Anonymous denial uploads and derived prefill cache
Owner: Privacy Officer
24 hours active, then encrypted archive pending case linkage or deletion review
Legal reviewSecurity and privacy
DenialHelp publishes the controls that are operating now and distinguishes them from planned work. Contract coverage, service eligibility, data class, and runtime checks all have to agree before protected health information may leave the application.
Sensitive application data stays on the encrypted data volume and travels over TLS. Backups and recovery evidence are checked operationally; a hosting-company name alone is not treated as proof.
Appeal access is scoped to the case credential or an explicitly consented professional grant. General security records are PHI-minimized and append-only at the database boundary; canonical case events and AI-handling receipts add hash-chain tamper evidence.
Every AI path declares its provider, model allowlist, permitted data class, retention/training posture, and failure mode. Raw PHI is refused if the approved de-identification path is unavailable.
Anonymous uploads and derived files remain on the encrypted PHI volume. Archive operations refuse symbolic links and cross-filesystem moves; destructive clinical retention is paused pending policy approval.
A legal hold overrides destructive retention. Case, document, communications, billing, and audit records use separate record-class decisions instead of a blanket one-size-fits-all period.
Security alerts and operating logs must remain PHI-free. Access anomalies, incidents, backups, and privileged jobs have named owners and runbooks.
This public view intentionally excludes contract documents and internal evidence locations. Each entry was reviewed on the date shown; enabling another service requires a new eligibility and privacy review.
| Service | Purpose | Permitted data | Boundary | Reviewed |
|---|---|---|---|---|
| Amazon Web Services | Textract OCR, encrypted S3 backups, Lightsail TLS gateway | public, internal, pii, phi, deidentified | Executed BAA; approved services only | 2026-08-28 |
| Paubox Email API | transactional email | public, internal, pii, phi, deidentified | Executed BAA; approved services only | 2026-08-28 |
| Google Workspace | operator mailbox, administrative notifications | public, internal, pii, phi, deidentified | Executed BAA; approved services only | 2026-08-28 |
| Claude subscription CLI | AI inference after formal de-identification | public, internal, deidentified | No BAA asserted; de-identified data only | 2026-08-28 |
| Anthropic API | non-PHI development and explicitly classified public/internal workloads | public, internal, deidentified | Not used for PHI | 2026-08-28 |
| Stripe | payment and subscription billing using PHI-free metadata | public, internal, financial_non_phi | Not used for PHI | 2026-08-28 |
| Cloudflare DNS | authoritative DNS only | public | Not used for PHI | 2026-08-28 |
| Sentry | PHI-scrubbed error and performance telemetry | public, internal | Not used for PHI | 2026-08-28 |
| Telegram Bot API | aggregate PHI-free operational alerts | public, internal | Not used for PHI | 2026-08-28 |
| Stedi Healthcare Eligibility | X12 270/271 eligibility checks | public, internal | Review pending | 2026-08-28 |
| Google Analytics / PostHog | aggregate public-site analytics only | public | Not used for PHI | 2026-08-28 |
Schedule 2026-08-28.1
Owner: Privacy Officer
24 hours active, then encrypted archive pending case linkage or deletion review
Legal reviewOwner: Privacy Officer
Current 30-day deadline is an interim minimization control; destructive disposition requires privacy and legal approval
Legal reviewOwner: Privacy Officer
Jurisdiction-, role-, contract-, and legal-hold-specific; existing seven-year deadlines are interim and require review
Legal reviewOwner: Privacy Officer
6 years
ReviewedOwner: Security Officer
6 years unless a longer legal hold applies
ReviewedOwner: Finance
Finance/tax policy; jurisdictional review required
Legal reviewDo not include patient information in the first message. Ask the support team to escalate the report to the Security or Privacy Officer.
hello@denialhelp.com