CSAIChaptersEventsBlog
Join the June 2 webinar to learn how AI-driven threats are reshaping enterprise security and what teams can do to stay ahead. Register now →

STAR Registry Listing for

EZAppeal

EZAppeal

EZAppeal is a multi-tenant SaaS platform that generates insurance appeal
letters and prior authorization requests for U.S. healthcare providers,
billing companies, and law firms.

Service Architecture

A React single-page application served via Vercel (CDN/edge) and a Node.js
/Express backend hosted on Railway (AWS-backed U.S. infrastructure).
PostgreSQL stores account metadata, anonymized usage telemetry, and
executed Business Associate Agreements — no clinical content is persisted.
AI inference runs exclusively on AWS Bedrock under an executed BAA,
in U.S. regions only.

Data Handling

Users submit denial letters and clinical notes through the authenticated web
interface. The platform processes documents in real time and returns
generated correspondence in seconds. Protected health information exists
only in transient memory during inference — no PHI is persisted at rest.

Audit logs record document-generation events with anonymized metadata only
(payer, procedure code, criteria-match metrics).

Assessment Scope

This CAIQ self-assessment covers the EZAppeal web application, REST API,
authentication, Stripe payments integration, and the AWS Bedrock inference
pipeline. Infrastructure controls inherited from AWS, Railway, Vercel, and
Stripe are identified as third-party outsourced where applicable. A
Business Associate Agreement is executed with every customer before
platform access is granted.

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Information about EZAppeal
Listed Since: 05/21/2026

STAR Level 1

Self-Assessment & Partner-Provided

Cloud Controls Matrix

CAIQ Self-assessment v4.1.0

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

Created or renewed 4 days ago, on May 21, 2026.