Security & Compliance
Go ahead. Try to make it cross the line.
Every Shift Agent is built around the specific way it could go wrong: coding above the chart, cancelling care over a coverage check, contacting a patient without consent. Ask it to do the wrong thing. It stops, says why, and hands the decision to a person.
- BAA with every customer
- HIPAA-aligned controls
- PHI never trains a model
Pick a request · Shift Agents
0 of 7 tried · 0 lines crossed
Staff · Teams
Bump this visit to a 99215
Reads the provider’s note
Medical decision-making supports a 99213: two stable chronic problems, low-risk management
Never codes above what the documentation supports.
Charge Capture Agent · what it did instead
- Kept the provider’s 99213
- Sent the request to Dr. Patel for review, with the note sections that set the level
audit · hold · charge_capture · E/M above documentation · routed: physician · rationale saved
Two kinds of line
One line never moves. The rest are yours to set.
Fixed, for every agent
No agent gives medical advice. A clinical question goes to your care team, whatever the configuration.
Set by you
Conservative-coding preferences, escalation rules, what an agent may say to a patient, and which steps need a person’s sign-off before anything is written back.
How much it does on its own →Every agent’s line
Nine agents. Nine failure modes, designed out.
- Charge Capture
- Never auto-applies a higher E/M level or a changed primary diagnosis over the provider’s own. Disagreements go to the physician.
- Denial Management
- Routes resubmissions to a coder or clinician for payers whose contracts require sign-off, rather than assuming its own authority.
- Prior Auth
- Never fabricates a clinical justification. If the chart doesn’t support medical necessity, it says so.
- Referral
- Never routes a referral to scheduling while a required PCP referral or prior auth is missing.
- Insurance Verification
- Never cancels, reschedules or denies care over a coverage finding. Coverage informs care; it doesn’t gate it.
- Scheduling
- Checks before a provider or visit-type change, so a reschedule never silently voids an auth or referral.
- Registration
- Reads back every write to the PM system and verifies it before treating it as saved.
- Patient Balances
- Consent and TCPA rules gate every outbound contact; PCI rules govern how payment is collected.
- Document Intake
- Matches the patient before filing, and escalates a critical result immediately instead of queueing it.
Your data
Your data does your work, and nothing else.
Models run in a private, isolated environment on AWS’s HIPAA-eligible cloud. What your practice teaches its agents, from payer quirks to your own SOPs, stays yours.
- Private, isolated models
- Hosted in an isolated environment on AWS’s HIPAA-eligible cloud. PHI never trains or fine-tunes a model.
- Yours alone
- Never shared with, or used to train, another customer’s agents.
- Minimum necessary
- Each agent sees only what its task needs, not the full record.
- Encrypted
- At rest (AES-256, AWS KMS) and in transit (TLS 1.2+).
- Access
- Role-based access and mandatory MFA.
- Audit trail
- Every action logged with its rationale. 7-year retention.
- Monitoring
- 24/7, with AWS GuardDuty, CloudWatch and Inspector.
- People
- Annual HIPAA training and background checks for staff and subcontractors.
- If something happens
- A documented incident-response plan, with prompt breach notification under HITECH.
- Contract
- A BAA with every customer.
Who owns what
Clear lines here too.
Shift
- Infrastructure security and platform controls
- Encryption and monitoring
- Agent guardrails and the audit trail
Your organization
- User access and authentication practices
- Data classification and endpoint security
- Staff training
- Legal responsibility for, and ownership of, all PHI
Shift runs on AWS’s HIPAA-eligible infrastructure. AWS holds its own SOC 1, 2 and 3 attestations for that infrastructure; they are AWS’s, not Shift’s.
Bring us your hardest request.
We’ll run it against an agent, live, in the demo.