HIPAA and Compliance

How ClaimCompass Protects Your Information

ClaimCompass, LLC
3623 Crossings Dr. Ste 382
Prescott, AZ 86305
Email: admin@myclaimcompass.ai

Effective Date: 06-20-2026
Last Updated: 06-20-2026

Our Commitment to Privacy and Compliance
ClaimCompass operates at the intersection of health information, government benefits, financial data, and personal documents. We take our obligations to protect your information seriously — not because compliance requires it, but because the people who trust us with their most sensitive documents deserve nothing less.This page describes our approach to HIPAA compliance, data security, and the protections we have built into our platform for your benefit.

HIPAA Compliance
Who We Are Under HIPAA
ClaimCompass acts as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) when we handle protected health information (PHI) on your behalf. PHI includes any information in your uploaded documents that relates to your health condition, healthcare treatment, or payment for healthcare that identifies you or could reasonably be used to identify you.

Our HIPAA Obligations
As a Business Associate, ClaimCompass is obligated to:Use and disclose PHI only as permitted by our Business Associate Agreement and applicable law.Implement appropriate administrative, physical, and technical safeguards to protect PHI.Report any breach of unsecured PHI to affected individuals and relevant authorities as required by the HIPAA Breach Notification Rule.Ensure that any subcontractors or vendors who handle PHI on our behalf are contractually bound to the same HIPAA protections.

Technical Safeguards
ClaimCompass's technical infrastructure includes:Encryption of all data in transit using TLS 1.2 or higher.Encryption of all data at rest.Access controls and authentication requirements limiting access to PHI to authorized personnel only.Automated deletion protocols for documents uploaded by users who do not complete a purchase.Infrastructure hosted on Amazon Web Services, which maintains a signed HIPAA Business Associate Agreement with ClaimCompass.

Minimum Necessary Standard
ClaimCompass processes only the information contained in your uploaded documents that is necessary to provide the analysis and appeal generation services you request. We do not seek additional health information beyond what you choose to upload.

Your HIPAA Rights
You have the following rights with respect to your PHI:The right to access your PHI held by ClaimCompass.The right to request amendment of inaccurate PHI.The right to request an accounting of disclosures of your PHI.The right to request restriction of certain uses and disclosures.To exercise any of these rights, contact our Privacy Officer at steve@myclaimcompass.ai.

Financial Compliance
Not a Financial Institution
ClaimCompass is not a bank, financial institution, investment adviser, or credit service. ClaimCompass does not provide financial advice, financial services, or credit services of any kind.

Payment Processing
All payment transactions on ClaimCompass are processed by Stripe, Inc., a PCI DSS-compliant payment processor. ClaimCompass does not store, process, or transmit full payment card data. Our payment practices comply with applicable payment card industry standards.

Not a Legal Service or Insurance Service
ClaimCompass does not provide legal services, insurance services, insurance brokerage, or claims adjustment services. ClaimCompass is a technology platform that assists users in preparing their own appeal documents. The use of ClaimCompass does not constitute the practice of law or the provision of insurance services.

Data Security Standards
ClaimCompass maintains the following security standards:
Infrastructure Security:
Our platform operates on Amazon Web Services (AWS) infrastructure, which maintains SOC 2 Type II and ISO 27001 certifications and is a HIPAA-eligible service provider.
Encryption:
All data transmitted to and from the ClaimCompass platform is encrypted in transit. All stored data is encrypted at rest.
Access Controls:
Access to user data and PHI is restricted to authorized personnel on a need-to-know basis. We maintain access logs and conduct periodic access reviews.
Incident Response:
ClaimCompass maintains a documented incident response plan. In the event of a data breach involving PHI, we will notify affected individuals and relevant authorities as required by HIPAA and applicable state law.
Vendor Management:
We conduct due diligence on all third-party vendors who may have access to user data and require contractual commitments to maintain appropriate security standards.

Breach Notification
In the event of a breach of unsecured PHI, ClaimCompass will notify affected individuals without unreasonable delay and no later than 60 days following the discovery of the breach, in accordance with HIPAA Breach Notification Rule requirements. Notification will be provided by first-class mail or, if you have provided an email address, by email.

Contact Our Privacy Officer
For questions about our HIPAA practices, data security, or compliance obligations, please contact:

Privacy Officer
ClaimCompass, LLC
3623 Crossings Dr. Ste 382
Prescott, AZ
Email: steve@myclaimcompass.ai