Security & Trust

You're considering sending us your practice's billing data. Here is exactly how that data is protected — and, just as importantly, how the money flows.

Your money never touches us.
Payers pay your practice, directly, exactly as they do today. Recoveries post on your own remittances, to your own accounts. We invoice a percentage only after you can see the recovery in your own data. We are never in the payment path.
A BAA before a single byte.
A HIPAA Business Associate Agreement is signed before any file transfer — it legally binds us to HIPAA's safeguards, breach-notification duties, and use limits.
Files move one way, into locked storage.
Claim files move only through access-controlled, encrypted, BAA-covered channels — the secure upload on our signup page (available only after the BAA is executed) or a private BAA-covered folder. Never plain email attachments.
Analysis runs on secured systems — not scattered cloud tools.
Claim files are processed on access-controlled machines under our BAA obligations. Patient data is not fed into third-party tools outside BAA coverage.
One approval, then we run.
You authorize recovery once, at engagement. From there we prepare and file resubmissions, appeals, and disputes under that standing authority — no per-claim sign-offs eating your staff's time. A complete log of every filing is available to you, and you can pause us at any time.
Minimum necessary, deleted on exit.
We request only the files the work requires. When an engagement ends, PHI is returned or destroyed per the BAA.

Questions?

Ask us anything about data handling before sending a file — including a copy of our BAA to review with your compliance contact: rahul@claimmender.com.