Human approval before delivery
Generated letters remain editable drafts. An authorized user must review the facts, confirm the deadline, and choose a delivery action.
Trust center
ClaimParrot is designed around review-first AI, scoped records, and practical auditability. Security and compliance still depend on the providers, contracts, and controls configured for the production environment.
Do not upload PHI to a demo or preview environment. A signed BAA and eligible service plans are required before a medical-billing deployment handles PHI.
Generated letters remain editable drafts. An authorized user must review the facts, confirm the deadline, and choose a delivery action.
The application uses user- and organization-scoped records. Production storage is designed for private buckets and time-limited signed URLs.
The data model supports AI audit records and PHI access logs so configured teams can inspect who accessed data and what generation occurred.
Analytics and error-reporting helpers remove common patient, member, policy, claim, and credential fields before telemetry is sent.
ClaimParrot can route a behavioral-health denial and prepare review questions, but qualified staff must verify clinical findings, coding, medical necessity, and the final submission.
The product may identify a criteria source named by the payer. It does not reproduce proprietary ASAM, MCG, InterQual, LOCUS, or payer criteria; organizations must use properly licensed source material.
Procurement checklist
Ask for the actual provider list, service plans, BAAs, retention policy, access model, and incident process for the environment you intend to use.
| Area | ClaimParrot status | What to verify |
|---|---|---|
| AI output | Draft only | Human review and approval are required before sending. |
| Storage | Environment dependent | Use private Supabase buckets, signed URLs, and an appropriate retention policy. |
| Encryption | Provider managed | Encryption in transit and at rest depends on the configured production providers and plan. |
| Audit records | Supported in product | AI audit and PHI access models are available; retention and export must be configured. |
| HIPAA / BAA | Not automatic | PHI use requires eligible infrastructure and signed BAAs with every applicable business associate. |
| Delivery integrations | Optional | Email, fax, mail, and SMS require separate provider accounts and production credentials. |
| Clinical and coding review | Human controlled | Qualified staff must verify medical-necessity, level-of-care, diagnosis, coding, criteria, and deadline conclusions. |
HHS guidance says a cloud service provider that creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate is itself a business associate. Medical-billing buyers should verify signed BAAs and eligible plans with every applicable provider before PHI enters the system.
Role checks must be enforced in every route and data query.
Define archival, export, and deletion windows before launch.
Validate identifiers, facts, codes, deadlines, and attachments.
Confirm provider eligibility and execute required BAAs.
The sample denial lab uses fictional data and requires no account.
Inspect the workflow first.