Accreditations & Security

Rigorously accredited, fully compliant, and secure end-to-end.

URAC Accredited Independent Review Organization - Internal Review - Expires 04/01/2028
Gold-Standard Recognition

URAC Accredited Independent Review Organization

CMRS holds full URAC accreditation as an Independent Review Organization – the gold-standard recognition for clinical integrity, process rigor, and consumer protection in independent medical review. URAC accreditation is a contractual requirement for many payer relationships and a cornerstone of our credibility with carriers, TPAs, and regulators.

Accreditation: Independent Review Organization – Internal Review
Current through: 04/01/2028
SOC 2 Type II audited cloud platform

Information Security · Audited Cloud Platform

SOC 2 Type II & ISO 27001 Audited Platform

CMRS operates its case workflow, reviewer coordination, and records on an enterprise cloud platform that is independently audited annually to SOC 2 Type II and certified to ISO/IEC 27001 and ISO/IEC 27701. Platform audit reports are available to client security teams under NDA on request.

Platform audits: SOC 2 Type II · ISO 27001 · ISO 27701
Standard: AICPA Trust Services Criteria
HIPAA-compliant operations

Patient Privacy · PHI Security

HIPAA-Compliant Operations

CMRS maintains a HIPAA-compliant program, with policies, procedures, and safeguards implemented in accordance with the HIPAA Privacy and Security Rules. PHI is encrypted at rest and in transit, role-based access is applied on a minimum-necessary basis, and platform-level audit logging supports these controls — applied consistently across clinical reviewers, coordinators, and administrators. As a Business Associate, we execute Business Associate Agreements with our clients and uphold our obligations thereunder.

Privacy Rule · Security Rule · Breach Notification Rule
Virtru end-to-end email and file encryption

End-to-End Encryption

Virtru-Encrypted Email & File Exchange

CMRS uses Virtru for end-to-end email and file encryption, so sensitive claim information stays secure throughout every exchange with carriers, providers, and counsel. Carriers and TPAs sending PHI to CMRS, or receiving completed reports back, get the protection of a zero-trust, attribute-based encryption platform that travels with the file.

Email encryption · Secure file share · Revocable access