Skip to content

Security, authority, and data boundaries

Keep consequential decisions with the people accountable for them.

Kept Count makes work, exceptions, ownership, and review history visible. Your organization keeps clinical judgment, compliance oversight, coding decisions, and final claims authority.

Illustrative photograph of a reviewer stamping a medical chart reviewed before billing handoff. Not Kept Count staff, customers, or patients.

Why the boundary matters

The person on the other end of this work is someone's patient, not a record in a queue.

That is the reason authority stays with the people who are accountable for it, at every handoff below.

The control model

Clear ownership at every handoff.

The practice keeps clinical authority

Your licensed team defines the care model, approves clinical policy, receives escalations, and makes final patient-care decisions.

The practice keeps claims authority

Kept Count prepares review-ready evidence. It does not choose final codes, submit claims, receive collections, or release unsupported lines.

Exceptions stay visible

Missing consent, conflicting facts, unresolved requirements, and held billing lines remain visible with an owner and reason.

Access is role- and tenant-scoped

Provisioned users work within assigned roles and organizational boundaries; audit evidence records important actions and changes.

Recount stays bounded

Recount prepares the next contact and can draft attributable notes from the record the worker can already see. It does not approve clinical decisions, release billing lines, send messages, rank the worklist, or replace the named human owner. Covered use requires the appropriate agreements and a dedicated environment; public evaluation stays synthetic.

Partner reporting stays purpose-limited

Provider teams retain patient-level authority while community, sponsor, and network views are limited to approved aggregate or assigned operational information.

CMS and OIG audit-response readiness

Make compliance work reviewable, not invisible.

Assign owners, preserve a dated decision trail, surface missing or contradictory evidence, and track holds and corrections so your compliance team can monitor the process and prepare for record requests. Kept Count supports this workflow; it does not replace the practice's compliance program or audit plan.

Kept Count can

Organize candidate evidence, monthly work, consent records, exceptions, supervision, QA, and billing-support packets.

A responsible practice reviewer must

Confirm program fit, patient facts, clinical appropriateness, coding, coverage, and the final decision to submit or withhold a claim.

Kept Count does not

Guarantee reimbursement, certify compliance, replace counsel or a compliance officer, auto-submit claims, or make clinical decisions.

Data boundary

Synthetic until the covered environment is ready.

The public tour and evaluation experience use synthetic or de-identified examples. Real patient information must not enter the system until the contract, BAA, covered-vendor, security, and practice-acceptance gates are complete.

No PHI in public forms

Readiness and walkthrough requests are for business contact and implementation information only.

Production is a gated decision

The practice and Kept Count clear technical, contractual, security, clinical, and billing gates before activation.

Assurance status

Vendor coverage is one layer. Kept Count must prove the whole system.

A vendor BAA or SOC 2 report does not make its customer HIPAA compliant or transfer a SOC 2 attestation. Kept Count is building a covered production boundary and an independent assurance program; the current public environment remains synthetic-only.

Covered vendor layer

BAAs and covered accounts

Supabase and Vercel offer HIPAA-capable services under specific paid plans, signed BAAs, and configuration requirements. Kept Count must activate and evidence the exact covered accounts and projects before PHI use.

Kept Count layer

Operational HIPAA program

Risk analysis, policies, training, access reviews, incident and recovery procedures, vendor management, and customer activation controls remain Kept Count responsibilities. HHS does not recognize a shortcut “HIPAA certification.”

Independent assurance

Assessment, testing, and SOC 2

Kept Count does not currently hold its own SOC 2 report. The path is an independent HIPAA assessment and penetration test, followed by a scoped SOC 2 examination performed by an independent CPA firm when the controls and evidence period are ready.

Before production activation

Five gates before real patient data enters the system.

These are procurement and implementation controls, not badges. Evidence is reviewed with the responsible owners before the practice authorizes real-data use.

  1. 1A signed services agreement and appropriate business associate agreement
  2. 2A covered production environment with required vendor agreements and controls
  3. 3Practice-approved consent, supervision, escalation, documentation, and claims policies
  4. 4Named clinical, compliance, operations, security, and billing owners
  5. 5Role provisioning, workflow acceptance, and launch evidence

Bring your compliance, security, and RCM questions.

We will walk through the control boundary, the evidence path, and the exact decisions your practice would retain.