Security & compliance

HIPAA-grade protection for SNF chart intelligence

RevOptix1 is the only place resident protected health information (PHI) enters our systems. Charts, PDFs, and FHIR R4 bundles are uploaded inside the platform after your Business Associate Agreement is signed — never by email, never on PDPM Audit Group marketing pages, and never before onboarding is complete.

Where resident PHI goes

PHI accepted

RevOptix1 platform only

  • Chart Scanner (PDF / TXT upload)
  • FHIR R4 bundle upload
  • Authenticated dashboard after BAA + facility verification

No PHI

PDPM Audit Group & marketing

  • pdpmauditgroup.com consult forms
  • Email, chat, or sales attachments
  • Expert advisory calls without platform upload

Compliance assurances

What your compliance officer should see

Explicit controls for skilled nursing facilities uploading Medicare Part A charts, MDS exports, and FHIR streams.

SOC 2 compliant architecture Healthcare-grade access controls, audit logging, and least-privilege design aligned with SOC 2 trust principles.
100% HIPAA compliant Platform workflows built for SNF PHI: signup, BAA, upload gating, and secure analysis pipelines.
BAA signed upon engagement Electronic BAA before any chart processing. Upload stays disabled until execution and facility verification.
Encrypted at rest & in transit TLS for data in transit. Encrypted storage for data at rest. No PHI transmitted outside secured platform paths.

BAA & upload workflow

  1. Account + NPI verification

    Facility identity matched to CMS NPI Registry before any clinical data is accepted.

  2. BAA e-sign

    Business Associate Agreement executed electronically. Required under HIPAA before PHI processing begins.

  3. Upload gate opens

    Chart Scanner, FHIR upload, and batch tools unlock only after BAA completion and onboarding checks pass.

  4. Analysis inside RevOptix1

    Findings generated within the platform. Export or share reports through authenticated sessions only.

Compliance officer FAQ

Can we email a chart for review?

No. Email is not an approved PHI channel. All chart analysis happens inside RevOptix1 after BAA execution.

Does PDPM Audit Group receive our charts?

Expert advisory at pdpmauditgroup.com does not include chart upload. PHI stays in RevOptix1 unless you explicitly export findings from your authenticated session.

What happens to PHI if we cancel?

Upon termination, PHI is returned or securely destroyed per your BAA terms. Upload access is revoked immediately.

Who do we contact for a security review?

Email info@revoptix1.com with subject “Security review” or call (385) 888-7447.

Start free 72-hour trial Create account View pricing