The short version
We only collect what we need to audit your medical bill and help you dispute it. We don't sell your data, we don't share it for cross-context behavioral advertising, we don't use it to train third-party AI models, and you can delete your account and bills at any time.
1. HIPAA status
Patient Bill is not a healthcare provider, health plan, or healthcare clearinghouse, so we are not a HIPAA "covered entity."When you retain us to negotiate a bill, you appoint us as your authorized personal representative and sign a HIPAA authorization that lets your provider and insurer release your protected health information (PHI) to us. PHI flows from those providers to us under your authorization, and we use it solely to perform the Service.
We are not a "business associate" of your provider or insurer unless we sign a separate Business Associate Agreement with that entity. Your HIPAA rights (access, amendment, accounting of disclosures, etc.) run against your providers and insurers, not against us; we will, however, honor the access, correction, and deletion rights described below for the data we hold.
2. Categories of personal information we collect
Information you give us
- Identifiers: name, email address, password, phone number, postal address.
- Health information (sensitive PI): the bills, EOBs, itemized statements, medical records, diagnoses, procedure codes, dates of service, providers, and insurance details you upload or enter.
- Patient details for non-self cases: name, date of birth, and contact info of the patient on the bill if that person is not you.
- Payment information: processed by our payment processor (Stripe); we receive limited tokens and metadata, not full card numbers.
- Signature data: typed and drawn signatures, plus the timestamp, IP address, and user-agent captured at signing.
- Support correspondence: messages you send us.
Information collected automatically
- Usage data: pages visited, features used, and rough timing — used to fix bugs and improve the product.
- Device and log data: browser type, operating system, IP address, and security logs.
- Cookies and similar technologies: see Section 11.
3. Sources, purposes, and recipients
The table below summarizes the categories of personal information we collect, where they come from, why we use them, and the categories of recipients we may share them with.
| Category | Source | Business purpose | Recipients |
|---|---|---|---|
| Identifiers, account info | You | Create and secure your account; communicate with you | Hosting, email, error-monitoring vendors |
| Health information / sensitive PI | You, and providers/insurers under your HIPAA authorization | Audit the bill; draft and send dispute letters; negotiate on your behalf | AI sub-processor, mail vendor (Lob), providers and insurers you direct us to contact |
| Payment information | You, via Stripe | Bill our contingency fee on documented savings | Stripe |
| Usage, device, log data | Automatic | Security, fraud prevention, debugging, product improvement | Hosting, analytics, error-monitoring vendors |
| Signature data | You | Evidence of consent for the HIPAA authorization and Service Agreement | Hosting; providers and insurers when we present the authorization |
4. Sensitive personal information
Health information about you, and any non-self patient you authorize, is "sensitive personal information" under the California Consumer Privacy Act (as amended by the CPRA) and similar laws. We use it only to provide the Service you requested (and the supporting purposes listed in Section 3 above). We do not use sensitive PI to infer characteristics about you and do not use it for any purpose that triggers the right-to-limit under CPRA § 1798.121.
5. Legal bases for processing (users outside the US)
Patient Bill is intended for users in the United States. If you access the Service from outside the US, your information will be transferred to, stored, and processed in the United States. Where the EU/UK GDPR or similar laws apply, we rely on the following legal bases: contract(to provide the Service you requested), consent (for the HIPAA authorization, marketing texts, and non-essential cookies), legitimate interests (security, fraud prevention, product improvement, and direct service correspondence), and legal obligation (tax, recordkeeping, and responding to lawful requests).
6. What we don't do
- We don't sell or rent your personal information for money.
- We don't "share" your personal information for cross-context behavioral advertising (as those terms are defined under California law).
- We don't share your bills with advertisers.
- We don't use your bills to train third-party AI models. Our AI sub-processor is contractually prohibited from training on your content.
We have not sold or shared personal information for cross-context behavioral advertising in the prior 12 months, and we have no actual knowledge of selling or sharing the personal information of consumers under 16.
7. California privacy rights (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, and (if applicable) sell or share.
- Access a copy of your personal information in a portable format.
- Correct inaccurate personal information we maintain about you.
- Delete personal information we collected from you, subject to legal exceptions.
- Opt out of sale or sharing — we do not sell or share, but you may still submit a request.
- Limit the use of sensitive PI to the purposes identified in Section 4 above.
- Non-discrimination for exercising any of these rights.
Submit a request by emailing hello@patientbill.orgfrom the address on your account, or by writing to the postal address in Section 16. We will verify your identity using information already associated with your account. You may use an authorized agent; we will require written permission and may verify your identity directly. We will respond within 45 days (extendable by another 45 days where allowed). We honor the Global Privacy Control (GPC) signal as an opt-out preference signal where required.
8. Other US state privacy rights
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have similar rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising, sale, and certain profiling. We do not engage in targeted advertising, sale, or profiling that produces legal or similarly significant effects. To exercise these rights, contact us at hello@patientbill.org. You may appeal a denial by replying to our response.
9. Security
We use commercially reasonable technical, administrative, and physical safeguards designed to protect personal information, including encryption in transit (TLS) and at rest, role-based access controls and least-privilege permissions for employees, secure managed-hosting infrastructure, regular backups, and vendor due-diligence on our sub-processors. No system is perfectly secure; we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and applicable regulators as required by law.
10. Data retention
We keep personal information only as long as needed for the purposes described in this policy:
- Account information: while your account is active, plus up to 12 months after deletion to handle disputes and legal obligations.
- Case files (bills, EOBs, records, audit results): for the life of the case plus 7 years to support our records and applicable statutes of limitations.
- Mailed letters: rendered PDFs and mail-vendor metadata are retained for 7 years.
- Payment records and invoices: 7 years for tax and accounting purposes.
- Security and access logs: typically 12–24 months.
- Anonymous draft bills that are never claimed are cleaned up automatically after a short window.
- Backups: deleted records may persist in encrypted backups for up to 90 days before being overwritten.
11. Cookies and tracking technologies
We use a small number of first-party cookies and local-storage entries for authentication, session management, and remembering your preferences. We use limited analytics and error-monitoring tooling to understand how the Service is used and to diagnose problems; these may set first-party or third-party cookies. We do not use advertising cookies, retargeting pixels, or cross-site tracking. You can block or delete cookies via your browser settings, and we honor the Global Privacy Control (GPC) signal where required by law.
12. Sub-processors and service providers
We share personal information with vendors who help us run the Service under written contracts that restrict their use of the data to providing their service to us. Current categories include:
- Cloud hosting and database — to run the application and store your data.
- Payment processor (Stripe) — to collect contingency fees.
- Mail vendor (Lob) — to print and mail dispute letters via USPS.
- AI provider — to extract line items from uploaded bills and draft letters, under terms that prohibit training on your content.
- Transactional email provider — to send account, signature, and case-update emails.
- Error monitoring and analytics — to detect crashes and improve reliability.
We may also disclose personal information to professional advisors and to comply with law, respond to lawful requests, enforce our Terms, or protect our or others' rights. In a merger, acquisition, financing, or sale of assets, information may be transferred to a successor under equivalent protections.
13. Marketing communications
We send transactional messages (audit results, signature reminders, case updates, invoices) for as long as your account or case is active; you cannot opt out of these while the engagement is active. Any non-essential marketing email includes an unsubscribe link; you can also opt out by emailing hello@patientbill.org.
14. Automated decision-making
Audit results and recommended dispute letters are generated with the help of AI and other automated tooling. These outputs do not produce legal or similarly significant effects on you without human review — every letter is reviewed and approved (by you and, where applicable, by us) before it is sent, and you can request a human review of any audit by emailing hello@patientbill.org.
15. Account deletion
To delete your account, email hello@patientbill.orgfrom the address on your account. We will confirm the request, delete your account and active case data within 30 days, and overwrite remaining copies from backups within 90 days. We may retain limited records where required by law (for example, tax and payment records) or to enforce our Terms.
16. Children's privacy
Patient Bill is not intended for, and we do not knowingly collect personal information from, children under 13. A parent or guardian may use the Service to dispute a bill issued for a minor child; in that case the adult is the account holder, signs all authorizations, and is responsible for the account. If we learn that we have collected personal information from a child under 13 without a parent's consent, we will delete it. Parents or guardians may contact us at hello@patientbill.orgto review or request deletion of a child's information.
17. International data transfers
Personal information is processed and stored in the United States. By using the Service, you understand that your information may be transferred to and processed in a country whose data-protection laws may differ from those of your country of residence.
18. Changes to this policy
If we make material changes, we'll update the "Last updated" date above and, where appropriate, email you or post an in-product notice at least 14 days before the change takes effect (or sooner if required by law). Continued use after a change means you accept the updated policy.
19. Contact
Questions, requests, or complaints about privacy:
Patient Bill, Inc. — Privacy
2261 Market St #4501
San Francisco, CA 94114
Email: hello@patientbill.org
California residents may submit CCPA requests to the email address above; we maintain it as our designated CCPA request channel.
This page is provided for transparency, is a plain-language draft, has not been reviewed by counsel, and is not a substitute for legal advice. You are encouraged to consult an attorney before relying on it.