Skip to content

Trust center

Sensitive claim work deserves explicit boundaries.

ClaimParrot is designed around review-first AI, scoped records, and practical auditability. Security and compliance still depend on the providers, contracts, and controls configured for the production environment.

Do not upload PHI to a demo or preview environment. A signed BAA and eligible service plans are required before a medical-billing deployment handles PHI.

Human approval before delivery

Generated letters remain editable drafts. An authorized user must review the facts, confirm the deadline, and choose a delivery action.

Scoped document access

The application uses user- and organization-scoped records. Production storage is designed for private buckets and time-limited signed URLs.

Auditable AI activity

The data model supports AI audit records and PHI access logs so configured teams can inspect who accessed data and what generation occurred.

Telemetry scrubbing

Analytics and error-reporting helpers remove common patient, member, policy, claim, and credential fields before telemetry is sent.

Clinical decision boundary

ClaimParrot can route a behavioral-health denial and prepare review questions, but qualified staff must verify clinical findings, coding, medical necessity, and the final submission.

Criteria licensing boundary

The product may identify a criteria source named by the payer. It does not reproduce proprietary ASAM, MCG, InterQual, LOCUS, or payer criteria; organizations must use properly licensed source material.

Procurement checklist

Know what is product behavior and what requires configuration.

Ask for the actual provider list, service plans, BAAs, retention policy, access model, and incident process for the environment you intend to use.

AreaClaimParrot statusWhat to verify
AI outputDraft onlyHuman review and approval are required before sending.
StorageEnvironment dependentUse private Supabase buckets, signed URLs, and an appropriate retention policy.
EncryptionProvider managedEncryption in transit and at rest depends on the configured production providers and plan.
Audit recordsSupported in productAI audit and PHI access models are available; retention and export must be configured.
HIPAA / BAANot automaticPHI use requires eligible infrastructure and signed BAAs with every applicable business associate.
Delivery integrationsOptionalEmail, fax, mail, and SMS require separate provider accounts and production credentials.
Clinical and coding reviewHuman controlledQualified staff must verify medical-necessity, level-of-care, diagnosis, coding, criteria, and deadline conclusions.
HIPAA boundary

A BAA is a contract and infrastructure decision, not a badge in the UI.

HHS guidance says a cloud service provider that creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate is itself a business associate. Medical-billing buyers should verify signed BAAs and eligible plans with every applicable provider before PHI enters the system.

Access

Role checks must be enforced in every route and data query.

Retention

Define archival, export, and deletion windows before launch.

Review

Validate identifiers, facts, codes, deadlines, and attachments.

Contracts

Confirm provider eligibility and execute required BAAs.

Inspect the workflow before discussing deployment.

The sample denial lab uses fictional data and requires no account.

Inspect the workflow first.