Paritas

Trust & security

You're considering sending a stranger your patients' claims.

That deserves a straight answer rather than a badge. This page describes exactly what we do, what we don't do, and what we haven't done yet.

Standing

Paritas is a HIPAA Business Associate

Working your denials means handling protected health information on your behalf, which makes Paritas a Business Associate under HIPAA and puts us under the Privacy and Security Rules. That's not a courtesy posture — it carries direct legal obligations, and it's the basis of every commitment below.

An agreement is signed before any data moves, including for the free report. The Denial Leakage Report is a regulated data exchange, not a marketing giveaway, so a short evaluation agreement covering that specific exchange comes first. If you engage us, a full Business Associate Agreement governs the engagement.

The channel

One way in, and it isn't email

Denial data reaches us through a single encrypted upload link, issued to you after the evaluation agreement is signed. There is no second path.

Please never email us patient files, and never enter patient information into a form on this website. The request form on this site collects your name, your practice and how to reach you — nothing more. If patient data arrives by email we'll ask you to delete it and resend properly, because an ordinary inbox is not a compliant channel and we won't pretend otherwise.
In transit
Encrypted in transit. Uploads use a single‑use link that expires; the storage location is not publicly reachable and is configured to refuse any unencrypted connection.
At rest
Encrypted at rest with keys we control, in private storage with public access blocked at every level.
Access
Least‑privilege access, scoped to the specific job being done, with no long‑lived credentials. Access to the file store is logged.
Retention
Files are deleted on a defined schedule, with an automatic deletion backstop. Deletion is real — the store is deliberately configured so that a deleted file leaves no recoverable copy behind. We can certify destruction on request.
Minimum necessary
We ask only for the billing and claim data needed to work the denial. We do not want, and do not ask for, more of the chart than that.
Excluded outright
We do not accept psychotherapy notes as HIPAA defines them — the separately kept process notes. We do not accept substance use disorder treatment records governed by 42 CFR Part 2. Both are excluded by written agreement, not just by practice.

On medical‑necessity appeals we do need the treatment documentation from the chart — diagnosis, treatment plan, session and progress notes. That documentation is a different thing from HIPAA "psychotherapy notes," and it's what the appeal is built from.

The question everyone asks

Are you running AI on our patient data?

Yes, in specific places, and here is exactly where and under what conditions. It's a fair question and it deserves more than reassurance.

Where automation is used

Reading and structuring denial files, sorting denials into categories, and preparing draft appeal correspondence. This is what makes it economical to fight a $150 claim at all — it's the reason we can work on contingency when doing it by hand doesn't pay.

Where it is deliberately not used

  • Appeal deadlines. There is no AI anywhere in that path. Deadline tracking is plain, deterministic calendar logic that produces the same answer every time. A missed appeal window can never be reopened, and we won't put a probabilistic system anywhere near an irreversible loss.
  • Clinical judgment. No model decides whether care was medically necessary, whether documentation is clinically sufficient, or which code should have been used. Those determinations are your clinician's and stay that way.
  • Filing. Nothing is submitted to a payer by an automated process without a person approving it first.

The conditions on the data

Where it runs
In a HIPAA‑eligible cloud environment, in a single US region, covered by a Business Associate Agreement with the cloud provider.
Training
Your data is not used to train any model. We use models configured so that inputs and outputs are not retained for training.
Who can see it
The model provider has no access to your data — no prompts, no outputs, no logs. The cloud provider is our only subprocessor with access, and it is named on the subcontractor schedule of our BAA.
Logging
We log system activity for audit purposes. We deliberately do not log the contents of model requests, because those contents would contain PHI.

Oversight

A person reads every appeal before it's filed

Every appeal and every report is reviewed and approved by a person before it leaves us. Nothing is auto‑submitted.

On medical‑necessity appeals there's a second step that we consider non‑negotiable: your licensed clinician reviews and attests the clinical statements before submission. We prepare the appeal and highlight every clinical assertion in it for that review. We are not clinicians and will never represent clinical judgment to a payer on your behalf.

Paritas provides administrative claim‑recovery support. Responsibility for clinical judgment, coding, documentation accuracy and representations to payers remains with your practice, and the services agreement says so plainly.

Money

We never touch your funds

Every recovery is paid by the payer directly to you, through your normal remittance. Paritas never receives, holds, or routes your money, and we don't operate a trust or escrow account, because we never have a reason to.

We invoice you after a recovery has reached you. We also never pursue balances from your patients — our work is with payers only.

Honesty

What we don't claim

Plenty of vendors imply more than they hold. Ours is a young firm, and here's the straight version:

  • We do not hold SOC 2, HITRUST, or any third‑party security certification. No audit firm has examined our controls. If anyone tells you HIPAA itself involves a certification, they're mistaken — it doesn't.
  • We can't show you client references or case studies yet. Paritas is new. The free report is deliberately the first thing we hand you, because demonstrated work is the only credential we can honestly offer up front.
  • We don't guarantee outcomes. Some appeals fail. Recoverable figures in our report are conservative ranges with the methodology footnoted, never promises, and we'd rather understate than oversell.
  • We can't recover a claim whose appeal window has closed. Those deadlines are absolute. It's why the report leads with what's expiring.

What we do have: a documented security posture, written policies, a completed risk assessment, signed agreements before any data moves, and a system built with the compliance constraints designed in rather than added afterward.

If something goes wrong

We maintain a written breach‑response plan. If PHI you sent us were ever improperly accessed or disclosed, we'd notify you without unreasonable delay and within the timeframes HIPAA requires, with the detail you'd need for your own obligations. Our BAA sets out those terms in full, and you'll have read it before anything moves.

Questions about any of this — including ones this page doesn't answer — go to stuart@paritaspartners.com. We'd rather answer a hard question before you send anything than after.

Still want to see the number?

Request the report and we'll send the evaluation agreement and secure upload link. Nothing moves before you've signed it.