HIPAA Notice
Last updated: July 31, 2026
This notice describes how Denial Appeal Pro ("DAP") handles protected health information (PHI) when provider offices and billing professionals use our appeal-generation software.
Our role
DAP processes PHI contained in denial letters, EOBs, and remittance documents you upload — including patient names, member IDs, dates of service, and clinical/billing codes. Provider offices and covered entities typically remain responsible for HIPAA compliance for their patients' information.
When a covered entity transmits PHI to DAP for appeal generation, DAP may act as a Business Associate under HIPAA. Covered entities are responsible for determining whether a BAA is required and for obtaining patient authorization or another lawful basis to disclose PHI to us.
Business Associate Agreement (BAA)
Covered entities and business associates that require a BAA with DAP may request one by emailing baa@denialappealpro.com. Include your organization name, primary contact, and estimated usage. We will respond with BAA terms appropriate to your deployment.
Subprocessors and BAA status
| Provider | Function | PHI / BAA notes |
|---|---|---|
| Supabase | Database, authentication, storage | BAA available on HIPAA-eligible Supabase plans (Team/Enterprise). Customers must enable HIPAA add-on and sign Supabase's BAA. |
| OpenAI | AI extraction and letter generation | BAA available under OpenAI Enterprise agreements. The standard API is not intended for PHI unless covered by a signed BAA. De-identify documents before upload if you are not on an Enterprise/BAA-covered plan. |
| Netlify | Hosting and serverless functions | BAA available on Netlify Business or Enterprise plans. Production deployments handling PHI should use a BAA-covered Netlify tier. |
| Stripe | Payment processing | Processes billing and account data only — not PHI from uploaded denial documents. Stripe maintains PCI-DSS compliance for payment data. |
| Resend | Transactional email | Sends account and payment emails. Do not include PHI in email content. Evaluate BAA requirements if email templates ever contain patient-specific information. |
Security practices
- Encryption in transit (TLS 1.2+) for all web and API traffic;
- Encryption at rest via cloud provider infrastructure;
- Role-based access controls and authenticated sessions;
- Row-level security on user data in the database layer;
- Uploaded source documents retained up to 30 days unless longer retention is required for active accounts or legal obligations;
- Rate limiting and monitoring on public endpoints.
Your responsibilities
- Determine whether a BAA with DAP is required for your use case;
- Execute BAAs with DAP and applicable subprocessors before uploading PHI;
- Use minimum necessary PHI — redact or de-identify when full identifiers are not required;
- Review all generated letters before submission to payers;
- Maintain your own workforce training and access policies.
Contact
BAA requests and HIPAA questions: baa@denialappealpro.com
See also our Privacy Policy.