Compliance

HIPAA & Business Associate Agreements

When PAuthNow handles Protected Health Information (PHI) on behalf of a covered entity, we do so as a HIPAA business associate under 45 CFR 160.103.

Scope of services

PAuthNow provides administrative support for medication (pharmacy benefit) prior authorizations only. Our staff are trained administrative specialists — not licensed physicians, pharmacists, nurses, or other clinicians. We do not select therapy, counsel patients, make medical necessity determinations, or provide medical, pharmacy, legal, or insurance advice. Every PA request is authorized and signed by the prescriber. We do not handle surgical, procedural, imaging, DME, or other medical-benefit prior authorizations.

Business Associate Agreement (BAA)

Before any PHI is exchanged with PAuthNow, we execute a mutually acceptable Business Associate Agreement that meets the requirements of 45 CFR 164.504(e). Our standard BAA covers permitted uses and disclosures, safeguards, subcontractor obligations, breach notification, and return or destruction of PHI at termination. We can review our standard form or your covered entity's form.

Safeguards

Standards & interoperability

We support workflows consistent with the CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) and NCPDP SCRIPT electronic prior authorization (ePA) standards where payers and PBMs have implemented them. Common submission channels include CoverMyMeds, Surescripts, payer/PBM portals, and fax where required.

Certifications

SOC 2 Type II readiness is in progress. PAuthNow does not currently hold SOC 2 or HITRUST certification and will not represent otherwise on this site, in RFP responses, or in customer communications. A current program status summary is available on request from security@pauthnow.com.

Contact

Security & compliance: security@pauthnow.com

← Back to home