Revyn RCM
Trust through verification

Security and business-associate diligence

Security review should match the proposed services, data, systems, people, subprocessors, and contractual responsibilities. This page explains the questions and evidence to verify before protected health information is exchanged.

Important boundary

What this public page does—and does not—establish

A marketing statement is not a substitute for contracting, evidence review, risk analysis, or the safeguards required for the actual relationship.

No certification claim

This page does not claim that Revyn has been certified as HIPAA compliant. HHS says certification cannot replace a required business-associate contract. HHS also says private Security Rule evaluations may be performed, but it does not recognize those certifications as establishing compliance or preventing later enforcement findings.

Not an executed BAA

Nothing on this page is a signed business associate agreement. Whether a BAA is required and acceptable must be determined from the parties, services, data, and applicable requirements.

Evidence must match scope

Policies, controls, systems, access, subprocessors, incident terms, continuity, data return, and contract language should be reviewed for the specific proposed engagement.

Diligence topics

What to verify for the proposed operating model

The exact evidence depends on the work and systems in scope. These categories organize the review without asserting that a control has been tested or certified.

Data flow and minimum necessary

Map what information is created, received, maintained, transmitted, viewed, exported, retained, and returned—and why each access path is needed.

Identity and access

Review authorization, role design, account provisioning, authentication, privileged access, access review, termination, logging, and exception handling.

Administrative safeguards

Review assigned responsibility, risk analysis and management, policy governance, workforce training, sanctions, documentation, and periodic evaluation.

Technical and physical context

Review system boundaries, transmission and storage safeguards, device and workspace controls, audit controls, integrity processes, and approved tools.

Incidents and continuity

Review identification, escalation, containment, documentation, notification responsibilities, restoration, backups, downtime procedures, and testing evidence.

Subcontractors and exit

Identify downstream parties and obligations, then confirm access removal, data return or destruction, transition support, retention, and surviving responsibilities.

BAA review sequence

Verify the relationship before PHI moves

  1. 1Define the services and dataDocument the work, systems, data categories, access, locations, parties, and downstream dependencies.
  2. 2Determine applicable roles and agreementsHave qualified reviewers determine whether a business-associate relationship exists and which written terms are required.
  3. 3Review terms and evidence togetherAlign permitted uses, safeguards, reporting, subcontractors, access, return or destruction, termination, and operational evidence.
  4. 4Execute before applicable PHI exchangeComplete required approvals and agreements before using a workflow that creates, receives, maintains, or transmits PHI.
  5. 5Govern the active relationshipTrack material changes, incidents, access, subprocessors, findings, renewals, and exit responsibilities on an agreed cadence.

Official references and review record

Last content review: August 6, 2026. HHS materials provide the authoritative federal context cited here. This page is general information, not legal advice or proof that a particular agreement or safeguard satisfies an organization’s obligations.

Make the security review match the actual scope

Start with the services, systems, data, access, parties, and responsibilities under consideration, then identify the evidence and agreements that require review.