Privacy Policy
ClaimGrade LLC · Effective February 2026
ClaimGrade LLC (“ClaimGrade,” “we,” “us,” or “our”) is committed to protecting the privacy and security of your information. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use the ClaimGrade platform and related services (the “Services”).
As a healthcare technology provider, we are especially vigilant about protecting Protected Health Information (PHI) in compliance with the Health Insurance Portability and Accountability Act (HIPAA) and applicable state privacy laws.
1. Information We Collect
Account Information
When you create an account, we collect your name, email address, organization name, and professional role. This information is necessary to provide and administer your account.
Protected Health Information (PHI)
When you upload clinical documentation for analysis, the documents may contain Protected Health Information as defined by HIPAA. We process PHI solely to provide the Services and in accordance with our Business Associate Agreement (BAA).
Usage Data
We automatically collect information about how you interact with the Services, including pages visited, features used, timestamps, browser type, and device information. This data is used to improve the Services and does not include PHI.
Cookies and Similar Technologies
We use essential cookies required for authentication and session management. We use cookieless, privacy-friendly analytics (Vercel Web Analytics) to understand aggregate site usage; this does not set cookies, fingerprint visitors, or track individuals across sites. We do not use advertising or tracking cookies.
2. How We Use Your Information
- Provide, maintain, and improve the Services
- Analyze clinical documentation against payer requirements
- Communicate with you about your account and the Services
- Detect, prevent, and address technical issues and security incidents
- Comply with legal obligations, including HIPAA requirements
- Generate de-identified, aggregate analytics to improve our models (PHI is never used for this purpose without proper de-identification)
3. HIPAA Compliance
ClaimGrade operates as a Business Associate under HIPAA when processing PHI on behalf of Covered Entities. Our obligations regarding PHI are governed by our Business Associate Agreement.
- PHI is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Access to PHI is limited to authorized personnel and systems on a need-to-know basis
- We maintain audit logs of all PHI access as required by HIPAA
- PHI is never used for marketing, advertising, or any purpose outside the scope of the BAA
- We will notify you of any breach of unsecured PHI in accordance with HIPAA Breach Notification Rules
4. Data Sharing and Disclosure
We do not sell your personal information or PHI. We may share information with:
- Service providers who assist in operating the Services (e.g., cloud hosting, authentication), bound by data processing agreements and, where applicable, BAAs
- Law enforcement or government agencies when required by law, subpoena, or court order
- Professional advisors (legal, accounting) under obligations of confidentiality
All third-party service providers with potential access to PHI have executed Business Associate Agreements.
5. Data Retention
Account information is retained for the duration of your account and for a reasonable period afterward for legal and business purposes.
Uploaded clinical documents and analysis results are retained in accordance with your organization's settings and our BAA. You may request deletion of your data at any time.
Usage data and analytics are retained in de-identified form and may be kept indefinitely to improve the Services.
6. Data Security
We implement administrative, technical, and physical safeguards to protect your information, including:
- Encryption of data in transit and at rest
- Role-based access controls and multi-factor authentication
- Regular security assessments and vulnerability testing
- Incident response procedures aligned with HIPAA requirements
- Employee training on data privacy and security practices
No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your personal information
- Object to or restrict certain processing of your information
- Data portability (receive your data in a structured format)
- Withdraw consent where processing is based on consent
Rights regarding PHI are governed by HIPAA and our BAA. To exercise any of these rights, please reach out through the contact information on our website.
8. Children's Privacy
The Services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and, where appropriate, by email. Your continued use of the Services after changes become effective constitutes acceptance of the revised policy.
10. Contact Us
If you have questions about this Privacy Policy or our data practices, please reach out through the contact information on our website.