Security
Security and data handling
Plain statements, no badges we have not earned. If your compliance team has questions this page does not answer, we will answer them directly.
HIPAA posture
Mohenara operates as a business associate under HIPAA when handling protected health information for clients. We sign Business Associate Agreements with every client before any claim data moves. We maintain administrative, physical, and technical safeguards appropriate to our size and the data we handle, and we do not describe ourselves as "HIPAA certified," because no such certification exists.
Development runs on synthetic data
The system is developed and evaluated entirely on a synthetic claims testbed. The 750 cases in our corpus are generated from CMS synthetic public-use data: artificial patients, artificial providers, artificial claims. No real patient data is used to build, test, or demonstrate the product. When we share example cases publicly, they are synthetic and labeled as such.
Production infrastructure
- Client claim data is processed on HIPAA-eligible AWS services, in US regions, on an account covered by a Business Associate Agreement with AWS.
- Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256).
- Access is role-based and least-privilege, and access to client data is logged.
- Retention follows the client agreement: when an engagement ends, client data is returned or destroyed per the BAA.
Models
Model inference runs through AWS Bedrock on the same BAA-covered account. Client data is never used to train or fine-tune models, ours or anyone else's.
Subprocessors
Amazon Web Services (cloud infrastructure and model serving). This list will stay current as it changes, and clients are notified of additions under the BAA.
Certifications, honestly
We are an early-stage company and we do not claim certifications we do not hold. When we engage a SOC 2 audit, its status will be published on this page. In the meantime, we will complete your security questionnaire and walk your team through our controls directly.
Questions and disclosure
Security questions, questionnaires, or anything you believe we should know: hello@mohenara.com. We respond within one business day.