How Meridian protects healthcare data while automating middle-office operations across a private-equity portfolio.
Meridian is an AI-powered operations platform for healthcare businesses. Its software agents prepare administrative work — billing and revenue-cycle follow-up, clinical documentation drafts, scheduling, intake, and reporting — and every action that would touch a business's systems or its people is first reviewed and approved by a human.
The platform runs entirely on Microsoft Azure's managed, HIPAA-eligible cloud services, the same infrastructure foundation trusted by major health systems, and is deployed separately for each business so that no two businesses' data ever mixes.
| Question | Answer |
|---|---|
| Who can see patient data? | Only approved users of that specific business. Sign-in uses Microsoft Entra ID with multi-factor authentication, and each business's records are isolated from every other business on the platform. |
| Can the AI act on its own? | No. Meridian is 100% human-in-the-loop. Every agent action requires a person to approve it first — in the Meridian approval queue or a Microsoft Teams approval card — before anything is sent, changed, or billed. |
| Is data encrypted? | Yes — in transit (TLS 1.2+) and at rest with double encryption (AES-256 plus a second infrastructure-encryption layer). Data is replicated to a second Azure region for durability, and all platform access to storage uses managed identities — no shared access keys exist anywhere in the platform. Each business's data is additionally protected by its own encryption keys, rotated on a regular schedule. |
| Does the AI provider keep or learn from our data? | No. Language-model calls run under a zero-data-retention configuration: prompts and responses are not stored or used to train AI models by the provider. Meridian also sends the minimum information necessary. |
| Is there a record of everything? | Yes. A tamper-evident audit log records every recommendation, approval, rejection, and executed action, with timestamps and user attribution. |
| What happens if something goes wrong? | There is a documented incident-response and HIPAA breach-notification runbook, with defined containment steps, a formal four-factor breach risk assessment, and statutory notification timelines. |
| Is there a signed BAA? | Yes. A Business Associate Agreement is executed with Microsoft (the cloud provider), and Meridian signs BAAs with its portfolio companies as part of onboarding. |
| Domain | How Meridian addresses it |
|---|---|
| Identity & access control | Microsoft Entra ID single sign-on, multi-factor authentication, role-based access (portfolio / business / read-only), unique user identification per HIPAA §164.312(a)(2)(i). |
| Human oversight | Every consequential agent action passes through a human approval gate before execution — a design-level control, not a policy. |
| Encryption & tenant isolation | AES-256 at rest with a second infrastructure-encryption layer, geo-redundant replication, TLS 1.2+ in transit, per-business encryption keys, cryptographic separation between businesses, and keyless managed-identity storage access. |
| Data minimization & AI governance | Zero-data-retention AI provider configuration, prompt minimization, and an audited AI gateway for all model calls. |
| Audit & accountability | Centralized logging of all agent activity, approvals, and administrative actions with retention and export for compliance review. |
| Continuity & backup | Geo-redundant storage replicated to a paired Azure region, database point-in-time restore (30 days), and full infrastructure-as-code enabling complete environment reconstruction — a documented disaster-recovery posture, not just backups. |
| Network security | Private-network-first architecture: services are isolated from the public internet wherever technically supported, with documented exceptions and remediation plans tracked in the risk register. |
| Risk management | Annual HIPAA §164.308(a)(1)(ii)(A) risk analysis with a maintained risk register and scheduled reviews. |
| Incident response | Documented runbook covering detection, containment, HIPAA breach risk assessment, and 60-day notification workflows. |
Compliance officers, IT security teams, and diligence reviewers can receive the complete technical Trust Pack — platform architecture, security and network design, LLM data-handling analysis, a control-by-control HIPAA safeguards mapping, risk register, BAA framework, incident-response plan, and a pre-filled security questionnaire.
Signed-in Meridian administrators: read the full documentation at the full Trust Pack page (requires sign-in).
Everyone else: request it from your Meridian account team during diligence — it is shared under NDA.