Privacy Policy
Effective 28 August 2026 · Policy version 2026-08-28.1
What we collect
To draft your appeal letter, escalation letters (second-level, external review), peer-to-peer prep, and supporting tools, we collect and process:
- Your email address
- The denial letter file you upload
- Your insurance company, plan name, and requested drug
- Clinical context relevant to the appeal — diagnoses, lab values, prior therapies, and other facts you supply about your medical history
- Your treating physician’s name (and optionally, email)
- Technical data such as IP address and browser metadata, used for security and audit compliance
How we use it
We use the information you provide only to:
- Draft your appeal letter at any level (first-level, second-level, external review), and on request, generate a peer-to-peer call brief or letter summary
- Send you that letter and related communications
- Maintain HIPAA audit logs of PHI access
- Operate, maintain, and secure the Service
- Comply with legal obligations
We do not sell or rent your information and do not use your PHI to train a public AI model. Each AI route is limited by an exact service, data class, model allowlist, retention and training posture, and failure policy. Raw PHI is not approved for Anthropic routes; text must pass the approved de-identification and outbound-leakage controls or processing is refused.
HIPAA and PHI handling
Case data is encrypted in transit and at rest. Sensitive access and state changes are recorded in durable, PHI-minimized audit records. Canonical case events and AI-handling receipts add hash-chain tamper evidence; the general audit log does not claim that property. Third-party use is governed at the exact service and data-class level: an executed Business Associate Agreement does not make every product from that vendor eligible for PHI. Services without an approved PHI boundary receive only the approved non-PHI or de-identified class, and the application fails closed when that boundary cannot be met.
Sub-processors
The following services have different purposes and data boundaries. Contract status is assessed per service; a vendor-level agreement is not a universal approval. Configuration must also match the reviewed service, region, data class, and termination procedure before data flows.
- Google Workspace — corporate email (mic@denialhelp.com and aliases) and Google Drive used for internal operations. May receive PHI when patients or clinicians email PHI to denialhelp.com addresses. Covered by Google's HIPAA Business Associate Addendum, accepted by mic@denialhelp.com on 2026-05-12 on Workspace Business Standard. Only services on Google's HIPAA-Covered Services list (Gmail, Drive, Docs, Meet, Calendar, Chat) are used for PHI; non-Covered services and third-party add-ons are restricted by admin policy.
- Amazon Web Services — public TLS gateway (Lightsail, Sydney), document OCR (Textract), and S3 (encrypted offsite backups). Covered by our signed AWS Business Associate Addendum from 2026-05-08. PHI flows over private channels (Tailscale tailnet from Lightsail to our home server) and is encrypted at rest with SQLCipher (AES-256) on top of LUKS-encrypted disk.
- Anthropic — approved only for public, internal, or de-identified AI payloads through the registered routes. No executed BAA is asserted for these routes. Raw PHI is blocked, and a failed de-identification or outbound-leakage check refuses processing rather than sending the original text.
- Stripe — payment processing. Receives only PHI-free metadata (customer email, opaque appeal/customer IDs, tier name). Drug, insurer, and clinical fields stay in our local encrypted database. We rely on the HIPAA financial-institution / payment-conduit exception (45 CFR 164.501) so a Stripe BAA is not required.
- Transactional email — delivered by Paubox Email API. Covered by Paubox's own HIPAA Business Associate Agreement, signed 2026-05-16 (separate from the AWS BAA). Email-content metadata includes your address, subject, and basic appeal context (insurer, treatment). Earlier email vendors evaluated and discarded for HIPAA reasons: AWS SES (3 production-access denials, abandoned 2026-05-16), Resend (no BAA available, migrated away 2026-05-08), Postmark (refused to sign BAA, migrated away 2026-05-09).
- Cloudflare — DNS only. Cloudflare's authoritative name servers resolve denialhelp.com to our AWS Lightsail gateway. PHI does NOT flow through Cloudflare's proxy or CDN; that path was decommissioned 2026-05-08 in favour of AWS (which has a signed BAA covering Lightsail, Textract, and S3).
- SRFax (HIPAA-compliant fax delivery) — used only when fax submission is enabled and the user opts in. Off by default; activated only after a signed BAA with SRFax is in place. SRFax is HIPAA-aligned by vendor design (its plans include BAA at no additional charge).
- Hunter.io / Apollo.io / Google Workspace SMTP — used only for our clinician-outreach workflows; these vendors do NOT receive any patient PHI.
- Headless Chrome / Playwright (operated by us) — used to fetch publicly available insurer coverage policies from insurer websites. No PHI is sent outbound; only the insurer name, plan type, and drug class are used as search inputs.
Outcome-report email links
Approximately 28 days after we send your appeal letter, we email you a follow-up message with three one-click links: "Approved", "Denied", and "Still waiting". These links contain a cryptographically signed token (HMAC-SHA256) bound to your appeal ID, the chosen outcome, and a 90-day expiry. Clicking a link shows a confirmation page; we record the outcome only after you confirm. Anyone with possession of the email link is able to record the outcome — we recommend you do not forward the email. The token cannot be used for any purpose other than recording an outcome on the specific appeal it was issued for.
Data retention
Retention is governed by a versioned schedule for each record class, not one blanket period. Anonymous uploads remain on encrypted storage and enter a controlled archive or case-linkage review after 24 hours; destructive clinical retention is paused until the applicable jurisdiction, role, contract, and legal-hold rules are approved. HIPAA-required policy documents and PHI-minimized security audit evidence use their reviewed six-year schedules. A legal hold overrides deletion. You may request access, correction, export, or deletion through the dashboard or privacy@denialhelp.com; we will explain any legal or contractual limit that applies.
Browser extension
When you use the DenialHelp browser extension, the denial text you choose to check is sent to DenialHelp only to generate your explanation. Before any AI analysis, that text is de-identified on our own systems — names, dates of birth, member IDs and other direct identifiers are removed. We do not store the text you check through the extension; it is used only to produce your result and then discarded, and the request is logged without its content (metadata only). The extension reads only the text you explicitly paste or highlight and submit — it does not read other page content, track your browsing, or collect anything else. You can remove the extension at any time from your browser's extensions page.
Your rights
You may at any time:
- Request access to the PHI we hold about you
- Request correction of inaccurate information
- Request deletion of your account and data
- Request an accounting of disclosures of your PHI
California residents have additional rights under the CCPA. EU/UK residents have rights under GDPR/UK GDPR. We honor these rights.
Security
We use encryption in transit, encrypted application storage, role-based access controls, and PHI-minimized audit records that are append-only at the database boundary. Canonical case events and AI-handling receipts add hash-chain tamper evidence; the general audit log does not claim that property. No system is perfectly secure; a suspected incident follows the documented investigation and legally required notification process.
Contact
For privacy inquiries, deletion requests, or to exercise your rights, email our Privacy Officer at privacy@denialhelp.com. The Privacy Officer is Michael John Ryan, designated under HIPAA §164.530(a)(1) and §164.308(a)(2). DenialHelp, LLC is a Delaware limited-liability company.
This notice describes the current product data flows. Material changes are versioned and presented through an appropriate notice or acceptance flow before they take effect.