Security & compliance

Fits your stack. Built for compliance.

Workers' comp runs on sensitive health information. MACS is built privacy-first from the ground up — with controls designed around HIPAA, multi-state recording consent, and the realities of how claim data moves.

HIPAA-aligned by design

Access controls, encryption in transit and at rest, and privacy-first data handling are built into the platform — not bolted on afterward.

Per-state recording consent

Recording-consent requirements vary by state. MACS captures and enforces the appropriate consent before any recording begins.

Encrypted storage & audit

Protected health information is secured with managed-key encryption, and every action is logged for an auditable record.

Vendor Business Associate Agreements

We maintain Business Associate Agreements with our AI, cloud, and infrastructure partners so PHI is covered across the stack.

Connects to your claims systems

Integrate with the claims platform your adjusters already use, so coordination data flows where the work happens.

A person in the loop

AI output is reviewed and approved by a case manager before it reaches the injured worker — judgment stays human.

MACS is designed to support our customers' workers' compensation and HIPAA obligations. It is not a substitute for your organization's own compliance program or legal counsel. Specific compliance arrangements are confirmed as part of onboarding.

Have questions about security or compliance?

We're happy to walk your security, privacy, or procurement team through how MACS handles protected health information.

Contact us