Privacy notice
How ApprovalHelp handles information
Effective 28 August 2026 · Policy version 2026-08-28.1
This product-specific notice describes current information flows and boundaries. A practice agreement, BAA, jurisdiction, and documented legal hold may create additional obligations.
Scope and roles
This notice covers ApprovalHelp, the payer-work product operated by DenialHelp, LLC. A practice ordinarily determines why and how patient information is used; ApprovalHelp processes that information for the practice under the applicable services agreement and Business Associate Agreement. Direct product, support, security, and billing interactions may make DenialHelp, LLC the controller or responsible business for limited account information.
Information handled
The service may handle professional account and organization details, patient and insurance identifiers, coverage facts, prior-authorization and denial records, clinical evidence supplied for payer review, documents, tasks, deadlines, communications, access events, outcomes, billing identifiers, and device/session security metadata. Payment-card details are collected by the payment processor; the application forbids clinical information in billing metadata.
Purposes
Information is used to authenticate users; create, review, submit, and track payer work; coordinate authorized team members; maintain evidence and audit history; secure, support, and improve the service; meet contractual and legal duties; and generate aggregate, de-identified operational measures. ApprovalHelp does not sell patient information or use raw PHI to train general-purpose models.
Access and sharing
Access is tenant-scoped and role-based. A patient-to-practice handoff requires an explicit, recorded grant and can be revoked without erasing historical audit evidence. Vendors receive only the data classes approved for their reviewed service. Legal disclosures are limited to valid obligations and documented incident or safety needs.
AI-assisted work
AI output is a draft for qualified review. Each AI route has a provider, model, data-class, contract, retention/training, and failure policy. Raw PHI is refused when the approved processing or de-identification path is unavailable.
Security and incidents
The service uses encrypted storage, TLS, bounded sessions, mandatory multi-factor authentication, tenant and capability checks, same-origin protections, audit evidence, legal holds, backups, and incident runbooks. No system is risk-free; suspected privacy or security events are assessed under the applicable notification duties.
Individual rights and practice requests
Requests to access, correct, restrict, export, account for, or delete patient information are normally coordinated through the treating practice, which controls the record. ApprovalHelp assists the practice and preserves records that must remain under law, contract, audit, security, or legal hold. Account users can review active sessions and revoke access from Security settings.
Vendors and subprocessors
Contract coverage is service-specific. The current public register is below; internal contract evidence is not exposed.
Amazon Web Services
Textract OCR, encrypted S3 backups, Lightsail TLS gateway
Permitted: public, internal, pii, phi, deidentified
Paubox Email API
transactional email
Permitted: public, internal, pii, phi, deidentified
Google Workspace
operator mailbox, administrative notifications
Permitted: public, internal, pii, phi, deidentified
Claude subscription CLI
AI inference after formal de-identification
Permitted: public, internal, deidentified
Anthropic API
non-PHI development and explicitly classified public/internal workloads
Permitted: public, internal, deidentified
Stripe
payment and subscription billing using PHI-free metadata
Permitted: public, internal, financial_non_phi
Cloudflare DNS
authoritative DNS only
Permitted: public
Sentry
PHI-scrubbed error and performance telemetry
Permitted: public, internal
Telegram Bot API
aggregate PHI-free operational alerts
Permitted: public, internal
Stedi Healthcare Eligibility
X12 270/271 eligibility checks
Permitted: public, internal
Google Analytics / PostHog
aggregate public-site analytics only
Permitted: public
Retention and deletion
Schedule 2026-08-28.1. ApprovalHelp does not apply one blanket period to every record. Unapproved clinical destruction remains paused, and legal holds override every destructive action.
Anonymous denial uploads and derived prefill cache
24 hours active, then encrypted archive pending case linkage or deletion review
Hardship applications, denial evidence, and financial-need narrative
Current 30-day deadline is an interim minimization control; destructive disposition requires privacy and legal approval
Case, clinical evidence, documents, communications, and filed artifacts
Jurisdiction-, role-, contract-, and legal-hold-specific; existing seven-year deadlines are interim and require review
HIPAA-required policies, procedures, assessments, and approvals
6 years
Access, security, and AI-handling audit evidence
6 years unless a longer legal hold applies
PHI-free billing events and reconciliation evidence
Finance/tax policy; jurisdictional review required
Contact and complaints
Do not include patient information in an initial email. Contact privacy@denialhelp.com or use the practice support channel and request the Privacy Officer. You may also complain to the relevant regulator; doing so will not affect your access to care.