Security & data handling

Written before we hold anyone's data.

N2 will act as a business associate of the healthcare organizations it serves. We are not a covered entity and we do not provide patient care. This page describes the architecture we are building to and the conditions that have to be met before protected health information reaches us.

Current status. N2 holds no customer protected health information. Development runs on synthetic data only. PHI will not be introduced until the applicable customer agreements and business associate agreements are executed, our subprocessor agreements are in place, and production security controls are complete.

Infrastructure

Where the data will sit

  • AWS, under an executed Business Associate Addendum. Our infrastructure is being built on Amazon Web Services, under a BAA that is already in force.
  • United States processing. Customer data will be processed and stored in US regions.
  • Encryption in transit and at rest. Will be applied to customer data throughout.
  • Separate development and production environments. Production data will not flow into development, and development will not run on customer data.
  • Tenant isolation. Each customer organization's data will be separated, and access scoped to that organization.
  • Least-privilege access. People and services will get the narrowest access that lets them do the work, and no standing access beyond it.
  • Centralized audit logging. Access and administrative activity will be logged centrally, with logs designed not to duplicate PHI unnecessarily.

Artificial intelligence

What the model is and is not allowed to do

Core claims processing, reconciliation, eligibility, financial and compliance logic is deterministic software. AI operates over results that software has already produced.

  • Any AI processing of PHI will run under an executed business associate agreement with the provider, on endpoints configured for the retention terms that agreement requires.
  • No training on customer data. Customer data is not used to train or improve third-party models.
  • No final clinical decisions, and no determination of legal or regulatory compliance by a model.
  • No autonomous consequential actions. Transmitting a claim, altering a system record or sending a customer communication requires deterministic application controls, explicit human approval, or both.
  • Human review. Generated analysis, code and outputs are reviewed by N2 personnel before they reach production software or a customer.

Where a finding is presented, the intent is that it can be traced to the underlying records rather than accepted on the model's word.

Working with us

What has to be true first

  • An executed business associate agreement, before any protected health information moves.
  • Minimum necessary. We ask for the narrowest extract that answers the question, and use de-identified or limited data sets where the analysis allows.
  • A secure transfer channel, agreed in advance. Never email attachments.
  • Subprocessors disclosed, each under its own business associate agreement, with terms flowed down.
  • Returned or destroyed at the close of an engagement, on the customer's written instruction.

Security documentation and architecture detail are available to prospective customers under a mutual non-disclosure agreement. Write to nrobles@n2analytics.org.

Please do not send us patient information. Nothing on this site is a channel for protected health information, and our email is not one either. If a conversation needs that kind of data, we will put an agreement and a secure channel in place first.