Accreditations & Security
Rigorously accredited, fully compliant, and secure end-to-end.

URAC Accredited Independent Review Organization
CMRS holds full URAC accreditation as an Independent Review Organization – the gold-standard recognition for clinical integrity, process rigor, and consumer protection in independent medical review. URAC accreditation is a contractual requirement for many payer relationships and a cornerstone of our credibility with carriers, TPAs, and regulators.
Current through: 04/01/2028

Information Security · Audited Cloud Platform
SOC 2 Type II & ISO 27001 Audited Platform
CMRS operates its case workflow, reviewer coordination, and records on an enterprise cloud platform that is independently audited annually to SOC 2 Type II and certified to ISO/IEC 27001 and ISO/IEC 27701. Platform audit reports are available to client security teams under NDA on request.
Standard: AICPA Trust Services Criteria

Patient Privacy · PHI Security
HIPAA-Compliant Operations
CMRS maintains a HIPAA-compliant program, with policies, procedures, and safeguards implemented in accordance with the HIPAA Privacy and Security Rules. PHI is encrypted at rest and in transit, role-based access is applied on a minimum-necessary basis, and platform-level audit logging supports these controls — applied consistently across clinical reviewers, coordinators, and administrators. As a Business Associate, we execute Business Associate Agreements with our clients and uphold our obligations thereunder.

End-to-End Encryption
Virtru-Encrypted Email & File Exchange
CMRS uses Virtru for end-to-end email and file encryption, so sensitive claim information stays secure throughout every exchange with carriers, providers, and counsel. Carriers and TPAs sending PHI to CMRS, or receiving completed reports back, get the protection of a zero-trust, attribute-based encryption platform that travels with the file.