Skip to main content

How Sydra handles protected health information.

An NSA IDR submission contains your patient's name, date of service, diagnosis, procedure codes, operative note excerpts, and disputed claim amounts. Every document uploaded to Sydra is protected health information under HIPAA. This page describes how we handle PHI specifically.

SOC 2

SOC 2 alignment.

Sydra's controls are SOC 2 aligned, covering security, availability, and confidentiality for the systems that process customer data.

A SOC 2 report is available under NDA to qualified prospects during evaluation. Email sales@sydrahealth.com with your compliance contact copied and we'll send it the same business day.

Safeguards

How Claude via Amazon Bedrock handles your PHI.

Sydra runs on Claude via Amazon Bedrock. Claude is contractually barred from training on your PHI, and Bedrock is covered under our AWS Business Associate Agreement. Your claim data is processed inside the same HIPAA aligned boundary as the rest of your workflow.

AWS Bedrock is a HIPAA eligible service. AWS's HIPAA BAA covers Amazon Bedrock when used in the context of a covered healthcare workload. Sydra operates within that BAA scope.

When Sydra generates an IDR draft from your operative note: the operative note is processed by Claude via Amazon Bedrock. PHI in that document stays inside the AWS HIPAA eligible service boundary. No PHI is transmitted to Anthropic's systems or any other third party during generation. No data is used to train the Claude model or any other model.

Infrastructure and encryption.

  • Hosting: Sydra production workloads run on AWS infrastructure in US regions.
  • Encryption at rest: Documents are stored in Amazon S3 with AES 256 server side encryption. Keys managed through AWS Key Management Service (KMS).
  • Encryption in transit: All data between your browser and Sydra's servers is transmitted over TLS 1.2 or higher.
  • Document access: Documents aren't accessible through persistent public URLs. Retrieval uses signed URLs with short expiry windows (minutes, not days).
  • Database: PHI is stored with row level security. Each practice has a unique tenant identifier. Queries are scoped to the authenticated practice's tenant by default.

Access control and isolation.

Within your practice: Role based access control. You define which staff members can view, draft, approve, or export. Permissions are granted explicitly, not inherited by default.

Between practices: Strict tenant isolation enforced at multiple layers: application logic, API authorization, database row level security, and audit logging.

Within Kronos Health: Software engineering team access is governed by internal HIPAA training. Kronos Revenue RCM team access to PHI only for practices using Sydra + Kronos Support. Leadership access for quality review and escalated cases. No PHI accessible to sales or marketing without an operational need.

Audit logging.

Every log entry captures: user name, email, user ID, timestamp (UTC to the second), action performed, record affected (submission ID, document ID), IP address, session identifier. Logs are available to your account administrator on request.

Business Associate Agreement.

A BAA is available for all covered entities and business associates using Sydra to process PHI. The BAA is executed during contracting. What the BAA covers: permitted uses and disclosures of PHI, our obligation to safeguard PHI, breach notification timelines (60 day notification per HIPAA), your right to audit our compliance, data return or destruction on termination, subprocessor obligations.

If you want to review the BAA template before booking a demo, email sales@sydrahealth.com. We send it the same business day.

Incident response.

Documented incident response procedures covering detection, escalation, containment, recovery, and customer notification. If an incident involves your PHI: We notify you per the timeline in your BAA. We haven't had a reportable incident involving customer PHI.

Requesting security documentation.

Available to qualified prospects during evaluation: BAA template, security one pager, subprocessor list (AWS, Stedi, ModMed, and others in scope), AWS Bedrock HIPAA eligibility documentation, SOC 2 report under NDA.

Request: email sales@sydrahealth.com with your compliance contact copied. Response within one business day.

Built on Claude via Amazon Bedrock · Built to support HIPAA safeguards · BAA on request · ModMed and Stedi integrations · SOC 2 aligned, report under NDA · Security details

Sourced references
  1. 1. CMS Federal IDR Q1/Q2 2025 Public Use FileReleased January 21, 2026cms.gov/nosurprises/policies-and-resources/reports
  2. 2. Georgetown University CHIR · Health Affairs webinarMarch 2026 — 3.4 million disputes through June 2025; 88% win rate; median award ~4.5x in network rate
  3. 3. Zelis — NSA IDR Eligibility ChallengesMarch 2026 — 44% of 2024 IDR cases challenged as ineligible by non initiating party
  4. 4. ACEP analysis of CMS data~10% of eligible claims estimated to reach IDR arbitration
  5. 5. Brookings Institution NSA Arbitration DatabookApril 2026brookings.edu/articles/no-surprises-act-arbitration-databook
  6. 6. ACR — Providers Prevail in Vast Majority of IDR ClaimsJanuary 2026 — 88% of disputes found in provider's favor; 87% of awards exceeded QPA
  7. 7. No Surprises Act: Public Law 116-260, Division BB, Title I
  8. 8. Federal IDR regulations: 45 CFR Part 149ecfr.gov/current/title-45/subtitle-A/subchapter-F/part-149
  9. 9. CMS No Surprises Act overviewcms.gov/nosurprises
  10. 10. HHS HIPAA for professionalshhs.gov/hipaa/for-professionals