Security
Controls described as boundaries, not blanket claims.
ApprovalHelp is operated by DenialHelp, LLC. This page explains the current application controls and vendor data boundaries. A contract, BAA, and service-eligibility review—not a Boolean badge—determine whether a service may handle PHI.
Identity and access
Professional sessions idle after 20 minutes and have a 12-hour absolute lifetime. Actions use a five-role capability model, tenant scoping, same-origin checks, and reauthorization boundaries.
Data at rest and in transit
Application PHI is restricted to the encrypted data volume. TLS is enforced at the gateway. Backups, recovery evidence, and service eligibility are verified operationally rather than inferred from a hosting brand.
AI handling
Every AI route declares its provider, service, contract status, allowed data class, model allowlist, retention/training posture, and failure behavior. A PHI-capable route refuses the call if its approved de-identification path is unavailable.
Audit and integrity
Security records are append-only at the database boundary. Canonical case events and AI-handling receipts are hash-linked for tamper evidence; the general audit log does not claim that property. This is detection evidence, not a claim that local records are impossible to alter.
Retention and legal holds
Retention is versioned by record class. Clinical destruction is paused pending jurisdiction, role, contract, and legal review. Active legal holds override every destructive timer.
Incident operations
Access anomalies, breach clocks, vendor review dates, backups, and privileged jobs have owners and runbooks. Monitoring payloads are restricted to non-PHI evidence.
Vendor and data-class register
This public view omits contract documents and internal evidence locations. Enabling a new service still requires service-level eligibility, region, subprocessor, retention, and termination review.
| Service | Purpose | Permitted data | Contract boundary |
|---|---|---|---|
| Amazon Web Services | Textract OCR, encrypted S3 backups, Lightsail TLS gateway | public, internal, pii, phi, deidentified | Executed BAA; covered services only |
| Paubox Email API | transactional email | public, internal, pii, phi, deidentified | Executed BAA; covered services only |
| Google Workspace | operator mailbox, administrative notifications | public, internal, pii, phi, deidentified | Executed BAA; covered services only |
| Claude subscription CLI | AI inference after formal de-identification | public, internal, deidentified | No BAA asserted; de-identified data only |
| Anthropic API | non-PHI development and explicitly classified public/internal workloads | public, internal, deidentified | Not used for PHI |
| Stripe | payment and subscription billing using PHI-free metadata | public, internal, financial_non_phi | Not used for PHI |
| Cloudflare DNS | authoritative DNS only | public | Not used for PHI |
| Sentry | PHI-scrubbed error and performance telemetry | public, internal | Not used for PHI |
| Telegram Bot API | aggregate PHI-free operational alerts | public, internal | Not used for PHI |
| Stedi Healthcare Eligibility | X12 270/271 eligibility checks | public, internal | Pending review |
| Google Analytics / PostHog | aggregate public-site analytics only | public | Not used for PHI |
Report a security concern
Do not send patient information in the first message. Contact the monitored ApprovalHelp support channel and request escalation to the Security Officer.
Contact ApprovalHelp →