Technology, Security & Compliance
CMRS operates as a URAC-accredited Independent Review Organization with HIPAA-compliant policies, procedures, and workforce controls. Our case workflow runs on a SOC 2 Type II and ISO/IEC 27001 audited cloud platform, and every email and file exchange of PHI is encrypted end-to-end through Virtru under a signed Business Associate Agreement.
Our Security & Compliance Framework
Every CMRS engagement carries Protected Health Information (PHI) at its core. We pair an audited, enterprise-grade cloud workflow platform with HIPAA-compliant policies, URAC-accredited review processes, and Virtru end-to-end encryption for every email and file exchange. The framework below describes the controls and certifications we rely on, who provides them, and what we can document on request.
SOC 2 Type II & ISO 27001 Platform
Independently audited cloud infrastructure
The cloud workflow platform that powers CMRS intake, case routing, reviewer coordination, and report delivery is operated by an enterprise platform vendor that is independently audited annually under SOC 2 Type II and certified to ISO/IEC 27001 and ISO/IEC 27701. These are the platform vendor’s certifications; the vendor’s audit reports and certificates can be made available to client security teams under NDA on request.
- SOC 2 Type II annual audit (vendor) covering security, availability, processing integrity, confidentiality, and privacy
- ISO/IEC 27001 certified information security management system (vendor)
- ISO/IEC 27701 certified privacy information management system (vendor)
- Vendor-provided audit attestations available under NDA on request
- U.S.-based platform hosting
HIPAA & HITECH Operations
PHI handled to HIPAA standards
CMRS operates as a HIPAA Business Associate and maintains a HIPAA-compliant program. Our written policies, workforce procedures, and operating practices are implemented in accordance with the HIPAA Privacy, Security, and Breach Notification Rules, including the strengthened obligations of the HITECH Act.
- Business Associate Agreements (BAAs) executed with clients and PHI-handling vendors as required
- Role-based access aligned to job function — minimum necessary principle
- Documented workforce HIPAA training and ongoing security awareness
- Documented incident response and breach-notification procedures
- Annual HIPAA risk assessment with documented remediation tracking
Email & File Encryption
Virtru end-to-end protection for PHI
Every email and file exchange of PHI between CMRS and its clients, providers, and reviewers is encrypted end-to-end using Virtru. Virtru operates under a Business Associate Agreement with CMRS and uses AES-256, FIPS 140-2 validated cryptography that travels with the message itself — protection persists even after the file leaves CMRS.
- Virtru: AES-256 client-side, end-to-end encryption for email and file exchange under BAA
- Persistent control: Revoke access, set expirations, and audit recipient activity after a message is sent
- TLS 1.2+ in transit across our portals and platform connections
- AES-256 at rest on the workflow platform (vendor-managed)
- Encrypted upload links available for secure document submission to CMRS
URAC Accreditation
Independent Review Organization
CMRS holds URAC accreditation as an Independent Review Organization – the gold-standard recognition for clinical integrity, process rigor, and consumer protection in independent medical review. URAC accreditation is a contractual requirement for many payer relationships and is a cornerstone of our credibility.
- Documented review processes audited against URAC standards
- Reviewer qualifications, credentialing, and conflict-of-interest controls
- Independent appeal pathways and consumer protections
- Continuous quality improvement against URAC performance metrics