Built to Hold Less of Your Data

Most vendors ask a practice to trust how well they guard a database of patient records. Patient Validator is built so there is no such database to guard. Contact data passes through, gets verified, and is gone — which is the difference between a safeguard and a promise.

1. Pass-Through by Design — No Patient Database

The most reliable way to protect patient data from ransomware and database breaches is to never accumulate it.

  • No patient records at rest: Patient Validator runs as a real-time pass-through verification service. A contact is submitted, checked against live sources, and the result is returned to your interface. We do not build, keep or sell a database of the patients you validate.
  • Nothing carried between sessions: Once a check completes, the submitted contact is released from working memory. No patient-identifiable payload is written to a persistent store or a long-lived cache.
  • What we do keep is about your practice, not your patients: your account details, billing record and validation counts — never the contacts you looked up.

2. Encrypted in Transit, Authenticated per Practice

Every hop between your workstation and our infrastructure is encrypted, and every request has to prove who it belongs to.

  • TLS 1.3 in transit: All traffic to and from the dashboard, the browser extension and the API is encrypted in transit using current TLS. Nothing is sent in the clear.
  • Per-account API credentials: Each practice is issued its own API key. Requests that do not carry a valid key for an active account are rejected before any lookup runs, and a key can be rotated on request if you suspect exposure.

3. Business Associate Agreements

Patient Validator operates as a business associate under HIPAA, and we paper that relationship properly.

  • A signed BAA for every practice that asks: we execute a written Business Associate Agreement with the practices we serve. Request one at any time and we will send it for signature — there is no fee and no negotiation cycle for our standard terms.
  • Our own vendors are papered too: the subprocessors handling email and phone verification, and our core infrastructure, are covered by Business Associate Agreements with us. We will name them and share the current list on request.
  • Terms you can read before you sign: the BAA sits alongside our Privacy Policy and Terms & Conditions, and all three are available for your compliance officer to review in advance.

4. Verified Against Authoritative Sources

A validation is only worth as much as what it was checked against. We do not guess at deliverability from patterns.

  • Addresses are standardised and confirmed against official postal reference data, including USPS data for United States addresses.
  • Phone numbers are checked against live carrier and number-portability data, so a disconnected or reassigned line is caught.
  • Email addresses are verified at the mail server rather than by pattern-matching, without sending a message to the patient.

5. Continuous Threat Mitigation

Our backend never faces the open internet directly. It sits behind a managed edge network that filters traffic before it reaches the application, providing automated mitigation against:

  • Distributed Denial of Service (DDoS) campaigns.
  • Scripted credential stuffing and brute-force API key guessing.
  • Automated scraping and bot traffic against the application and the public site.

Building Strategic Trust Together

Patient Validator was built by Bonfire Revenue to make clinical outreach land, not to accumulate data. Choosing a pass-through utility over another platform that stores your patient list means your practice cleans up its touchpoints without creating a second copy of that list somewhere else — and a second breach to worry about.

Request a BAA or Technical Review

Tell us your practice name and who should sign, and we will send the Business Associate Agreement for signature. Please do not include patient information in the message.

This page describes how Patient Validator handles data. It is not legal advice, and it does not on its own satisfy your practice's own HIPAA obligations.