needs, onto company-managed laptops with encrypted drives and multi-factor sign-in, saved to BAA-covered cloud storage. Files are deleted when the work is done or as our agreement with you specifies.

How do we get results and reports?

Emailed summaries contain no client data: counts, dollar amounts, denial reasons, and root causes. Claim-level detail comes as an encrypted, password-protected ZIP attached to the email on the Business plan (it doesn’t expire, and the password is shared separately), or through the web portal on Enterprise. Client data is never sent unencrypted.

How do you use AI?

We use AI to help triage denials and find the patterns behind them, such as a payer rule, an authorization setup, or a provider enrollment issue. We only use AI vendors that have signed a BAA, we remove identifiers first wherever possible, and no PHI is used to train AI models. A person reviews every correction before it’s submitted.

Are you SOC 2 certified?

Ravenswood doesn’t hold its own SOC 2 report. The software we use comes from SOC 2 audited vendors. Once a BAA or NDA is in place, we share the full list of software we use along with those vendors’ SOC 2 reports, so your compliance team can review them directly.

What happens to access and files when someone leaves or the engagement ends?

Each team member has their own login, so one person’s access can be removed without affecting anyone else. When someone stops working on your account, their access is removed. When the engagement ends, all access is removed and any files we hold are returned or deleted as our agreement specifies.

Questions From Your Compliance Team?

Bring them to a free 30 minute call. We’ll walk through access, file handling, and what we share after signing.