Security & Compliance

Enterprise-grade security
for healthcare data

Healthcare data requires more than security theater. Anka processes Protected Health Information (PHI) and financial data daily. We comply with the regulations that govern it, and we go beyond compliance. Zero data breaches. 100% uptime SLA. Real-time encryption.

HIPAA Compliant SOC 2 Type II BAA Required
Enterprise Security Dashboard
Zero
Breaches
99.95%
Uptime SLA
AES-256
Encryption
Secure Data Pipeline
PHI Input
EHR connectors, payer feeds
Verified
Encrypted
TLS 1.3, AES-256
Active
Processed
Isolated compute nodes
Isolated
Audit Logged
Immutable records, 12-month retention
Logged
Certifications

The standards we meet (and exceed)

HIPAA Compliant

Full compliance with the Health Insurance Portability and Accountability Act. Business Associate Agreement required before any PHI transfer. Administrative, physical, and technical safeguards in place.

SOC 2 Certified

Type II certification. Independent third-party audit confirms our controls over security, availability, processing integrity, confidentiality, and privacy. Audited annually.

Business Associate Agreement

BAA in place before any data transfer. Specifies permitted uses and disclosures of PHI. Standard HIPAA BAA language with no exceptions. Signed before data flows.

US Data Residency

All data stored and processed within the United States. No international transfers. No third-country servers. Complies with state-level healthcare data residency requirements.

Technical Controls

How we protect your data

Encryption in Transit

All data transmitted over TLS 1.2 or higher. End-to-end encryption from your system to Anka and back. No unencrypted data on the wire.

Encryption at Rest

All stored data encrypted using AES-256. Encryption keys stored separately from data. Hardware security modules (HSM) for key management. Regular key rotation.

Access Control (RBAC)

Role-based access control. Every Anka team member has minimal required access. No blanket database access. Principle of least privilege enforced at system level.

Multi-Factor Authentication

MFA required for all user logins. Phishing-resistant authentication (FIDO2 compliant). No passwords alone. Secure credential management across all access points.

Audit Logging

Every access, every modification, every API call logged. Immutable audit trails. Log retention: 12 months minimum. Logs backed up and encrypted.

Vulnerability Management

Continuous vulnerability scanning. Annual penetration testing by third-party firm. Security patching within 24 hours of critical CVEs. Automated threat detection.

Integration

How your data enters and leaves Anka

Secure File Transfer Protocol (SFTP)

Your 835 files, denial reports, and claim data transferred via SFTP (SSH File Transfer Protocol). Encrypted end-to-end. Public key authentication. No passwords in transit.

REST API Integration

For real-time integrations with your EHR or billing system, Anka provides authenticated REST API endpoints. OAuth 2.0. Rate-limiting. IP whitelisting available. Every API call signed and logged.

Clearinghouse Integration

Appeals submitted via your clearinghouse (or ours). Anka never has direct database access to your EHR or billing system. Data flows through your existing, compliant channels.

No Direct Database Access

Anka never has read/write access to your EHR, billing, or claims database. All integrations are through controlled API endpoints. You maintain full control over your data.

AI Governance

AI and regulatory compliance

Anka’s AI executes denial management and underpayment recovery. This requires algorithmic transparency, audit trails, and human oversight to comply with healthcare regulations.

Explainability

Every Anka recommendation includes reasoning: why this claim was identified as appealable, which payer rule triggered the underpayment flag. Human judgment decides the final action.

Bias Monitoring

Algorithmic bias is monitored by provider, payer, geography, and claim type. Training data is audited for representativeness. Disparate impact testing conducted quarterly.

Audit Trails

Complete audit trail from claim intake to appeal submission. Every decision point logged. The full record of what the AI decided and why is always available for review.

Human Oversight

Anka recommends. Human reviewers verify and approve. Appeals are submitted under your organization’s name, reviewed by designated staff, signed by your representative.

Transparency

Our security posture

Zero
Data breaches since inception
Since launch
Zero
HIPAA violations
Clean record
Zero
SOC 2 audit findings
Critical or high severity
99.95%
Uptime SLA
Audited monthly

We participate in responsible disclosure. If you discover a vulnerability, contact [email protected].