Trust
HIPAA & Security
How Claimo approaches sensitive ABA records, PHI minimization, access control, AI-assisted review, security operations, and customer responsibilities.
Last updated: August 23, 2026
These materials are provided for transparency and product governance. They are not a substitute for advice from your counsel, privacy officer, or compliance advisor.
1. Current security posture
Claimo is designed for sensitive ABA operational records, including claims, session notes, authorizations, payer rules, provider information, and related documentation. The platform is built to reduce unnecessary exposure of patient-identifying information, enforce workspace access controls, and maintain auditability around note QA, document processing, risk scoring, and review workflows.
Claimo describes its current safeguards transparently. Formal attestations, certifications, and customer-specific commitments are confirmed during contracting, and customers should rely only on representations made in a written agreement or in current documentation provided by Claimo.
Security and compliance are shared responsibilities. Claimo provides platform controls and safeguards; customers remain responsible for their own HIPAA compliance program, workforce training, minimum-necessary determinations, user access decisions, payer submissions, clinical documentation practices, and internal policies.
2. HIPAA role and contracting
When Claimo creates, receives, maintains, or transmits protected health information for or on behalf of a covered entity or business associate, Claimo expects to operate under appropriate written business associate or data protection terms. The application includes an electronic BAA acceptance workflow for onboarding where applicable, and any customer-specific terms must be reviewed and agreed before production PHI is submitted.
Claimo's public website, waitlist, demos, screenshots, and general email channels are not approved channels for PHI. Customers should not use Claimo to process production PHI unless the required contractual, security, and organizational approvals are in place.
Claimo does not provide legal advice and does not determine whether a customer is a covered entity, business associate, or subcontractor. Customers should consult counsel or privacy leadership to determine their HIPAA obligations and contracting requirements.
3. Data flow at a high level
A typical workflow starts when an authorized user uploads or imports a claim, note, authorization, treatment plan, or related document into the customer's workspace. Claimo stores operational metadata, extracts text or structured fields, applies PHI minimization where feasible, and runs ABA-specific analysis over the relevant billing, authorization, utilization, and documentation context.
Claimo then stores generated outputs such as extracted fields, note QA findings, risk flags, match statuses, Practice Risk Scores, entity risk scores, utilization summaries, review decisions, and audit events. Customer users review outputs in the dashboard and decide what, if any, action is appropriate.
Some workflows may preserve encrypted identity-linkage records so authorized users can reconcile pseudo IDs back to real clients when necessary. Reveals of sensitive identities are intended to be role-gated and audit-logged.
4. PHI minimization and AI review
Claimo is built around PHI minimization. Product workflows are intended to strip, tokenize, or avoid unnecessary patient-identifying information before AI-assisted review where feasible for the workflow. The purpose is to allow risk analysis of billing, authorization, and documentation patterns without exposing more patient information than necessary.
Downstream analysis prompts are designed around de-identified or tokenized text. Certain narrow preprocessing steps may need to inspect source text to identify client identity, classify documents, extract authorization context, or improve PHI stripping before downstream analysis. Those steps should be limited, server-side, and logged.
The standard document-processing pipeline is designed to extract scanned document text locally where feasible and to avoid sending raw uploaded document bytes to external vision APIs for transcription.
AI-assisted outputs are operational review aids. They do not create legal conclusions, clinical determinations, payer approvals, or audit guarantees. Customers are responsible for reviewing AI-assisted results before taking billing, clinical, compliance, or legal action.
Claimo does not intentionally use identifiable customer PHI to train general-purpose AI models. De-identified or aggregate information may be used to improve workflow quality, model evaluation, and product reliability when allowed by the applicable agreement and privacy terms.
5. Authentication and session controls
Claimo uses authenticated access for protected application areas. Password rules require strong passwords, and session controls are designed around inactivity timeouts, absolute session limits, secure cookies, and re-authentication for sensitive operations.
The platform includes infrastructure for multi-factor authentication and organization-level MFA enforcement. Customers should confirm the current MFA configuration for their workspace during onboarding or security review.
Users should use strong, unique credentials and should protect devices, browsers, password managers, and email accounts used to access Claimo. Suspected account compromise should be reported promptly to founders@tryclaimo.com.
6. Authorization, roles, and tenant isolation
Claimo is intended to support role-aware access to customer workspaces. Current roles include administrative and operational roles for organization owners, clinical leadership, billing workflows, and elevated platform administration.
Database access is designed around row-level security policies and organization scoping so users can access only records associated with organizations they are permitted to use. Server-side routes also perform authorization checks for sensitive workflows.
Claimo is currently a multi-tenant application. Dedicated per-customer storage, single-tenant deployment, and customer-managed encryption keys are available only where separately implemented and agreed in writing.
7. Encryption and transport security
Claimo is designed to protect data in transit using HTTPS/TLS and security headers such as HSTS, frame restrictions, content-type protections, referrer controls, permissions policies, and a content security policy.
Sensitive application fields are designed to use AES-256-GCM application-layer encryption with key version tracking and tenant-scoped key derivation. Cloud infrastructure also provides underlying encryption for database, storage, and backup layers.
Encryption reduces risk but does not remove the need for careful access control, logging, key management, secure administration, customer endpoint security, and contractual review for production PHI workflows.
8. Auditability and administrative controls
Claimo is intended to preserve operational context around document processing, extracted fields, risk scores, review activity, and user actions so teams can understand how outputs were produced and what records were involved.
Audit events are designed to capture security-relevant and workflow-relevant actions such as authentication events, document activity, PHI stripping events, identity reveals, review decisions, exports, administrative actions, and system changes. Audit metadata should avoid storing raw PHI.
Audit logs are designed as append-only operational records, with database protections intended to prevent ordinary update or delete operations. Certain maintenance or test-only tooling may exist for non-production reset workflows and should not be used for production audit-history deletion.
Audit logs and metadata are operational safeguards, not a substitute for a customer's legal record retention program. Customers remain responsible for deciding what records must be retained, amended, exported, or produced during payer, regulatory, or legal review.
9. Data lifecycle and retention design
Claimo's retention design distinguishes between raw uploaded files, de-identified analysis results, audit records, and de-identified training or evaluation examples. Raw files are intended to be kept only as long as needed for processing and short-term operational support.
The application includes a retention policy function designed to delete raw uploaded files from storage after analysis and a short retention period, currently targeting a 24-hour raw-file window for analyzed documents, while preserving de-identified analysis results, operational metadata, and audit trails for longer review and compliance needs.
Customer-specific retention, deletion, export, legal hold, and backup obligations should be confirmed in a written agreement before production use. Backup, audit, security, and archival records may persist where needed for continuity, security, auditability, or legal obligations.
10. Secure development and change management
Claimo's engineering practices are intended to include code review, dependency awareness, environment separation, least-privilege access, and controlled handling of production data. Specific controls may mature as the product moves through early access and broader release.
Security-sensitive changes, access changes, and data-handling changes should be reviewed with attention to patient privacy, auditability, and customer obligations. Customers with formal control-mapping, CI/CD, branch protection, change approval, or evidence requirements should request current documentation during contracting.
Formal third-party reports and attestations are shared, when available, under appropriate confidentiality terms. Customers should not assume a specific report is available unless Claimo provides current documentation.
11. Vendors and subprocessors
Claimo may use vendors for hosting, storage, authentication, email, security monitoring, analytics, AI infrastructure, and other operational needs. Vendors are evaluated based on their role, access to sensitive data, and security posture.
Where PHI is processed by a vendor acting as a subcontractor business associate, Claimo expects appropriate contractual protections to be in place before that vendor is used for the relevant production workflow. Current subprocessor documentation is provided during contracting.
Customers with subprocessor review, data residency, vendor risk, or approval requirements should request current documentation during contracting and before uploading production PHI.
12. Incident response
Claimo maintains procedures intended to identify, investigate, contain, and remediate security incidents. If an incident affects customer data, Claimo will provide notice consistent with applicable law and contractual obligations.
Incident handling may include triage, containment, access revocation, log review, customer communication, remediation, evidence preservation, and post-incident review. Notification timelines and breach-specific obligations should be defined in the applicable customer agreement and any required business associate terms.
Security reports should include a description of the issue, affected route or account if known, reproduction steps, and contact information for follow-up. Please do not include patient information in initial vulnerability reports unless specifically requested through a secure channel.
13. Customer responsibilities
Customers are responsible for workforce training, role assignment, user offboarding, endpoint security, internal access reviews, payer submissions, clinical documentation practices, legal holds, minimum-necessary determinations, and determining whether Claimo is appropriate for a given workflow.
Customers should review outputs against source documents before taking action. Claimo can help surface risk patterns, but it does not decide whether a service was medically necessary, whether a note is clinically adequate, or whether a payer will accept a claim.
Customers should not upload production PHI until they have completed their own vendor review, confirmed the approved workflow, configured appropriate users and roles, and completed any required contractual terms.
14. Frequently asked security questions
Is Claimo HIPAA compliant? Claimo is built with HIPAA-aligned technical safeguards, PHI-minimization controls, and BAA onboarding support, but HIPAA compliance depends on the full technical, administrative, physical, and contractual context. Claimo does not make a customer HIPAA compliant by itself.
Does every customer automatically have a BAA? No public page should be treated as a signed BAA. Where a production PHI workflow requires business associate terms, the applicable BAA or data protection terms must be completed through onboarding or another written process before PHI is submitted.
Is Claimo SOC 2 certified? A SOC 2 attestation is not part of Claimo's current representations. Any future report would be shared after completion and under appropriate confidentiality terms.
Does Claimo support SSO? Authentication is based on the platform's current auth stack and role-aware access controls. Enterprise SSO options are handled through written agreement where separately implemented.
How is customer data isolated? Claimo is designed as a multi-tenant application with organization scoping, row-level security, and role-aware access controls. Dedicated isolation options are handled through written agreement where separately implemented.
Does Claimo train AI models on identifiable PHI? Claimo does not intentionally use identifiable customer PHI to train general-purpose AI models. De-identified or aggregate information may be used for evaluation and product improvement when allowed by applicable terms.
15. Scope of representations
No software makes an organization HIPAA compliant by itself, and Claimo does not guarantee payer acceptance, audit immunity, legal compliance, clinical adequacy, claim payment, or the absence of all documentation risk. Claimo supports, and does not replace, counsel, compliance officers, billing specialists, and clinical supervisors.
The representations that apply to a customer relationship are those confirmed in a written agreement or in current documentation provided by Claimo, including any attestations, certifications, testing reports, isolation or key-management options, insurance details, subprocessor documentation, and Business Associate Agreements completed through contracting and onboarding.
16. Security contact
Security questions, vulnerability reports, vendor review requests, HIPAA contracting questions, or privacy questions may be sent to founders@tryclaimo.com.
