Skip to main content

Security and HIPAA at ClaimsRevenue™

Your claims and insurance payment files contain your patients' protected health information (PHI). This page explains, in plain language, exactly how ClaimsRevenue protects that information and how our Business Associate Agreement works.

Security at a glance

  • A signed BAA with every practiceEvery practice signs our HIPAA Business Associate Agreement before it can use ClaimsRevenue.
  • Encrypted everywhereData is scrambled while it travels and while it is stored, so only our system can read it.
  • Two-step sign-in for everyoneEvery user must confirm a second step, such as a code or passkey, to sign in.
  • Only the right people see itEach user gets only the access their role needs, and practices can never see each other's data.
  • Every action is recordedAn audit trail records who did what and when, including any access by our support team.
  • Hosted in the United StatesClaimsRevenue runs in secure, professionally managed cloud data centers in the United States.

Our Business Associate Agreement (BAA)

HIPAA requires a written agreement between your practice and any company that handles PHI for you. That agreement is called a Business Associate Agreement, or BAA. It legally commits the company to protect your patients' information the way HIPAA requires.

At ClaimsRevenue, the BAA is part of signing up. No practice can use the platform without one.

How signing works

  1. During signup, the person creating your account reviews the BAA alongside our Terms, Privacy Policy, and Claims Validation Disclaimer.
  2. They check a box (never pre-checked) confirming they agree and that they are authorized to sign for the practice.
  3. They type their full name as an electronic signature, which is legally binding under the federal ESIGN Act.
  4. ClaimsRevenue countersigns, and your account is created in the same step. The agreement is in place before any patient data is uploaded.

For your records we store the exact version and text you accepted, the date and time, the signer's typed name, and the IP address and browser used.

Always available to you

  • You can view and download a PDF copy of the agreements you accepted at any time from your account settings (View my legal acceptances).
  • The current BAA is published at https://login.claimsrevenue.com/legal/baa.

What the BAA commits us to

  • Protecting PHI with the administrative, physical, and technical safeguards the HIPAA Security Rule requires.
  • Using only the minimum PHI necessary for the service.
  • Never selling PHI.
  • Requiring any subcontractor that handles PHI for us to agree in writing to protections at least as strong as ours.
  • Giving you a 30-day window to export your data if you leave, then returning or destroying PHI as the agreement describes.

The BAA is the controlling document. If anything on this page differs from it, the BAA governs.

Encryption: your data is scrambled in transit and in storage

Encryption scrambles data so that it is unreadable to anyone without the key. Even if someone intercepted it, they would see only meaningless characters.

While it travels

Every connection to ClaimsRevenue is encrypted, from your browser to our servers and between our own systems. Unencrypted connections are not allowed.

Technical summary: HTTPS with modern TLS encryption on every connection.

While it is stored

Application data is encrypted while stored on our infrastructure. The most sensitive items get a second, separate layer of encryption inside our database:

  • the original claim (837P) and payment (ERA/835) files, and claim submission records
  • your practice's Tax Identification Numbers (TINs)
  • the secrets behind every user's two-step sign-in

Technical summary: industry-standard AES-256 encryption.

Protecting every account

Most breaches start with a stolen password. ClaimsRevenue is built so a password alone is never enough.

  • Two-step sign-in is required for every user. After the password, users confirm with an authenticator app, a passkey, or a one-time code sent by email. Users can mark a personal device as trusted for a limited time, and that trust is cancelled whenever the password changes.
  • Strong passwords are required.
  • Automatic sign-out. Inactive sessions end automatically, and changing or resetting a password signs that account out everywhere.
  • Protection against guessing and bots. Repeated failed sign-in attempts are blocked, and sign-in and signup pages are protected against automated bots.
  • One person, one login. Every user must have their own account. Shared logins are not allowed, so every action can be traced to the person who took it.

Who can see your data

  • Your team, by role. Each user is an owner, admin, biller, or viewer, and sensitive abilities such as filing claims or managing billing are switched on per person.
  • Never another practice. Every request is checked against your practice, and requests for another practice's records are refused.
  • Our support team, only when needed and always on record. Support access to an account requires a specific staff permission and a single-use, short-lived link, and every action is recorded under the staff member's own name. Staff accounts have their own, stricter sign-in requirements.

A complete audit trail

ClaimsRevenue records important activity: who did it, when, from where, and what changed. This supports the accountability HIPAA expects and helps answer "who touched this record?"

Where your data lives

  • United States hosting. ClaimsRevenue runs in secure, professionally managed cloud data centers in the United States.
  • Network protection. Traffic passes through an enterprise security network that filters malicious traffic and bots, and the application is kept out of search engines.
  • Layered safeguards. ClaimsRevenue maintains administrative, physical, and technical safeguards designed to protect PHI, including access controls, authentication, encryption, audit controls, and backup protections as appropriate to the service.

How long we keep data, and how you leave

  • Raw files are purged automatically. The original claim and payment files are removed after 90 days. The organized claim and payment records you work with are kept under our records-retention policy.
  • Records retention. Practice, claim, and ERA records are generally kept for seven years under our records-retention policy.
  • Leaving is simple. If you cancel, you have 30 days to download a full export of your data.
  • We never sell your data, and never train AI on identifiable patient or claim information.

Your free claims analysis

If you send us an ERA (835) file for a free claims analysis, we delete that file after your review is complete.

Substance use disorder records (42 CFR Part 2)

42 CFR Part 2 is a federal law that gives extra protection to certain substance use disorder treatment records. ClaimsRevenue does not accept Part 2 records by default, and practices complete a Part 2 attestation at signup. If you are unsure whether your records are covered, before submitting them.

Security questions

How long does ClaimsRevenue™ retain claim and ERA data?

ClaimsRevenue™ generally retains applicable practice, claim, and ERA records for seven years under its records-retention policy, subject to legal, regulatory, contractual, backup, and legal-hold requirements. Account cancellation does not necessarily result in immediate deletion of retained records due to legal requirements.

More questions about security, HIPAA, or our BAA? (live support Monday–Friday, 9:00 AM – 8:00 PM Eastern Time.).

See ClaimsRevenue on your own data, safely

See what your own insurance payment and denial history reveals. Free, with no obligation.