Frequently Asked Questions

Questions from compliance officers, general counsel, and procurement teams, including the hard ones about data, privacy, and discoverability. If you don't find what you're looking for, email us at support@ruleresource.com.

About RuleResource

What is RuleResource?

RuleResource is a healthcare compliance intelligence platform built for in-house compliance officers, general counsel, and risk managers at health systems and provider organizations. It combines federal statutes, regulations, OIG advisory opinions, enforcement actions, and state guidance into one platform, synthesizes them into a structured plain-language analysis, and delivers a citeable, exportable research record for your compliance file.

Who is this for?

Chief Compliance Officers, General Counsel, compliance analysts, and risk managers at hospitals, health systems, physician practices, behavioral health organizations, FQHCs, and other healthcare providers. If your team regularly asks "what does the regulation say" and needs a documented, citeable answer: RuleResource is built for you.

How is this different from asking a general-purpose tool?

General-purpose tools generate answers from their training data. They cannot tell you which official source a statement comes from, cannot verify that the source is current, and frequently produce confident-sounding but incorrect regulatory statements. RuleResource only synthesizes information from indexed official government sources. Every statement is tied to a specific cited document. You can click through and verify every authority cited. The platform is built to synthesize only from indexed official sources, and it tells you when it has no coverage rather than guessing.

How do I get access?

RuleResource is currently invite-only during a private beta. There is no self-serve signup, and no payment is collected during the beta. Request a demo and we will set up your organization and walk you through the platform with your own compliance questions.

How is this different from Westlaw or LexisNexis?

Westlaw and LexisNexis are general-purpose legal research databases priced for law firms on a per-seat basis. Most in-house compliance teams don't have them. RuleResource is purpose-built for healthcare compliance: it covers the specific regulatory areas that matter (CMS, HHS, OIG, DEA, HIPAA, Stark, AKS, EMTALA, CLIA), produces a structured 12-section deliverable instead of raw search results, includes automated regulatory change monitoring, a Compliance Assistant with 11 specialized tools, email ingestion and document upload with intelligent analysis, and is priced as an organizational subscription rather than per attorney seat. Contact us for custom pricing.

Sources & Accuracy

What sources does RuleResource use?

Only official government sources: federal statutes via the eCFR and Congress.gov, federal regulations (42 CFR, 45 CFR, 21 CFR, and others), Federal Register notices and final rules, federal court opinions from all circuits and the U.S. Supreme Court, OIG Advisory Opinions, HHS Departmental Appeals Board decisions, and state statutes and agency guidance for covered states. We never use secondary sources, commentary, or third-party summaries.

Does it include case law?

Yes. Every research query includes a dynamic search of federal court opinions, which covers all federal appellate courts and the U.S. Supreme Court. For fraud and abuse topics, we also include OIG Advisory Opinions, the most authoritative guidance available on specific Anti-Kickback Statute arrangements. The case law citations are synthesized into the analysis alongside the regulatory text, so you get both the rule and the judicial interpretation.

How current are the sources?

Every source record displays a 'last verified' date. Our system re-fetches and hash-checks sources continuously, in batches every two hours, so the full corpus cycles about every day and a half. When content changes, the source is flagged and a significance assessment is generated. The confidence badge on every research result tells you how recently the underlying sources were verified: Verified (within 7 days), Review (7–30 days), or Stale (over 30 days).

What if RuleResource doesn't have indexed sources for my question?

We will tell you explicitly. If no indexed sources match your topic and jurisdiction combination, the response will say so clearly: we will never generate content from general knowledge to fill a gap. This is a feature, not a bug: a "no indexed sources" result is an accurate answer, not a failure.

What states are covered?

All 50 states, the District of Columbia, and federal. Depth is not uniform and we do not present it as though it were: federal coverage is by far the deepest, most states carry several separately indexed agency and statutory sources, and a few carry only one or two. Every source in the platform shows the date it was last verified against its publisher, and a source whose URL has stopped resolving is labeled that way on the result and in every export rather than being presented as current. Enterprise clients may request prioritized depth for particular states. Where a state's regulations have no free, machine-readable official edition, we carry the governing statute instead and name it for what it is, with the chapter and section range in the title so nothing is presented as a regulation that is not one. That applies to Texas, whose Administrative Code moved to a portal with no public data feed; California, whose Code of Regulations is published under contract by a commercial service; and Massachusetts, Nevada and Delaware, where the same is true for different reasons. For those states most sources are the statutes the rules are adopted under rather than the rules themselves.

Do you cover rules that have not taken effect yet?

Yes, for federal rulemaking. Rulemaking Watch tracks proposed federal rules in the parts of the CFR healthcare compliance actually lives in, and shows the date each comment period closes. It is checked daily against the Federal Register and filtered to rules that would change what a healthcare provider must do, so grant programs, workplace safety standards and food and device notices published by the same agencies are left out. If you watch a matching topic you are alerted when a rule appears and again as its comment period runs out, at thirty days, seven days and one day. A proposed rule is not law and may never become law, and every one is labeled that way. State-level proposed rulemaking is not covered yet.

The Research Report

What does a research report include?

Every report has twelve sections: (1) the research question in professional language, (2) a summary of applicable standards, (3) federal standards, (4) state standards by jurisdiction, (5) how federal and state standards interact, (6) relevant case law and agency guidance, (7) common compliance pitfalls, (8) an audit-ready checklist, (9) documentation requirements, (10) a risk watch flag when applicable, (11) related requirements to review, and (12) recommended next steps.

Can I export my research?

Yes. Every completed research report can be exported to PDF (formatted, with a locked disclaimer footer) or Word (.docx) for your compliance file. The PDF includes the full 12-section report with all authorities cited and linked. You can also copy the full text to your clipboard.

Does it provide legal advice?

No. RuleResource provides informational research, the same kind of research a paralegal or compliance analyst would produce to support a legal decision. It tells you what the law says, what courts have held, and what OIG has opined. It does not tell you what your organization should do, does not create an attorney-client relationship, and does not substitute for qualified legal counsel. The research record is designed to support your counsel's analysis, not replace it.

Can I refine a research result with follow-up questions?

Yes. After receiving a result, you will see suggested follow-up questions that could sharpen the research, for example, whether an LCSW is in a private practice vs. agency setting, or whether the arrangement involves a telehealth component. You can answer those questions and re-run the analysis with the additional context.

Your Data & Privacy: The Honest Answers

Does the platform train on our data? Does it learn from what we ask?

No. RuleResource's analysis engine is configured for zero data retention. Your queries and org data are never used to train any external model, by anyone. Each request is processed and discarded. The system has no memory of what you asked yesterday, last week, or last year. Your questions do not improve any service that any other organization uses. This is a core architectural commitment, not a setting you have to remember to turn on.

Where does my data actually live?

Your data lives in RuleResource's private database, hosted in a SOC 2-compliant cloud environment in the United States. It is row-level isolated, so no other organization can access your queries, history, or profile. The analysis engine processes your queries in transit but does not store them. Your data is not indexed, not shared, and not visible to other RuleResource users or customers.

Does the platform know who we are? Does our org's name leave our account?

No. This is deliberate. When we inject your organization's profile into an analysis to personalize it, we strip your organization's name and any identifying details before it reaches the analysis engine. The system receives categorical context, such as "medium-sized behavioral health organization operating in Texas and Florida with Medicare/Medicaid payer mix," not your org's name. Your organization's name stays in your private account database only.

What does the platform use when I submit a query?

The text of the research question you type. Official source content retrieved from government databases. An anonymized profile of your organization's type, size, states, and compliance risk areas (no name, no identifying info). That's it. The analysis engine receives enough context to produce a tailored, relevant result, but not enough to identify your organization.

Can we use this for sensitive compliance investigations?

RuleResource is best suited for regulatory research and proactive compliance work. For sensitive investigations (potential fraud, specific individual conduct, whistleblower matters), you should work directly with qualified legal counsel. The platform's query history is a business record, and for sensitive investigations you want to manage privilege and discoverability carefully from the start. We provide research infrastructure, not legal strategy.

What about HIPAA? Does RuleResource process any PHI?

RuleResource does not process, store, or transmit Protected Health Information (PHI). The platform handles regulatory research, billing pattern analysis using publicly available CMS data, and compliance assessment, none of which involves individual patient records. Do not submit PHI in your research queries. The NPI and billing analysis tools use public CMS datasets that do not contain individual patient information.

Do you support SSO / SAML?

Not yet. Every account signs in with a password plus a required authenticator-app code (two-factor). Single sign-on with Microsoft Entra ID and Google Workspace will be offered once it can carry the same second factor.

How long do you retain our data, and what happens if we leave?

Your data is retained for the life of your subscription, per your organization's configured retention setting. If you terminate, your organization's data can be exported first and is then deleted in accordance with that retention policy.

Is there an audit trail we can give our auditors?

Yes. Every material action is recorded in an append-only audit log, exportable to CSV.

Platform Learning & Getting Smarter

Does the platform get better the more we use it?

Yes, in two ways. First, your Organization Intelligence Profile improves with use: the more your team interacts with the platform, the richer the profile of your organization's risk profile, service lines, and compliance focus areas. Second, the relevance feedback you give (marking results as helpful or not) is used to understand what kinds of analyses your team finds most valuable, and future responses are shaped by that history.

What is the Organization Intelligence Profile?

The Intelligence Profile is a structured description of your organization built from your website, public enforcement records, and operational data you provide. When you run a research query, this profile is used (in anonymized form) to tailor the analysis to your specific context: your provider type, your payer mix, your risk areas, your enforcement history if any. A hospital's research result looks different from a physician practice's, even on the same question. The profile is what makes that personalization possible.

How does feedback improve results?

When you mark a research result as helpful or unhelpful, that signal is stored against your account. Over time, patterns in your feedback tell the platform which types of analysis, which source types, and which levels of detail your compliance team finds most useful. Future responses are calibrated against those patterns. This learning is local to your account, and it never leaves your database or improves anyone else's experience.

Is there a way to speed up the learning?

Yes. Build your Intelligence Profile first (Settings → Build Intelligence Profile), then use the platform for the regulatory questions your team actually has. The more queries you run in your actual practice areas, the faster the platform understands your risk profile. High-quality feedback (marking what's useful and what isn't) accelerates the calibration.

Compliance Assistant

What is the Compliance Assistant?

The Compliance Assistant is an intelligent chat assistant available from any page in the platform via the floating button in the lower right corner. It can help you search regulations, check sanctions, look up enforcement actions, manage matters and watches, and answer compliance questions in context. It has access to 11 specialized tools that connect directly to the platform's data and capabilities. The Assistant is designed to augment your compliance workflow, not replace professional judgment.

What can the Compliance Assistant do?

The Assistant can search federal and state regulations by keyword or topic, screen individuals against sanctions databases, look up OIG exclusion status, search enforcement actions by provider type or violation category, create and manage matters, add or remove watches on regulatory sources, retrieve your recent research history, and answer general healthcare compliance questions grounded in regulatory knowledge. It operates within the same privacy architecture as the rest of the platform: your conversations are not used for training and your organization's identity is never exposed.

Is the Compliance Assistant a substitute for legal counsel?

No. The Compliance Assistant provides informational research support and platform navigation assistance. It does not provide legal advice, does not create an attorney-client relationship, and should not be relied upon as a substitute for qualified legal counsel. Use it to accelerate research and platform tasks, then apply professional judgment to the results.

Email Ingestion

What is email ingestion?

Email ingestion lets you forward compliance-related emails to RuleResource for automatic categorization and filing. When you forward an email to your designated ingestion address, the platform analyzes the content, assigns a compliance category (regulatory update, enforcement action, policy change, industry guidance, or general compliance), extracts key details, and stores it as a document in your vault. This is designed to help compliance teams capture and organize the steady stream of regulatory communications without manual sorting.

What happens to emails I forward to the platform?

The email content is analyzed by the platform's intelligent analysis engine to determine its compliance relevance and category. The analysis follows the same privacy architecture as all other platform features: your organization's name is not sent to the analysis engine, the content is processed in transit and not retained by the analysis system, and the resulting document is stored in your private account database with row-level isolation. The original email content and the automated categorization are both available in your Document Vault.

What types of emails should I forward?

Forward regulatory updates from federal and state agencies, enforcement action notices, industry association bulletins, payer policy updates, compliance newsletter content, and any other communications your compliance team would typically review and file. Do not forward emails containing Protected Health Information (PHI), privileged attorney-client communications, or sensitive investigation materials unless your organization's counsel has determined it is appropriate to do so.

Document Upload & Intelligent Analysis

What is document upload with intelligent analysis?

You can upload compliance documents (policies, contracts, BAAs, memos, regulatory correspondence, and similar materials) to the Document Vault for intelligent analysis. The platform reviews the document and produces a structured compliance analysis that may include regulatory implications, relevant citations to federal and state authorities, identified compliance risks, and suggested action items. The analysis is intended to support your compliance review process, not replace it.

What types of documents can I upload?

The platform accepts PDF, Word (.docx), and plain text files. Common use cases include compliance policies for gap analysis, vendor contracts for BAA and compliance clause review, regulatory correspondence for impact assessment, and internal memos for compliance alignment review. Do not upload documents containing Protected Health Information (PHI).

How accurate is the intelligent analysis of uploaded documents?

The intelligent analysis is designed to identify compliance-relevant content and map it to regulatory requirements. It draws from the same indexed official government sources used in research queries. However, automated analysis of complex legal documents may not capture every nuance, and the results should be reviewed by qualified compliance or legal professionals before being relied upon for decision-making. The analysis is a starting point for review, not a final compliance determination.

Change Monitoring

What is regulatory change monitoring?

When you run a research query, you can click 'Monitor' to add that query to your watch list. When any of the regulatory sources underlying that query change, you will receive an alert via your weekly digest email. Changes are classified as Significant or Minor, and you can configure your account to receive alerts only for significant changes.

How does the change detection work?

Our system re-fetches sources in batches every two hours, cycling the full corpus about every day and a half, and compares a cryptographic hash of the content to the previous version. If the content has changed, the platform analyzes the new content and classifies the change as significant (a substantive change to requirements, enforcement, or coverage) or minor (formatting, cross-references, or clerical). Significant changes are flagged immediately in your next digest.

How often do I receive digest emails?

Weekly, on Monday mornings, if you have active monitors and there are changes to report. You can configure your frequency to monthly or never in your account settings. We only send the digest when there is something to report; we do not send blank digests.

Still have questions?

We will answer them on a demo call, using your own compliance questions as examples.

Request a Demo