Privacy & Compliance
ClaimCompass, LLC 3623 Crossings Dr. Ste 382 Prescott, AZ 86305 Email: admin@myclaimcompass.ai
Effective Date: 06/20/2026 Last Updated: 09/13/2026
Does HIPAA Apply to ClaimCompass?
No. HIPAA applies to covered entities (hospitals, doctors, health insurers) and their business associates (vendors hired by those entities). ClaimCompass is neither.
ClaimCompass is a direct-to-consumer document preparation tool. You — the patient — voluntarily upload your own denial letter to prepare your own appeal. Because you are initiating the data sharing for your personal benefit, and because ClaimCompass does not work on behalf of a healthcare provider or insurer, HIPAA does not regulate this Service.
This is the same reason a personal finance app that reads your own bank statements is not regulated by banking law — the regulation follows the institution, not the data.
What Laws Do Govern Us?
| Law | What It Requires |
|---|---|
| FTC Act | We cannot make deceptive claims about how we handle your data |
| FTC Health Breach Notification Rule | If your health data is intercepted or exposed during transmission, we must notify you |
| California CCPA / CPRA | You have rights to know, delete, and opt out regarding your personal data |
| Arizona consumer protection law | Honest, accurate disclosures about our service |
How We Handle Your Documents
When you upload a denial letter to ClaimCompass:
- It is transmitted to our servers over an encrypted HTTPS connection (TLS)
- It is received by an AWS Lambda function and processed entirely in memory
- The text is analyzed by our AI to generate your appeal score and strategy
- The result is returned to your browser
- Your document is discarded — it is not written to any database or storage system
For paid orders, your claim details (denial type, payer, appeal strategy) are passed through Stripe's secure payment system to generate your appeal letters. Your letters are then emailed to you and not retained on our servers.
What We Do Not Do
- We do not store your uploaded documents
- We do not sell your information
- We do not share your documents with third parties for any purpose other than generating your appeal
- We do not log the contents of your documents
- We do not use your appeal content to train AI models for unrelated purposes
Technical Security Measures
Encryption in Transit: All data between your browser and our servers is encrypted using TLS 1.2 or higher.
In-Memory Processing: Documents are analyzed in isolated AWS Lambda execution environments. No content is written to disk or persistent storage.
No PHI Logging: Our Lambda functions are configured to avoid logging document content. Error handling strips document text before any log entries are written.
AWS Infrastructure: Our analysis pipeline runs on Amazon Web Services, which maintains SOC 2 Type II and ISO 27001 certifications.
FTC Health Breach Notification
Under the FTC Health Breach Notification Rule, if your health information is accessed or disclosed without authorization during transmission to or from our service, we are legally required to notify you promptly. We maintain incident response procedures to detect and report any such event.
Financial Compliance
Not a Financial Institution: ClaimCompass is not a bank, financial institution, investment adviser, or credit service.
Payment Processing: All payments are processed by Stripe, Inc., a PCI DSS-compliant payment processor. ClaimCompass does not store, process, or transmit full payment card data.
Not a Legal Service: ClaimCompass does not provide legal advice, legal representation, or insurance services. We are a document preparation platform. Use of ClaimCompass does not create an attorney-client relationship.
Contact
For questions about our privacy or compliance practices:
Privacy Officer ClaimCompass, LLC 3623 Crossings Dr. Ste 382 Prescott, AZ 86305 Email: steve@myclaimcompass.ai