Compliance
HIPAA & Business Associate Agreements
When PAuthNow handles Protected Health Information (PHI) on behalf of a covered entity, we do so as a HIPAA business associate under 45 CFR 160.103.
Scope of services
PAuthNow provides administrative support for medication (pharmacy benefit) prior authorizations only. Our staff are trained administrative specialists — not licensed physicians, pharmacists, nurses, or other clinicians. We do not select therapy, counsel patients, make medical necessity determinations, or provide medical, pharmacy, legal, or insurance advice. Every PA request is authorized and signed by the prescriber. We do not handle surgical, procedural, imaging, DME, or other medical-benefit prior authorizations.
Business Associate Agreement (BAA)
Before any PHI is exchanged with PAuthNow, we execute a mutually acceptable Business Associate Agreement that meets the requirements of 45 CFR 164.504(e). Our standard BAA covers permitted uses and disclosures, safeguards, subcontractor obligations, breach notification, and return or destruction of PHI at termination. We can review our standard form or your covered entity's form.
Safeguards
- Administrative, physical, and technical safeguards aligned with the HIPAA Security Rule (45 CFR Part 164, Subpart C).
- Access to PHI is restricted to authorized workforce members on a role-based, least-privilege basis and logged for audit.
- PHI is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256).
- Workforce members receive HIPAA privacy and security training upon hire and annually thereafter.
- We maintain a documented incident response plan and breach-notification procedure.
Standards & interoperability
We support workflows consistent with the CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) and NCPDP SCRIPT electronic prior authorization (ePA) standards where payers and PBMs have implemented them. Common submission channels include CoverMyMeds, Surescripts, payer/PBM portals, and fax where required.
Certifications
SOC 2 Type II readiness is in progress. PAuthNow does not currently hold SOC 2 or HITRUST certification and will not represent otherwise on this site, in RFP responses, or in customer communications. A current program status summary is available on request from security@pauthnow.com.
Contact
Security & compliance: security@pauthnow.com