Skip to main content

The business associate agreement

Your practice is the covered entity; Denialbase is your business associate. We sign a business associate agreement (BAA) with every practice before any patient data moves: until it’s signed, sending claims, patient invites and the claims API stay closed. If a BAA is revoked or expires, they close again. Our BAA covers what HIPAA requires of business associates, including permitted uses and disclosures, safeguards, breach notification, subcontractors, patients’ access to their information, and returning or destroying data when the agreement ends. You can download your signed copy in Settings → Agreements.

What we use your data for

To review the claims you send, decide how to appeal them, and work the appeals: nothing else. We don’t sell data or use health information for advertising or marketing.

Retention and deletion

Export

Each user can download a copy of their account data from their account settings.

Patients

Patients hear from us only after your practice sent their claim and our team decided their signature is needed. They see only their own case, and they can revoke their authorization any time. Our privacy policy has the full detail.