The HITRUST r2 letter in your vendor-risk file for Vyne Medical was earned inside a company that was split in two this week. MRO announced on September 16 that it bought Vyne Medical, the business behind Trace, Refyne and Cloud Fax, while Vyne Dental stays with private equity firm TJC. The certification may well survive the sale. Whether it does turns on one question neither press release answers: who operates Trace's security controls during the "Vyne Medical, an MRO Company" transition. Get that answer in writing before you renew anything.
This is a carve-out, not a clean handoff, and carve-outs are where security paperwork lags reality.
What MRO Bought, and What Stayed Behind
MRO bought the hospital half of Vyne and left the dental half — and the shared corporate history — with the seller. MRO's announcement describes Vyne Medical as "a provider of data intake and intelligent document processing solutions for over 800 hospitals nationwide," and says the combined organization "will serve more than 2,500 hospitals and 35,000 clinics." Terms were not disclosed. HIT Consultant describes MRO as a Norristown, Pennsylvania company backed by Parthenon Capital, historically known for release of information (ROI), payer audit management and clinical data exchange.
The products are what touch your data. Per Vyne Medical's site, Trace captures and consolidates incoming documents, voice recordings and images, with document automation and EMR integration; Refyne transmits patient records digitally to CMS for claims, audits and appeals using esMD; and Cloud Fax handles fax intake. If you have read our breakdown of where OCR ends and extraction begins, this is that stack sold as a service, with humans behind it.
The seller was candid about why. "This is a focus decision," Vyne CEO Steve Roberts said in the seller's release, calling dental revenue-cycle management "the largest, fastest-growing opportunity in front of us." The same release promises that Vyne Medical's clients "will continue to be supported by the same team without interruption."
This is MRO's third acquisition in 15 months. It bought Q-Centrix, an enterprise clinical data management platform, in June 2025, with Parthenon making a significant new investment to support MRO's expansion, and bought Clinetic, a clinical-trial recruitment platform, in November 2025.
Whose HITRUST Certification Covers Trace Today?
Vyne Medical's own r2 covers Trace — not MRO's — and it was assessed before the sale. Vyne Medical announced on February 3, 2025 that its "hosted Trace® Platform and Refyne® Denials Management solution" had earned HITRUST r2 certified status. MRO's own HITRUST certification, announced February 14, 2025, names four different systems: Exchange Manager, Exchange Connector, Patient Central and Requester Central. MRO's letter is not a substitute for Vyne's, and your file should not treat it as one.
A HITRUST r2 certification is a validated assessment of a named environment's controls. HITRUST says it "is valid for two years," with an interim assessment after one year and a full assessment at the end of the term. If Vyne Medical's letter is dated near its February 2025 announcement, that full reassessment lands around early 2027 — performed under MRO ownership, on an environment MRO will have owned for only a few months.
One more word in that announcement deserves attention: hosted. The certification names the hosted Trace platform. If your Trace deployment is not the hosted one, check whether the letter describes your instance at all.
When Does a Sale Count as a Significant Change?
A sale becomes a significant change when the people running the certified controls change — not when the logo does. HITRUST's guidance on changes to a certified environment lists as potentially significant any acquisition or change in control "where controls over in-scope systems are no longer being operated by the Assessed Entity that originally obtained the certified report or the entity that acquired substantially all the assets of the Assessed Entity." Once an organization believes that has happened, it "must notify HITRUST," which may require an external assessor, re-testing, or a new assessment.
Take the strongest version of the reassuring case first. That clause is friendly to this deal. If MRO bought Vyne Medical whole and the same team keeps operating the same hosted environment, the certification plausibly carries through untouched — and "the same team without interruption" is exactly the promise you would want.
The exposure is whatever Vyne Medical did not run by itself. When TJC bought Vyne from Accel-KKR in 2019, it was one company selling to dental practices and to "more than 800 hospital and health system clients," built on what it called "the company's robust technology platform." Today Vyne Medical and Vyne Dental still list the same headquarters: 100 Ashford Center North, Suite 300, Dunwoody, Georgia. The previous certification cycle shows how intertwined the two were: Vyne Medical's November 2022 r2 covered FastAttach — a claim-attachment product now sold by Vyne Dental — alongside hosted Trace and Refyne. The 2025 scope drops FastAttach, but that says nothing about which controls underneath it were shared.
Nothing public says which controls were shared: identity provider, security monitoring, endpoint management, hosting contracts, onboarding and offboarding. Neither release mentions a transition-services arrangement either way. But if any of those controls now come from Vyne Dental on MRO's behalf, they are being operated by neither the certified entity nor its buyer — the exact case HITRUST names. That is the gap to close, and only the vendor can close it.
What Happened After MRO Bought MediCopy?
An earlier acquired business kept running its own tooling for years, and that is where the breach landed. MRO bought MediCopy, a Nashville release-of-information firm serving physician practices, in February 2022. On January 13, 2026, per HIPAA Journal, an unauthorized party breached cloud-based file-sharing software managed by "MRO Corp-owned company MediCopy" and downloaded files containing Deaconess Health System patients' names, Social Security numbers, medical record numbers and medical records. MediCopy told Deaconess on February 2 — twenty days later.
This is not evidence that MRO runs weaker security than its peers; release-of-information vendors are targets because of what they hold. It is evidence of something more useful to a buyer. Almost four years after the deal, the acquired business still had its own file-sharing tool, and a hospital reading MRO's 2025 certification announcement would not have found it among the four named platforms. The parent's letter describes the parent's environment. Acquired environments converge on their own schedule — the same lesson in our piece on Medallion's purchase of Andros, where NCQA credit turned out to follow the certified entity doing the work, not the brand on the invoice.
How Much of Your PHI Pipeline Does MRO Now Touch?
For many hospitals, both ends of it. MRO CEO Jason Brown's stated goal is to "capture that information at the 'front door' when it enters a provider's workflow, curate it into discrete, structured clinical data, and exchange it wherever it needs to go." Map that onto a health system that buys the whole portfolio and one vendor now touches:
- Inbound intake — faxes, calls and scanned images through Trace and Cloud Fax.
- Outbound CMS submissions — audit responses, claims and appeals through Refyne's esMD gateway.
- Disclosure — release of information and payer audit management, MRO's core business.
- Abstraction — clinical data management through Q-Centrix.
It also puts two CMS esMD gateways under one owner. MRO says it became one of the first certified Health Information Handlers in 2011, and Vyne Medical describes itself as one of fewer than 20 nationwide certified to provide that gateway.
The case for consolidation is real. HIT Consultant reports that hospitals facing "administrative labor shortages" are moving away from managing separate vendors for fax intake, call recording, record indexing and ROI fulfillment. Fewer vendors means fewer BAAs, fewer integrations and fewer security reviews for an HIM team that is already short-staffed. The cost is that one incident, one outage or one contract dispute now spans the front door and the back door of your PHI. Score it as one vendor in your third-party risk register, not three — the same concentration question we raised when Bending Spoons closed Airtable in 31 days.
Who Signs Your Business Associate Agreement Now?
Probably the same entity as before — but confirm it, and confirm who sits beneath it. Under 45 CFR 164.502(e)(1)(ii), a business associate may let a subcontractor "create, receive, maintain, or transmit protected health information on its behalf" only if it "obtains satisfactory assurances" that the subcontractor will safeguard it. If Vyne Dental keeps touching Trace or Refyne data during the transition, it is Vyne Medical's subcontractor and needs that paper. If MRO infrastructure starts carrying it, the same applies.
Ask one AI-specific question while you are there. HIT Consultant describes the combined platform as "machine-learning automation for data extraction, classification, and routing" paired with human-in-the-loop specialists. Your BAA's permitted-use language decides whether documents your hospital sends through Trace can be used to improve that automation. Read it now, not after the platforms merge.
What to Do Before the 2027 Recertification
This Week:
- Pull every Vyne Medical contract and BAA — Trace, Refyne, Cloud Fax — and record the exact legal entity named as counterparty.
- Send your account team four written questions: Which entity operates the controls in the hosted Trace and Refyne r2 scope today? Are any provided by Vyne Dental or TJC during the transition, and until when? Has HITRUST been notified of a significant change, and what did it decide? What is the certification's expiry date?
- Confirm your Trace deployment is the hosted platform the certification names.
This Month:
- Map MRO's full footprint in your PHI flow — intake, esMD submissions, ROI, payer audits, abstraction — and re-tier it as a single concentrated vendor in your third-party risk register.
- Get the breach-notification clock and a named incident-response contact in writing for the transition. MediCopy's notice reached Deaconess 20 days after the intrusion, and HIPAA runs the business associate's clock from discovery, not intrusion; check whether your BAA requires faster, and which entity is on the hook to meet it.
- Request a subcontractor list for hosted Trace and Refyne dated after September 16, 2026.
Before Renewal or Early 2027, Whichever Comes First:
- Require the next r2 to name hosted Trace and Refyne in scope — whether they stay a standalone environment or migrate into MRO's platform — and make receipt of that letter a renewal condition.
- Add a cure-or-exit right tied to certification lapse, and identify a non-MRO esMD path so an outage or dispute cannot stall your Medicare audit responses.
The Bottom Line
A certification is a photograph of an org chart, and this one was taken before the org chart changed. The industry already learned this lesson with SOC 2: buyers ask for a bridge letter to cover the months between report periods. A carve-out is the same gap, stretched across a change of owner, and there is no bridge letter unless you ask for one.
None of this says MRO will handle Trace badly. It says the paper in your file describes a company that no longer exists in that form, and the vendor who can tell you what replaced it has every reason to answer quickly while the relationship is new. Our six questions for an AI vendor security review apply here almost unchanged.
The letter certifies who ran Trace in 2025. Ask who runs it now.
Continue Reading
- Medallion Bought Andros. Your NCQA Credit Is Per Element.
- Valsoft Bought Square 9. Who Funds the Next Model?
- AI Vendor Security Review: 6 Questions That Change the Answer
- Kiteworks Bought Bonfy. Ask for the Terms WAMNET Got.
- Alianza Bought Skribby. Your Meeting Audio Changed Owners.
- Hospitals Test Vendor AI. Fewer Than Half Have a Sandbox.
