Trust & security
You're considering sending a stranger your patients' claims.
That deserves a straight answer rather than a badge. This page describes exactly what we do, what we don't do, and what we haven't done yet.
Standing
Paritas is a HIPAA Business Associate
Working your denials means handling protected health information on your behalf, which makes Paritas a Business Associate under HIPAA and puts us under the Privacy and Security Rules. That's not a courtesy posture — it carries direct legal obligations, and it's the basis of every commitment below.
An agreement is signed before any data moves, including for the free report. The Denial Leakage Report is a regulated data exchange, not a marketing giveaway, so a short evaluation agreement covering that specific exchange comes first. If you engage us, a full Business Associate Agreement governs the engagement.
The channel
One way in, and it isn't email
Denial data reaches us through a single encrypted upload link, issued to you after the evaluation agreement is signed. There is no second path.
On medical‑necessity appeals we do need the treatment documentation from the chart — diagnosis, treatment plan, session and progress notes. That documentation is a different thing from HIPAA "psychotherapy notes," and it's what the appeal is built from.
The question everyone asks
Are you running AI on our patient data?
Yes, in specific places, and here is exactly where and under what conditions. It's a fair question and it deserves more than reassurance.
Where automation is used
Reading and structuring denial files, sorting denials into categories, and preparing draft appeal correspondence. This is what makes it economical to fight a $150 claim at all — it's the reason we can work on contingency when doing it by hand doesn't pay.
Where it is deliberately not used
- Appeal deadlines. There is no AI anywhere in that path. Deadline tracking is plain, deterministic calendar logic that produces the same answer every time. A missed appeal window can never be reopened, and we won't put a probabilistic system anywhere near an irreversible loss.
- Clinical judgment. No model decides whether care was medically necessary, whether documentation is clinically sufficient, or which code should have been used. Those determinations are your clinician's and stay that way.
- Filing. Nothing is submitted to a payer by an automated process without a person approving it first.
The conditions on the data
Oversight
A person reads every appeal before it's filed
Every appeal and every report is reviewed and approved by a person before it leaves us. Nothing is auto‑submitted.
On medical‑necessity appeals there's a second step that we consider non‑negotiable: your licensed clinician reviews and attests the clinical statements before submission. We prepare the appeal and highlight every clinical assertion in it for that review. We are not clinicians and will never represent clinical judgment to a payer on your behalf.
Paritas provides administrative claim‑recovery support. Responsibility for clinical judgment, coding, documentation accuracy and representations to payers remains with your practice, and the services agreement says so plainly.
Money
We never touch your funds
Every recovery is paid by the payer directly to you, through your normal remittance. Paritas never receives, holds, or routes your money, and we don't operate a trust or escrow account, because we never have a reason to.
We invoice you after a recovery has reached you. We also never pursue balances from your patients — our work is with payers only.
Honesty
What we don't claim
Plenty of vendors imply more than they hold. Ours is a young firm, and here's the straight version:
- We do not hold SOC 2, HITRUST, or any third‑party security certification. No audit firm has examined our controls. If anyone tells you HIPAA itself involves a certification, they're mistaken — it doesn't.
- We can't show you client references or case studies yet. Paritas is new. The free report is deliberately the first thing we hand you, because demonstrated work is the only credential we can honestly offer up front.
- We don't guarantee outcomes. Some appeals fail. Recoverable figures in our report are conservative ranges with the methodology footnoted, never promises, and we'd rather understate than oversell.
- We can't recover a claim whose appeal window has closed. Those deadlines are absolute. It's why the report leads with what's expiring.
What we do have: a documented security posture, written policies, a completed risk assessment, signed agreements before any data moves, and a system built with the compliance constraints designed in rather than added afterward.
If something goes wrong
We maintain a written breach‑response plan. If PHI you sent us were ever improperly accessed or disclosed, we'd notify you without unreasonable delay and within the timeframes HIPAA requires, with the detail you'd need for your own obligations. Our BAA sets out those terms in full, and you'll have read it before anything moves.
Questions about any of this — including ones this page doesn't answer — go to stuart@paritaspartners.com. We'd rather answer a hard question before you send anything than after.
Still want to see the number?
Request the report and we'll send the evaluation agreement and secure upload link. Nothing moves before you've signed it.