Skip to main content

Security, Compliance & Trust

HowWeProtectPatientInformation

A plain-language look at how protected health information is handled, how the Case Hub is secured, and how our clinicians are licensed and credentialed.

Built to Be Verified

Trust you can point to, not just a claim

Law firms, carriers, and government partners send us sensitive information every day. This page explains, in plain language, how that information is protected: the practices behind our HIPAA compliance, the security posture of the Empower Case Hub, and the licensure and credentialing behind every evaluation. If your compliance or procurement team needs more, we're glad to talk.

HIPAA Privacy & Security

How protected health information is handled

HIPAA-compliant systems

Referrals, records, and status updates move through HIPAA-compliant systems from first contact through the final report. Protected health information never travels through unsecured channels.

Minimum necessary access

Protected health information is accessible only to the patient's care team and shared with referring partners through secure channels. It is never sold, shared, or used outside the care relationship.

Secure records handling

Records are retained and released only through secure, authorized channels, and reports are written to withstand review by courts, carriers, and federal examiners.

Case Hub Data Protection

One secure portal, scoped to your organization

The Empower Case Hub is the private, HIPAA-compliant portal where your team receives medical records, invoices, treatment updates, and appointment statuses.

Private to your organization

Each partner organization gets its own secure portal. Your team sees only the cases your organization has referred, nothing else, and no one else sees yours.

Access controls

Access is granted per person on your team: attorneys, adjusters, case managers, and paralegals each receive their own secure access, so records are shared with the people who need them and no one else.

Secure delivery, not email attachments

Medical records, invoices, treatment updates, and appointment statuses are delivered inside the portal instead of moving through inboxes, so the complete case file stays inside a HIPAA-compliant system.

Full access audit trail

Every login, case update, record download, and the IP address behind each action is logged automatically. If your compliance team ever needs to verify who accessed a case and when, the record is there.

Clinician Licensure & Credentialing

Every evaluation, by a licensed clinician

Licensed for the work they do

Evaluations are conducted by licensed clinicians credentialed for their specific scope of work: psychologists, physicians, physician assistants, and nurse practitioners.

Named clinical leadership

Every service line operates under named clinical leadership, so clinical quality has an accountable owner, not an anonymous review queue.

Standards for network providers

Providers in the Trusted Partner Network are held to shared expectations for active licensing, ethical billing, and timely documentation.

Read the provider standards

Need compliance documentation?

If your organization requires a Business Associate Agreement (BAA), send your request directly to Baarequest@empowermh.co and our compliance team will take it from there. For broader security and compliance questions from your legal, IT, or procurement team, contact us and we'll connect you with the right person, happy to do it before you send your first referral.

Questions your compliance team wants answered?

Talk to us before you sign. We'll walk your operations, legal, or procurement team through how patient information is protected at every step.