Trust & security

Compliance & trust

Where Atticus stands against every framework that governs delegated care management — stated plainly.

Last updated: July 21, 2026

At most care-management companies, compliance is a scramble: an audit gets scheduled, and a team spends weeks reconstructing what happened months ago. We built Atticus the other way around. Compliance is the product, not the paperwork. Evidence is sealed the day the work happens — every outreach, every assessment, every clinical action lands in a tamper-evident ledger the moment it occurs, already mapped to the standards it satisfies.

Where we stand

Here is our current status against each framework. We state it exactly as it is — no rounding up.

Framework Status What it means
HIPAA Live We operate as a Business Associate under BAAs with every covered entity we serve — encryption, access controls, audit trails, and incident response in place today.
URAC Case Management v7.0 In progress Atticus is pursuing URAC Case Management accreditation. We will publish any accreditation only after URAC grants it.
NCQA HEDIS MY2026 Aligned Reporting capability: HEDIS MY2026 measures computed nightly across the population, with export packs for plan submission. This is a capability, not a certification claim.
CMS Stars Aligned Reporting capability: Star measures tracked continuously and tied to live interventions — adherence, screenings, follow-up. Again, a capability, not a certification.
SOC 2 In progress Our SOC 2 audit is underway. Security, availability, and confidentiality controls are in place and operating today; the report follows the audit.
GDPR Live We meet GDPR requirements for the personal data we handle — data-subject rights, processing agreements, and privacy by design.

URAC accreditation

Atticus is pursuing URAC Case Management accreditation. Our care-management evidence is organized continuously for review, and we will publish our accreditation status plainly once it is granted.

The evidence ledger

Everything Atticus does is written to an append-only ledger. Each entry is sealed when it's written and cryptographically chained to the entry before it, so nothing can be edited, backdated, or quietly removed — a daily integrity check verifies the whole chain. Each entry is also mapped, at write time, to the specific URAC, NCQA, CMS, and HIPAA requirements it evidences.

The practical result: when an auditor asks "show me every member who received discharge follow-up within the required window, with timestamps," the answer takes minutes, not weeks — because the proof was captured the day the follow-up happened.

Delegation oversight

Delegated care management means health plans are accountable for our work — so we make ourselves easy to oversee. Plans audit us as a standing right, not a negotiation. We maintain ready-to-export evidence packs for delegation oversight reviews, and our reporting gives plans a live view of the same data we run on, not a quarterly summary.

Your auditors are welcome. If your compliance or delegation-oversight team wants to review us — before contracting or any time after — email compliance@atticushealth.com and we'll set it up.

Subprocessors

We keep our vendor list short on purpose. Our infrastructure runs on Amazon Web Services, and every subprocessor that touches protected health information operates under a Business Associate Agreement and is held to the same safeguards we apply to ourselves. A current subprocessor list is available to customers and prospective customers on request.

Contact

Compliance questions, oversight requests, or documentation needs: compliance@atticushealth.com. For security-specific questions, see Security at Atticus.