Security and Compliance
Patient data handled with the care it deserves
Coral is designed with HIPAA safeguards and signs Business Associate Agreements with every covered entity we work with. Here is how we handle the data entrusted to us.
Built-in safeguards
Encryption at rest and in transit
All data is encrypted at rest using AES-256 and in transit over TLS 1.2 or higher. Fax documents and extracted fields are never transmitted or stored in plaintext.
Access controls and audit logs
Role-based access controls limit who can view or export patient data within your organization. All access events are logged with timestamps and user identifiers for audit purposes.
Minimum necessary data principle
Coral processes only the clinical fields required to file the prior authorization. We do not collect, store, or analyze data beyond what is needed to complete the task at hand.
Secure fax and file handling
Inbound faxes are received over encrypted channels and processed in isolated environments. Source documents are not retained beyond your configured retention window.
What data Coral processes
When a referral fax arrives, Coral reads the document and extracts the clinical fields needed for prior authorization filing: patient demographics, diagnosis codes, procedure codes, prescribing provider information, and insurance details. We do not build patient profiles, aggregate data across organizations, or use clinical content for model training.
- Referral document content (fax or uploaded file)
- Extracted clinical fields: ICD codes, CPT codes, patient name and date of birth, provider NPI, payer ID
- Authorization request status and payer response
Patient data is deleted after the authorization has been filed, subject to your organization's configured retention window. Coral does not retain PHI after the retention period expires. All infrastructure is US-based.
Business Associate Agreements
A Business Associate Agreement is a legal contract that formalizes the responsibilities of any vendor who handles protected health information on behalf of a covered entity. Coral signs a BAA with every customer before processing any patient data.
BAA execution is included with every Coral plan at no additional cost. To review the agreement or request a customized BAA for your organization, contact our team or see our pricing page for plan details.
Questions about our security practices?
Our team is available to walk you through our data handling, review our BAA, or answer compliance questions from your IT or legal team.