Privacy Policy

Last Updated: October 29, 2025

Important Notice: MedAppeals is committed to protecting your privacy and ensuring HIPAA compliance. This Privacy Policy explains how we collect, use, protect, and share information when you use our AI-powered medical appeals platform.

1. Information We Collect

1.1 Account Information

1.2 Medical Documents and Data

1.3 Technical Information

2. HIPAA Compliance and Medical Data Protection

HIPAA Business Associate: MedAppeals operates as a HIPAA Business Associate for covered healthcare providers. We maintain comprehensive safeguards to protect Protected Health Information (PHI).

2.1 PHI De-identification Process

2.2 Data Minimization

We only process the minimum amount of medical information necessary to generate effective insurance appeals. Our AI system focuses on:

2.3 Security Safeguards

3. How We Use Your Information

3.1 Core Platform Services

3.2 AI Training and Improvement

3.3 Platform Analytics

4. Information Sharing and Disclosure

4.1 No Sale of Medical Data

We never sell, lease, or commercially exploit your medical information or patient data.

4.2 Limited Sharing for Platform Operations

4.3 Legal Requirements

We may disclose information only when required by law, such as:

5. Data Retention and Deletion

5.1 Retention Periods

5.2 Data Deletion Rights

6. Your Rights and Choices

6.1 Access and Correction

6.2 Privacy Controls

6.3 Data Portability

7. International Data Transfers

Your data is primarily processed and stored in the United States using Microsoft Azure's secure cloud infrastructure. If data is transferred internationally, we ensure:

8. Children's Privacy

MedAppeals is designed for healthcare professionals and is not intended for use by individuals under 18. We do not knowingly collect personal information from minors. If we become aware of such collection, we will delete the information promptly.

9. Third-Party Services

9.1 Integrated Services

9.2 Analytics and Monitoring

We use privacy-focused analytics tools that do not track individual users or share data with advertising networks.

10. Security Incidents

In the event of a security incident affecting your data:

11. Updates to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or applicable laws. We will:

12. Contact Information

Privacy Officer

Email: [email protected]

HIPAA Compliance

Email: [email protected]

For General Support

Email: [email protected]

Platform: Submit requests through your account dashboard

13. State-Specific Rights

13.1 California Residents (CCPA/CPRA)

California residents have additional rights including:

13.2 European Residents (GDPR)

EU/EEA residents have rights including:

Questions about this Privacy Policy? Contact our Privacy Officer at [email protected] or through your account dashboard. We're committed to addressing your privacy concerns promptly and transparently.