Privacy & HIPAA Policy
Last updated: April 21, 2026
At ClaimAdvocate, protecting your personal and health information is our highest priority. This Privacy Policy details how we handle your data in strict compliance with HIPAA and modern security standards.
1. Information We Collect
We only collect the information necessary to process your appeal. This includes personal identifiers (name, email, phone number) and Protected Health Information (PHI) found within your denial letters, insurance policy codes, and provider details.
2. How We Secure Your Data
All data processed by ClaimAdvocate is encrypted both in transit (using TLS 1.3) and at rest (using AES-256 encryption). Our internal AI processing environment is fully air-gapped and HIPAA-compliant, ensuring that your data is never used to train generalized models outside of our organization.
3. Data Sharing
We do not sell, rent, or lease your personal or health data to third parties. We only share information with your specified insurance provider for the explicit purpose of submitting your appeal. Your data is strictly compartmentalized.
4. Data Retention and Deletion
We securely retain your case data to allow you to monitor your active appeals via the Dashboard. You may request full deletion of your PHI and account data at any time by contacting our privacy officer. All deleted data is completely purged from our servers within 30 days.
5. HIPAA Compliance
As a Business Associate, we adhere strictly to the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules. Regular third-party audits ensure our infrastructure continually meets or exceeds federal security standards.