STAR Registry Listing for
EZAppeal
EZAppeal
EZAppeal is a multi-tenant SaaS platform that generates insurance appeal
letters and prior authorization requests for U.S. healthcare providers,
billing companies, and law firms.
Service Architecture
A React single-page application served via Vercel (CDN/edge) and a Node.js
/Express backend hosted on Railway (AWS-backed U.S. infrastructure).
PostgreSQL stores account metadata, anonymized usage telemetry, and
executed Business Associate Agreements — no clinical content is persisted.
AI inference runs exclusively on AWS Bedrock under an executed BAA,
in U.S. regions only.
Data Handling
Users submit denial letters and clinical notes through the authenticated web
interface. The platform processes documents in real time and returns
generated correspondence in seconds. Protected health information exists
only in transient memory during inference — no PHI is persisted at rest.
Audit logs record document-generation events with anonymized metadata only
(payer, procedure code, criteria-match metrics).
Assessment Scope
This CAIQ self-assessment covers the EZAppeal web application, REST API,
authentication, Stripe payments integration, and the AWS Bedrock inference
pipeline. Infrastructure controls inherited from AWS, Railway, Vercel, and
Stripe are identified as third-party outsourced where applicable. A
Business Associate Agreement is executed with every customer before
platform access is granted.

Listed Since: 05/21/2026
STAR Level 1
Self-Assessment & Partner-Provided

CAIQ Self-assessment v4.1.0
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Created or renewed 4 days ago, on May 21, 2026.