Every hand signs first
Soro operates under signed Business Associate Agreements with every vendor that touches health data.
The full program is documented in our BAA template.
Security is not an add-on at Soro, it is how we operate. Six locks stand between your billing data and the outside world. Scroll through each one.
Follow your dataSoro operates under signed Business Associate Agreements with every vendor that touches health data.
The full program is documented in our BAA template.
Data moves over TLS and rests under AES-256, backups included. There is no unencrypted path in and no unencrypted copy inside.
Billing files upload through an encrypted channel that lands them directly in secured storage. They are never emailed and never handled as loose files.
People see only what their work requires, behind individual authenticated logins. Every access to health data is logged: who, what, when. Everybody who can touch PHI is certified to handle it.
Client data lives on HIPAA-eligible cloud infrastructure, inside an isolated network environment. Nothing sits on laptops or portable media.
Logging and monitoring run continuously. Unusual access gets flagged and reviewed the moment it appears, not discovered later.
From the moment it leaves your system to the moment someone reads it, a file is never unprotected and never unaccounted for.
The file leaves your system through an encrypted link. Nothing travels by email.
TLS wraps it the whole way. No readable copy exists en route.
It lands in secured storage and rests under AES-256, isolated from the open internet.
Every open and every read is logged with a name and a time. Nothing happens quietly.
Four promises we keep, four lines we do not cross.
If your security or compliance team wants to go deeper, we are glad to walk through it. Reach us through the contact page and you will get a direct answer.