Home Technology

Medical records intelligence is here.

Security & Compliance

Sensitive information deserves
serious protection.

Medical records and legal information contain some of the most sensitive data your organization handles.

Compex maintains a formal, risk-based security and privacy program designed to protect that information throughout our technology, operations and workflows, backed by robust controls, ongoing testing and independent audits. Our personnel receive HIPAA training and follow established operating procedures for handling protected health information.

Connect with Our Team Download Security & Privacy Overview →
Secure Login Options

Access that fits your security requirements.

The Compex Client Portal supports secure password-based access, multi-factor authentication and single sign-on. Organizations can require MFA or use SSO based on their corporate security and access requirements.

Security built into the workflow

Protection at every stage.

Security isn’t something added after the record arrives.

Compex applies administrative, technical and operational safeguards throughout the information lifecycle, from record retrieval and processing through access, delivery and storage.

Sensitive information is encrypted in transit and at rest, while least-privilege access, multi-factor authentication and privileged-access controls help limit information and systems to authorized users.

Centralized logging, monitoring, vulnerability scanning and independent penetration testing help Compex identify, assess and respond to potential risks.

Encrypted in transit
and at rest

Least-privilege
access controls

Multi-factor authentication

Centralized logging
and monitoring

Independently audited

Trust, backed by verification.

Compex undergoes an annual SOC 2 Type II audit performed by an independent third party. The audit evaluates controls relevant to the security and operation of Compex systems, providing customers with independent assurance around the practices used to protect sensitive information.

AICPA SOC for Service Organizations badge
SOC 2
Type II

Annual independent third-party audit

Ongoing
Testing

Routine vulnerability scanning and independent penetration testing

Formal Security
Program

Risk-based security and privacy practices designed for sensitive information

Download Security & Privacy Overview →
Resilience & business continuity

Protect the information.
Keep the operation running.

Security also means being prepared when something unexpected happens.

Compex maintains business continuity and disaster recovery practices designed to reduce the risk of data loss and minimize disruption to operations.

Geographically resilient recovery capabilities
Regular backup and restoration testing
Documented continuity and disaster recovery plans
24/7 infrastructure monitoring and alerting
Privacy matters

Your data is yours.

Compex does not sell client data.

Information entrusted to Compex is used to deliver our services and fulfill applicable legal and compliance obligations.

Our security and privacy practices are designed around a simple principle: sensitive information should be used only for the purposes for which it was entrusted to us.

Responsible technology

Innovation without compromising trust.

As Compex expands the use of automation and medical records intelligence, security and privacy remain fundamental to how new technology is developed and deployed.

Asabell™ is designed to help claims and legal teams understand medical information while operating within the broader Compex security and governance environment.

Technology should make sensitive information more useful, without making it less protected.

Meet Asabell™
Security across the Compex experience

One security framework. Across the workflow.

Security and privacy are foundational whether your team is requesting records through the Client Portal, connecting Compex with an existing system or using medical records intelligence.

Client Portal

Secure access to record requests, status and completed information.

Integrations & APIs

Security-conscious connections designed around supported customer workflows.

Asabell™

Medical records intelligence operating within the Compex technology and governance environment.

FAQs

Questions, answered.

Is Compex SOC 2 Type II audited?

Yes. Compex undergoes an annual SOC 2 Type II audit performed by an independent third party.

How does Compex protect sensitive information?

Compex uses safeguards including encryption in transit and at rest, least-privilege access controls, multi-factor authentication, security monitoring and testing designed to protect sensitive information.

Does Compex have business continuity and disaster recovery plans?

Yes. Compex maintains documented business continuity and disaster recovery plans, along with backup, restoration and recovery practices designed to support operational resilience.

Does Compex sell client data?

No. Compex does not sell client data. Client information is used to deliver Compex services and fulfill applicable legal and compliance obligations.

Security shouldn’t be an afterthought.

See how Compex protects sensitive medical and legal information
throughout the record workflow.

Connect with Sales Download Security & Privacy Overview →