Draft — pending legal review

Security

How we protect the bills, documents, and personal details you trust us with.

Last updated: May 15, 2026

The short version

Your bills are encrypted in transit and at rest, only you (and the small number of engineers who run the service) can see them, and we keep what we collect to a minimum.

Encryption

  • In transit: every connection to patientbill.org uses TLS 1.2 or higher. We don't accept unencrypted requests.
  • At rest: uploaded bills and database records are stored on encrypted disks managed by our cloud provider.
  • Passwords: stored as salted hashes — even we can't read them.

Access controls

  • Only your account can view your bills and audits through the app.
  • Internal access is limited to engineers who need it to operate the service, gated behind single sign-on and two-factor authentication.
  • Production access is logged. We review the logs.

Where your data lives

Patient Bill runs on managed cloud infrastructure in the United States. Uploaded files are stored in private object storage. We do not back data up to personal devices or third-party systems outside our hosting provider.

Vendors we rely on

We use a small set of trusted vendors — hosting, database, transactional email, and an AI provider that helps extract line items from bills. Each vendor is bound by contract to use your data only to provide their service to us, and to follow industry-standard security practices.

Data minimization and retention

  • We ask for as little as we need to run the audit.
  • Anonymous draft bills that are never claimed are deleted automatically after a short window.
  • You can delete your account and all associated bills at any time by emailing hello@patientbill.org.

Monitoring and incident response

We monitor the service for unusual activity and keep audit logs of sensitive actions. If a security incident affects your data, we'll notify you within 72 hours of confirming the incident, along with what happened and what we're doing about it.

What we ask of you

  • Use a strong, unique password for your Patient Bill account.
  • Don't share your account or "return link" emails with anyone you don't trust.
  • Keep your devices and browser updated.
  • Tell us right away at hello@patientbill.org if you suspect your account has been accessed by someone else.

Reporting a vulnerability

If you've found a security issue, please email hello@patientbill.org with the details. Don't publicly disclose the issue until we've had a reasonable chance to fix it. We'll acknowledge your report within two business days and keep you posted on the fix.

HIPAA and our role as your authorized representative

Patient Bill is not a HIPAA-covered entity and is not a business associate of your provider or insurer. We act as your authorized personal representative for billing matters: during intake you sign a HIPAA authorization that lets your providers and insurers release records to us and discuss your account with us, strictly for the purpose of resolving the bill you asked us to negotiate.

  • The HIPAA authorization is limited to the specific provider(s), date(s) of service, and bill you tell us about.
  • You can revoke the authorization at any time in writing — that stops us from contacting the provider further, but cannot undo disclosures already made.
  • We never sell your protected health information and never use it for advertising.
  • We retain a copy of your signed Service Agreement and HIPAA authorization for as long as the case is open plus six years, then purge per record-retention policy.

Not a law firm

Patient Bill is not a law firm and does not provide legal advice. We cannot represent you in court, file appeals on your behalf with an administrative-law judge, or handle bankruptcy or garnishment proceedings. If your case crosses into one of those areas we will tell you and recommend a qualified consumer-law attorney.

This page is a plain-language draft of our security and authorization practices and has not been reviewed by counsel or an external auditor.