How PriorDesk protects patient information

When PriorDesk performs services for a covered practice that involve protected health information, PriorDesk acts as the practice's HIPAA business associate.

This page explains how access is controlled, where patient information remains, who performs the work, and the safeguards PriorDesk uses when working through practice-approved systems and payer workflows.

Business Associate Agreements, security information, and applicable policy documentation are available to practices during evaluation and onboarding.

At a glance

  • Your practice creates, controls, and can revoke the accounts PriorDesk uses.
  • PriorDesk works through practice-approved systems and payer workflows and does not maintain a separate patient-record database.
  • Named PriorDesk specialists performing work involving protected health information are located in the United States and access PHI only from within the United States.
  • A Business Associate Agreement is executed before PriorDesk receives access to protected health information.
  • PriorDesk-controlled accounts use multi-factor authentication.
  • PriorDesk devices used for client work are encrypted and subject to defined security requirements.
  • Patient information is not accepted through the PriorDesk website.

Access your practice controls

Your practice creates the accounts PriorDesk uses, determines the permissions provided, and retains the ability to modify or revoke access.

Accounts are assigned to named individuals. PriorDesk does not use shared credentials for client systems.

PriorDesk requests only the access necessary to perform the services described in your Service Order, which may include authorization work queues, documentation required to prepare an authorization request, practice-management systems, and payer portals approved by your practice.

Access begins only after the Business Associate Agreement and applicable service agreement have been executed and your practice has provisioned the necessary accounts.

If the specialist assigned to your practice changes, PriorDesk coordinates with your designated contact so that access can be updated appropriately.

When the engagement ends, your practice can revoke PriorDesk's access to its systems.

Work stays within approved systems and payer workflows

PriorDesk performs authorization work through the systems and payer workflows your practice authorizes. These may include your EHR, practice-management system, payer platforms such as Availity, Carelon, eviCore, payer-specific portals, and authorized payer telephone channels when required.

PriorDesk does not maintain a separate patient-record database and does not download or retain copies of patient records outside the practice-approved systems required to perform the work.

Authorization documentation, payer reference numbers, statuses, follow-up activity, and outcomes are recorded in the systems designated by your practice. Telephone follow-up activity is documented in the same practice-approved workflow.

PriorDesk does not maintain patient-level case tracking outside practice-approved systems. Authorization status, payer reference numbers, patient-specific dates, documentation, and outcomes remain within the systems designated by your practice. PriorDesk may maintain aggregate operational information for workload and capacity management that does not identify individual patients.

Patient information should not be submitted through the PriorDesk website, ordinary email, text message, or other unapproved communication channels.

If patient information is inadvertently sent to PriorDesk through an unapproved channel, PriorDesk notifies your practice and deletes the information from PriorDesk-controlled systems in accordance with its documented privacy and incident-response procedures.

Who performs the work

Named PriorDesk specialists are assigned to client work.

Personnel who access protected health information for PriorDesk perform that work from within the United States. PriorDesk does not offshore client PHI access.

Specialists complete required privacy and security training before being granted access to client PHI and receive refresher training in accordance with PriorDesk policy.

Authorization work is performed by personnel authorized by PriorDesk and assigned to the practice.

Any person or entity permitted to create, receive, maintain, or transmit PHI on behalf of PriorDesk must satisfy the applicable HIPAA, confidentiality, security, and contractual requirements before access is granted.

How PriorDesk accounts and devices are protected

PriorDesk requires multi-factor authentication on every PriorDesk-controlled account.

Devices authorized for client work use full-disk encryption and are subject to PriorDesk security requirements.

Credentials are assigned to individual users and managed through approved credential-management practices. Credentials may not be shared between personnel.

PriorDesk uses a HIPAA-eligible workspace under a signed Business Associate Agreement with the platform provider for its internal email, documents, and video.

Patient information may not be stored in personal email accounts, on personal mobile devices, or in unauthorized applications.

Access to client systems follows the authentication and security controls established by the practice and the applicable platform.

What PriorDesk does not do

PriorDesk provides administrative prior authorization support. PriorDesk does not:

  • Make clinical decisions.
  • Determine medical necessity.
  • Select or change diagnosis or procedure codes.
  • Conduct peer-to-peer reviews.
  • Sign documents on behalf of a treating provider.
  • Represent itself as the treating provider.
  • Sell patient information.
  • Use patient information for purposes outside the services authorized by the practice.
  • Use client PHI to train or improve artificial intelligence models.

Clinical decisions and clinical documentation remain the responsibility of the treating practice.

If a security or privacy incident occurs

If PriorDesk becomes aware of a suspected security or privacy incident involving a client's information, PriorDesk follows its documented incident-response process to investigate, contain, document, and address the event.

The affected practice is notified without unreasonable delay and in accordance with the requirements contained in the applicable Business Associate Agreement and law.

Information provided to the practice will include, as applicable, what occurred, the information involved, actions taken in response, and any additional steps required.

PriorDesk designates responsibility for administration of its HIPAA privacy and security program, including risk analysis, workforce training, incident response, and maintenance of its security policies.

Agreements and documentation

Before live client work involving PHI begins, PriorDesk requires appropriate agreements and operational safeguards.

These include:

  • A Business Associate Agreement covering the parties' responsibilities under applicable HIPAA requirements.
  • A Service Order or service agreement documenting scope, responsibilities, capacity, pricing, and exclusions.
  • Written privacy and security policies applicable to PriorDesk personnel.
  • A documented security risk analysis and risk-management process.
  • Workforce privacy and security training records.
  • Defined incident-response procedures.
  • Appropriate agreements with subcontractors or service providers that may create, receive, maintain, or transmit PHI on PriorDesk's behalf.

Additional security documentation may be made available to contracted practices or prospective clients during security review.

Where your records remain

PriorDesk's operating model is designed so that patient records remain within the systems your practice has selected and approved.

PriorDesk does not maintain a separate patient-record database and does not retain copies of patient records outside those systems.

Florida law requires certain health care providers using certified electronic health record technology to ensure that patient information stored in an offsite physical or virtual environment is physically maintained in the continental United States, its territories, or Canada.

PriorDesk does not relocate or separately host your patient records.

As an additional PriorDesk operating control, personnel do not access client PHI from outside the United States.

What we ask of your practice

To help maintain appropriate access and information-security controls, we ask each client practice to:

  • Provision individual accounts with only the permissions required for the agreed scope of work.
  • Keep clinical documentation and patient information within approved practice systems.
  • Avoid sending PHI through ordinary email, text messages, the PriorDesk website, or other unapproved channels.
  • Notify PriorDesk when payer portals, EHR access, workflows, or designated practice contacts change.
  • Promptly revoke access when it is no longer required.
  • Notify PriorDesk of suspected security or privacy concerns involving our services.

Security questions and documentation requests

For questions about PriorDesk's Business Associate Agreement, security practices, or available compliance documentation, contact:

info@priordesk.com
1-888-601-4040

To report a suspected privacy or security concern involving PriorDesk, use the same contact information and mark the message “Urgent: Privacy/Security.”

Reported concerns are reviewed promptly by the person responsible for PriorDesk's privacy and security program.

Last reviewed: September 2026