HIPAA COMPLIANCE & PRIVACY PROTOCOLS

Privacy Policy

Last updated: August 2026

1. Patient Health & Financial Data Protection

Remedy handles Explanation of Benefits (EOB), hospital statements, and denial codes under strict client-side encryption and zero-retention principles.

  • Insurance & Patient Profiles: Patient name, date of birth, insurance carrier, member ID, group number, deductible, and out-of-pocket maximum accumulation metrics.
  • Billing Line Items: CPT procedure codes, diagnostic descriptions, hospital chargemaster billed amounts, in-network contractually allowed amounts, plan discounts, copayments, and coinsurance amounts.
  • Negotiation & Call Logs: Representative names, representative employee IDs, call reference ticket numbers, and promised billing holds.

2. Strict Prohibition on the Sale of Health Data

We never sell, rent, license, or monetize your health billing statements, procedure codes, or dispute histories to pharmaceutical companies, insurance underwriters, data brokers, or advertising networks.

We comply with state consumer health privacy legislation, including the Washington My Health My Data Act, Nevada SB 370, and the California Consumer Privacy Act (CCPA/CPRA).

3. Subprocessor Encryption & Data Minimization

All data is stored in tenant-isolated, encrypted cloud repositories (AES-256 at rest, TLS 1.3 in transit) on Google Cloud Platform / Firebase in USA regions. Payment card processing is executed directly by Stripe under PCI-DSS Level 1 certification.

4. Patient Rights & Data Portability

You may export your complete reconciliation records, audit logs, and dispute packets in PDF or HTML at any time, or request complete account erasure by contacting privacy@medicalclaimmanager.com.