FactAssess
sugeet@factassess.com +1 702 760 3038 +91-989 999 8198
Trust & Compliance
Home / Trust & Compliance
Your Clients' Data Deserves More Than a Privacy Statement
Personal injury law firms work with some of the most sensitive information imaginable — medical records, diagnoses, treatment histories, billing records, deposition transcripts, settlement information, and personally identifiable information.
Before they send a single file, they deserve a clear, direct answer to one question: how exactly is that data protected?
This page lays out FactAssess' approach to HIPAA compliance, information security management, data handling practices, and confidentiality policy — the same standards we hold ourselves to on every AI output audit, case review, and drafting engagement we take on.
HIPAA Compliance
Personal injury case files routinely contain Protected Health Information (PHI) — diagnoses, treatment histories, provider records — which means HIPAA compliance isn't optional for any vendor touching that data, including AI output audit and medical record review providers based outside the United States.
FactAssess' HIPAA-aligned practices include:
A documented Security Risk Assessment covering administrative, physical, and technical safeguards for all PHI handled during medical chronology, demand letter, and case review work
Business Associate Agreements (BAAs) available for every client engagement involving PHI, as required under HIPAA for any vendor processing protected health information on a covered entity's behalf
Role-based access controls limiting PHI exposure to only the reviewers actively assigned to a given case file
Documented breach notification protocols and incident response procedures
Ongoing staff training on PHI handling, HIPAA requirements, and secure data practices for all reviewers working with medical-legal documentation
HIPAA Certificate of Compliance issued to LinksToValue
ISO 27001:2022 — Information Security Management
ISO 27001:2022 is the current international standard for information security management systems (ISMS), covering how an organization identifies, manages, and reduces information security risk across people, processes, and technology.
FactAssess' information security program is structured around ISO 27001:2022 principles, including:
Formal risk assessment and risk treatment processes applied to all systems handling client and PHI data
Documented access control policies governing who can view, edit, or transmit sensitive case and medical record data
Encryption of data in transit and at rest across our document handling and review infrastructure
Regular internal security reviews and continuous improvement of our information security management system
ISO/IEC 27001:2022 Registration Certificate issued to LinksToValue
Data Handling & Security Practices
Beyond formal audit, day-to-day data handling practices are where security actually gets tested. Here's how case files, medical records, and AI-generated drafts move through our process:
Secure intake: All documents are submitted through an encrypted, access-controlled client portal — never through unsecured email or unencrypted file transfer
Encrypted storage and transmission: Data at rest and in transit is encrypted throughout the review, audit, and drafting process
Access controls: Reviewers only access the specific case files assigned to them, with activity logging across our systems
Retention and disposal policies: Client data is retained only as long as necessary for the engagement and securely disposed of according to documented retention schedules
Backup, Availability & Recovery: Appropriate backup, business-continuity, and recovery practices help protect information availability and support operational resilience
Confidentiality Policies
Every engagement is governed by strict confidentiality obligations, independent of and in addition to HIPAA-specific requirements:
Mutual confidentiality and non-disclosure terms are standard in every client agreement
Case-specific information is never shared, referenced, or reused across client engagements
Internal staff confidentiality agreements apply to every reviewer, analyst, and team member with access to client data
Client-specific data segregation practices prevent cross-contamination between different firms' case files
How We Handle Your Data
Stage
Our Approach
Client Assurance
Upload
Secure intake through the designated client submission workflow
Your records enter a controlled workflow
Processing
Access limited to authorized personnel and systems
Need-to-know handling of sensitive information
Review
Human reviewers work within the defined case workflow
Medical-legal information is handled confidentially
Delivery
Reviewed work product returned through the approved delivery channel
Controlled transfer of completed documents
Retention / Disposal
Retain for 5 years → Review after 5 years → Securely destroy if no longer required
Data retained and deleted according to documented policy and contractual requirements
Our Compliance Roadmap
Compliance isn't a one-time achievement — it's an ongoing commitment we continue to build on as our AI output audit services scale. Current and upcoming priorities include:
Milestone 1: HIPAA Compliance — Completed August 2026
Milestone 2: ISO 27001:2022 certification — Completed August 2026
Milestone 3: SOC 2 Type II attestation — Target December 2026
Security questions shouldn't slow down a decision. Ask us directly.
Request Our Security Overview →
Our Services
AI Output Audit Complex & Catastrophic Case Review Platform Partner Program (for AI vendors)
Resources
Blog Case Studies
ISO 27001:2022 Certified HIPAA Compliant
About Us
Our Company Who We Serve Trust & Compliance
Get in Touch with Us!
© 2026 FactAssess. All rights reserved. Privacy Policy