Security & Trust

How we handle sensitive information

Honest status on BAAs, PHI channels, and portal readiness — no seals for credentials we do not hold.

PHI channels

  • Public email & fax — administrative / non-PHI only. Never send case PHI to admin@arkmedisreviews.com or 832-678-7069.
  • Secure portal — the only path for case PHI. Secure case upload is available for authorized portal users (Business, Provider, and Admin) after MFA: a verified email and a second factor, with an authenticator preferred and US SMS supported. ArkMedis will review and process submitted cases after Texas Department of Insurance Independent Review Organization certification is issued. The application is filed and in process. Certification is not active. Send case PHI only through the portal vault. Do not send PHI by email or fax. Download of stored files is not available yet.
  • Contact — primary path today for partnerships and operational setup (non-PHI).

Business Associate Agreements

  • Google Workspace HIPAA BAA — held (accepted) for administrative Workspace mail.
  • Google Cloud HIPAA BAA — held; accepted 2026-09-17 for GCP project arkmedis-web.

Holding both BAAs is not an accreditation and is not TDI certification. Portal sign-in requires MFA (verified email and a second factor). Secure case upload is available for authorized portal users (Business, Provider, and Admin) after MFA: a verified email and a second factor, with an authenticator preferred and US SMS supported. ArkMedis will review and process submitted cases after Texas Department of Insurance Independent Review Organization certification is issued. The application is filed and in process. Certification is not active. Send case PHI only through the portal vault. Do not send PHI by email or fax. Download of stored files is not available yet. Audit events are structured stdout logs, not a retention-backed audit program.

Encryption & residency intent

Case storage runs on Google Cloud in the United States. Objects use opaque ids, with encryption in transit and at rest consistent with GCP defaults and the Cloud BAA. No customer-managed encryption key is set. There is no virus scan. Download is not enabled. Authorized sessions can store a file when the vault bucket is configured.

Portal controls

Secure case upload is available for authorized portal users (Business, Provider, and Admin) after MFA: a verified email and a second factor, with an authenticator preferred and US SMS supported. ArkMedis will review and process submitted cases after Texas Department of Insurance Independent Review Organization certification is issued. The application is filed and in process. Certification is not active. Send case PHI only through the portal vault. Do not send PHI by email or fax. Download of stored files is not available yet.

  • MFA — required for a portal session: verified email and a second factor (authenticator preferred, or US SMS). The app requires it before a session.
  • RBAC — Business, Provider, or Admin. No assigned role means no workspace.
  • Encrypted vault — authorized sessions can store a case file under an opaque id. Download is not enabled. No CMEK key is set.
  • Audit logs — structured stdout events. Not a retention-backed audit program.
  • Case status views and secure messaging are not live.

See Portal. We do not claim URAC, HITRUST, NCQA, NAIRO, SOC 2, or active TDI certification.

What we do not claim

This site does not claim URAC, HITRUST, NCQA, NAIRO, SOC 2, “certified IRO,” or any other accreditation we do not hold. We do not use “pursuing” language for those credentials in public marketing. Texas TDI IRO status is applicant only. The application is filed and in process. Certification is not active. That fact is also stated on About.

Full scannable checklist: About — Trust status.

Questions

Security or partnership questions (non-PHI): use Contact. Legal entity: FabCare LLC d/b/a ArkMedis · FEIN 33-1873176 · Houston primary office.