Skip to content
Medical Billing tier

HIPAA-conscious infrastructure for denial teams.

ClaimParrot can support medical billing workflows that involve PHI only after the customer signs the required Business Associate Agreement and the deployment is configured on eligible infrastructure.

BAA process

Medical billing and enterprise customers must complete a ClaimParrot BAA before uploading PHI.

Supabase HIPAA support requires a Supabase Pro plan minimum with a signed Supabase BAA, and Vercel deployment settings must be reviewed before launch.

Operational safeguards
  • Medical billing PHI fields are designed to pass through application-level encryption before storage when production keys are configured.
  • PHI access logging records user, field, target record, action, and timestamp for supported billing workflows.
  • Sentry, PostHog, and Axiom telemetry are routed through scrubbers to reduce claim identifiers and PHI exposure.
  • Retention jobs are prepared to remove encrypted PHI payloads after the configured seven-year window.

Contracts first. Then PHI.