Privacy Policy
Last updated: June 7, 2026
Overview
Claima (“we,” “us,” or “our”) is a HIPAA-compliant medical billing platform operated by Claima, Inc. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use our service. We are committed to protecting both personal information and protected health information (PHI) in accordance with applicable law, including the Health Insurance Portability and Accountability Act (HIPAA).
HIPAA Compliance
Claima acts as a Business Associate to covered healthcare entities (practices and providers) under HIPAA. As such:
- We execute a Business Associate Agreement (BAA) with each covered entity customer.
- PHI is encrypted at rest (AES-256) and in transit (TLS 1.2+).
- Access to PHI is limited to authorized personnel on a need-to-know basis.
- We maintain audit logs of all PHI access and modifications.
- PHI is never used for advertising, sold, or shared with third parties except as required to provide our services or as permitted by HIPAA.
- We notify covered entities of any PHI breach within 60 days of discovery.
Information We Collect
Account Information
When you create an account, we collect your name, email address, and (for password-based accounts) a hashed password. We may also collect your organization name and contact information.
Practice and Clinical Data
To provide billing services, we process practice information (NPI, Tax ID, address), provider information, patient demographic and insurance information, clinical service records, and insurance claim data. This data constitutes PHI and is handled in accordance with HIPAA.
Usage Data
We automatically collect certain usage information such as IP addresses, browser type, pages viewed, and actions taken within the application. This data is used to improve our service and ensure security.
How We Use Your Information
- To provide, maintain, and improve our billing platform
- To process and submit insurance claims on your behalf
- To generate AI-powered billing insights and recommendations
- To send service-related notifications and billing statements
- To comply with legal obligations including HIPAA reporting requirements
- To detect and prevent fraud and security incidents
AI and Machine Learning
Claima uses AI models (including third-party AI APIs) to provide features such as claim code extraction, denial analysis, appeal letter drafting, and revenue insights. When processing PHI through AI systems:
- PHI is processed through HIPAA-compliant AI service providers under BAA.
- We do not use PHI to train general-purpose AI models.
- AI-generated outputs (appeal letters, insights) are reviewed and controlled by your practice.
Data Sharing and Disclosure
We share information only as follows:
- Insurance Payers: Claim data is transmitted to payers as necessary for billing.
- Clearinghouses: EDI claim data may be routed through certified HIPAA clearinghouses.
- Payment Processors: Payment data is handled by PCI-DSS compliant processors (Stripe).
- AI Service Providers: Select data is processed by AI providers under BAA.
- Legal Requirements: We may disclose information when required by law or valid legal process.
We do not sell personal information or PHI to any third party.
Data Retention
We retain PHI for a minimum of 6 years from the date of creation or the date it was last in effect, as required by HIPAA. Account information is retained for the duration of your account plus a reasonable period thereafter. You may request deletion of non-PHI account data at any time.
Security
We implement administrative, physical, and technical safeguards to protect your information, including:
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption for data at rest
- Multi-factor authentication support
- Role-based access controls
- Regular security assessments and penetration testing
- SOC 2 Type II compliance (in progress)
Your Rights
Depending on your location, you may have rights to access, correct, or delete your personal information. To exercise these rights, contact us at privacy@claima.io. Note that rights with respect to PHI are governed by HIPAA and may be addressed through your covered entity.
Contact Us
For privacy inquiries, HIPAA questions, or to request a BAA: