CSAIChaptersEventsBlog
Join the June 2 webinar to learn how AI-driven threats are reshaping enterprise security and what teams can do to stay ahead. Register now →

CSA STAR Registry

Security, Trust, Assurance, and Risk Registry

Listings for EZAppeal

Listings for EZAppeal

EZAppeal is a B2B SaaS platform that helps healthcare providers, medical billing companies, and law firms generate insurance appeal letters and prior authorization requests using artificial intelligence. Architecture & Security EZAppeal is built on a zero-PHI architecture: clinical notes are processed in real time and never persisted to our systems. AI inference is performed exclusively on AWS Bedrock under a Business Associate Agreement, keeping protected health information within U.S.-based AWS regions and never used for model training. Every customer executes a Business Associate Agreement before accessing the platform. Infrastructure controls include TLS 1.2+ in transit, AES-256 at rest, bcrypt password hashing, JWT session management, account lockout, rate limiting, and full audit logging compliant with HIPAA § 164.312(b). Service Offering The platform supports outpatient workflows including imaging and diagnostics, durable medical equipment, therapy services, and specialist referrals. EZAppeal works with any U.S. payer through a combination of curated payer-specific criteria and AI-powered dynamic lookup, enabling rapid generation of evidence-based, payer-aligned appeals and prior authorization requests. EZAppeal is committed to reducing administrative burden on healthcare providers while maintaining the highest standards of patient data security and regulatory compliance.

EZAppeal

EZAppeal is a multi-tenant SaaS platform that generates insurance appeal letters and prior authorization requests for U.S. healthcare providers, billing comp...

Listed Since: 2026-05-21

CAIQ
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).