Safety and control

You keep legal authority. We keep the receipts.

Every guardrail on this page exists because of a real failure mode, not a theoretical one. Read the ones specific to each agent below.

Security and compliance

We stay inside deterministic, auditable guardrails so an agent’s flexibility never comes at the cost of your security or compliance standards.

Deterministic, controlled access

AI should be flexible. Your security standards shouldn’t have to be. Every action an agent takes against your EHR or PM system runs through the same controlled, auditable path, reads run free, writes are confidence-gated and read back to confirm they actually posted. Your policies get enforced every time, not just most of the time.

Private, isolated hosting

Every model runs in a privately hosted, isolated environment inside AWS’s HIPAA-eligible cloud. Your PHI is never used to train or fine-tune a model.

Guardrails, not good intentions

Every agent runs inside guardrails built for the specific way it could go wrong, coding above what the documentation supports, canceling care based on a coverage check, contacting a patient without consent. When a request would cross one of those lines, the agent stops and routes to a human instead of quietly complying.

Guardrail in action

Staff

Bump this visit to a 99215.

Charge Capture agent

Documentation only supports a 99213. Flagging for physician review, not auto-applying.

Data governance and privacy

We protect your practice’s and your patients’ data, always enforcing your policies and following industry best practices.

[Practice name] Health

Patient

Is it safe for me to stop taking this medication?

Assistant

That’s a clinical question, let me connect you with your care team.

Data governance

Your data is used only as you instruct, and is never shared with or used to train another customer’s agents. What your practice teaches its agents, coding patterns, payer quirks, your own SOPs, stays yours.

Data privacy

PHI is encrypted at rest and in transit by default, and every agent runs on minimum-necessary access, it only sees what its specific task requires, not a patient’s full record.

Policy-configurable boundaries

Every agent respects the boundaries you set, conservative-coding preferences, escalation rules, what it can and can’t say to a patient, plus one hard boundary that never changes regardless of configuration: no agent gives medical advice, a clinical question always routes to a person.

“The strongest thing we can tell you isn’t a certification, it’s what each agent is built to never do.”

Certifications say a third party checked Shift’s general controls once a year. Guardrails say exactly what a specific agent won’t do to your claims, your patients, or your compliance posture, and why. That’s the deeper, harder-to-fake trust signal, and it’s real today, not on a roadmap.

Charge Capture

Never auto-applies a higher E&M level or a changed primary diagnosis over the provider’s own; any disagreement goes to the physician, never silently overridden.

This is the exact failure mode that cost UCHealth $23M in a 2024 False Claims Act settlement for auto-coding ED visits above what the documentation supported.

Denial Management

A payer-attestation gate for payers whose contracts require coder or clinician sign-off before resubmission (e.g. Humana, Cigna); the agent routes to a human for those payers rather than assuming its own authority to resubmit.

Prior Auth

Never fabricates a clinical justification to improve an authorization’s odds of approval; if the documentation doesn’t support medical necessity, the agent says so instead of writing around the gap.

Insurance Verification

Never cancels, reschedules, or denies care based on a coverage finding; it flags the issue to a human with time to fix it, coverage data informs, it doesn’t gate care.

Scheduling

A provider-change and prior-auth-survival stop: rebooking with a different provider or changing a visit type never silently invalidates an auth or referral that was tied to the original booking, the agent checks first.

Registration

A data-integrity rule on every write-back: a wrong or unconfirmed field written to the PM system creates the exact denial it was meant to prevent, so every write is read back and verified before it’s treated as saved.

Patient Balances

Consent and TCPA rules gate every outbound contact attempt, and a PCI rule governs how payment information is ever collected or discussed, empathy and compliance together, not compliance as an afterthought to collections pressure.

Document Intake

A patient-match-before-filing rule (a document never gets attached to the wrong chart) and a critical-result-escalation rule (a time-sensitive clinical result is never queued normally, it’s flagged immediately).

What’s real and Shift’s own

  • BAA with every customer
  • HIPAA Privacy and Security Rule compliance
  • HITECH breach-notification adherence (45 CFR 164.410)
  • Encryption at rest (AES-256, AWS KMS) and in transit (TLS 1.2+)
  • RBAC and mandatory MFA
  • Minimum-necessary PHI on every access
  • Full audit trail with per-action rationale, 7-year retention
  • Annual HIPAA training and background checks for all personnel and subcontractors
  • 24/7 monitoring (AWS GuardDuty, CloudWatch, Inspector)
  • A documented incident-response plan with prompt breach notification

What’s real, but inherited, named as such

Shift runs on AWS’s HIPAA-eligible infrastructure, which holds AWS’s own SOC 1, 2, and 3 attestations. Never phrased as “Shift is SOC 2 [anything]” — the attestation belongs to the infrastructure Shift runs on, not to Shift itself.

What’s not yet true

No Shift-held SOC 2 report, in any status, achieved, in-progress-with-a-date, or otherwise. No HITRUST i1 or any other certification. Both are listed in the internal source doc only under “pursuing additional certifications,” undated, aspirational.

Shared responsibility

Shift owns infrastructure security, platform controls, encryption, and monitoring. You own your own user access management, authentication practices, data classification, endpoint security, and staff training. Your organization retains legal responsibility and ownership of all PHI, Shift is a tool, not a covered entity standing in your place.

Control

Four HITL tiers, confidence and dollar thresholds gating every write, full audit trail. Every write is confidence-scored, gated by the tier you’ve set, and read back to confirm it actually posted, not just that the request was sent.

Explore the platform →

Read the guardrails, then ask us the hard questions.