HIPAA Notice

Last updated: July 31, 2026

This notice describes how Denial Appeal Pro ("DAP") handles protected health information (PHI) when provider offices and billing professionals use our appeal-generation software.

Our role

DAP processes PHI contained in denial letters, EOBs, and remittance documents you upload — including patient names, member IDs, dates of service, and clinical/billing codes. Provider offices and covered entities typically remain responsible for HIPAA compliance for their patients' information.

When a covered entity transmits PHI to DAP for appeal generation, DAP may act as a Business Associate under HIPAA. Covered entities are responsible for determining whether a BAA is required and for obtaining patient authorization or another lawful basis to disclose PHI to us.

Business Associate Agreement (BAA)

Covered entities and business associates that require a BAA with DAP may request one by emailing baa@denialappealpro.com. Include your organization name, primary contact, and estimated usage. We will respond with BAA terms appropriate to your deployment.

Subprocessors and BAA status

ProviderFunctionPHI / BAA notes
SupabaseDatabase, authentication, storageBAA available on HIPAA-eligible Supabase plans (Team/Enterprise). Customers must enable HIPAA add-on and sign Supabase's BAA.
OpenAIAI extraction and letter generationBAA available under OpenAI Enterprise agreements. The standard API is not intended for PHI unless covered by a signed BAA. De-identify documents before upload if you are not on an Enterprise/BAA-covered plan.
NetlifyHosting and serverless functionsBAA available on Netlify Business or Enterprise plans. Production deployments handling PHI should use a BAA-covered Netlify tier.
StripePayment processingProcesses billing and account data only — not PHI from uploaded denial documents. Stripe maintains PCI-DSS compliance for payment data.
ResendTransactional emailSends account and payment emails. Do not include PHI in email content. Evaluate BAA requirements if email templates ever contain patient-specific information.

Security practices

  • Encryption in transit (TLS 1.2+) for all web and API traffic;
  • Encryption at rest via cloud provider infrastructure;
  • Role-based access controls and authenticated sessions;
  • Row-level security on user data in the database layer;
  • Uploaded source documents retained up to 30 days unless longer retention is required for active accounts or legal obligations;
  • Rate limiting and monitoring on public endpoints.

Your responsibilities

  • Determine whether a BAA with DAP is required for your use case;
  • Execute BAAs with DAP and applicable subprocessors before uploading PHI;
  • Use minimum necessary PHI — redact or de-identify when full identifiers are not required;
  • Review all generated letters before submission to payers;
  • Maintain your own workforce training and access policies.

Contact

BAA requests and HIPAA questions: baa@denialappealpro.com

See also our Privacy Policy.