Security and Trust Built for Healthcare

Protecting sensitive healthcare data is fundamental to healthcare decision intelligence, and to getting payments right. As a healthcare technology company entrusted with Protected Health Information, Lyric maintains a comprehensive cybersecurity program designed to meet the security, compliance, and regulatory expectations of our clients.

Talk to Lyric

Data Protection

Lyric's security program is risk-based, built on a defense-in-depth strategy that combines industry-leading controls, continuous monitoring, and proactive risk management, governed by strong oversight processes.

Sensitive information is secured through strong encryption, secure transmission protocols, access controls, and continuous monitoring, preserving the confidentiality, integrity, and availability of the PHI entrusted to our care.

Privacy and Regulatory Compliance

Lyric has achieved HITRUST Risk-based, r2 Certification and the HITRUST AI Security Assessment and Certification, some of the most extensive and demanding security and privacy certifications in the healthcare industry. It means our controls have been independently assessed against a broad set of healthcare, privacy, security, and regulatory requirements.

Lyric also maintains SOC 2 Type II compliance. Independent audits confirm our controls operate effectively over time, not just at a single point in time.

Responsibility and Explainable AI

35+ years of clinical expertise shapes every rule we author. AI extends our capability. Human judgment stays at the center.

Contact usContact us
  • Human Expertise First

    Every recommendation supports clinical and operational accuracy.

  • Explainable Intelligence

    Grounded in clinical policy and clinical knowledge. Transparent, every time.

  • Controlled, Responsible Deployment

    Clinical validation. Client-controlled implementation. Strong data protection.

  • Deterministic Claims Recommendations

    Decision engines run on rules-based logic. AI surfaces findings and organizes source material for expert review. 

Security Practices and Operations

Lyric's security program follows Zero Trust principles: never trust, always verify. Strong access controls, including multi-factor authentication, role-based access controls, and privileged access management, helps protect critical systems and sensitive healthcare information from unauthorized access.

Security is integrated throughout the software development lifecycle. Secure coding standards, automated security testing, penetration testing, and ongoing code review ensure security is built into every stage of product development.
 
Third-party relationships carry real risk. Lyric maintains a rigorous vendor and supply chain security program, with regular assessments that extend our standards across the broader business ecosystem.

Lyric maintains comprehensive business continuity and disaster recovery capabilities. Regular testing and backup validation keep us prepared to respond to operational disruptions.

Prevention alone isn't enough. Our security operations team provides continuous visibility through advanced threat intelligence, threat detection, incident response, and vulnerability management.

Governance and Accountability

Security is an ongoing commitment. Independent validation, adherence to industry best practices, and continuous improvement keep our security posture current.

Our clients trust us to get payments right. We honor that trust by making security foundational to everything we do.

Trust and Certifications

Frequently Asked Questions

The questions health plans ask us most about data protection, security, and responsible AI. Answered directly.

Does AI decide my claims or payments?

No. AI supports your use of Lyric’s clinical and payment tools. It does not replace judgement, and it doesn’t make the final call. Every claim runs on deterministic, rules-based logic that’s transparent, traceable and fully client- controlled.

Who reviews AI-assisted work before it reaches me?

A clinical expert, every time. AI helps our teams organize clinical, reimbursement, and coding guideline sources faster. A human expert still interprets that material and recommends how a payment rule is written and applied.

How does Lyric manage risk from vendors and third parties?

We hold third parties to the same standards we hold ourselves. Lyric runs a vendor and supply chain security program with regular assessments, extending our security standards across every partner in the chain.

What happens if Lyric faces a security incident or service disruption?

We plan before it happens. Continuous threat monitoring and detection catch issues early. Tested incident response, backup validation, and disaster recovery keep your data protected and your service available.