Soft Appeals · contact and vendor due diligence

Questions before you send a claim? Ask them first.

A healthcare organization should not have to hand over patient information to find out whether a vendor is appropriate. Use this page for questions about service fit, privacy and security, Business Associate Agreements, technology and AI, billing-team coordination, pricing, contracting, vendor review, procurement or the denial-recovery process itself.

No patient information on this page

Do not include protected health information in either form below, and do not attach claim documents. Neither form accepts a file.

If the service moves forward, the approved information-sharing process is established separately, and it will be obvious when that step arrives.

No upload field on either form Due-diligence questions welcome before any engagement No certification claimed that cannot be supported
Contact form

Tell us what you need.

Business information only. The first field routes your question, so it reaches the right answer instead of a general inbox.

Soft Appeals contact form

Which topics does your question cover?

Submitting this form begins a business-level conversation. It does not create a client engagement, authorize payer activity, or establish a channel for transmitting protected health information.

Vendor due diligence

Reviewing a vendor before information moves is the normal order of things.

Depending on the nature and stage of the proposed engagement, your organization may want to ask about any of the following. None of these questions are treated as an objection to get past.

01

Business Associate Agreement

How permitted PHI use and disclosure, safeguards, incident reporting, subcontractor responsibilities, termination and the other applicable obligations are addressed.

02

Data flow

How information would move from your organization into the Soft Appeals workflow, and through the recovery process.

03

Access model

What information is actually needed, whether any system access is required, and how unnecessary access is avoided.

04

Technology

Which kinds of technology support the workflow, and what part each one plays.

05

AI use

How AI or automation may assist administrative tasks, and what restrictions apply where PHI is involved.

06

Third-party services

Whether third parties or subcontractors may create, receive, maintain or transmit PHI as part of the workflow.

07

Retention and disposition

How information and access are handled once they are no longer required, and when an engagement ends.

08

Incident response

How suspected or known information-security events are identified, evaluated, documented, escalated and communicated under the applicable agreements and requirements.

09

Recovery workflow

How claims are reviewed, approved, submitted, tracked, reconciled and closed.

The published starting point for most of this is the data and security practices page. The request form below is for what that page does not answer for your organization specifically.

Request due-diligence information

What would your team like to review?

Tick what your organization needs, say who is asking, and add anything specific your process requires. Availability of any given document is confirmed during the review rather than assumed here.

Soft Appeals due-diligence request form

What would your team like to review?

A due-diligence request is a business-level conversation about the proposed relationship. It does not create an engagement or authorize any exchange of protected health information.

What to expect from due diligence

Review the process before the data.

Soft Appeals can address the questions your organization reasonably needs answered to evaluate the proposed relationship. They should be resolved before unnecessary patient information enters the workflow, which is the whole reason this page exists.

The seven the review has to settle
  • What work is being performed?
  • What information is actually required?
  • Where will that information go?
  • Who or what may access it?
  • What agreements apply?
  • What happens if something goes wrong?
  • What happens when the work ends?
What Soft Appeals will not do

Trust does not require overclaiming.

Soft Appeals will not represent a certification, audit result, security standard, insurance policy, technical control or other credential as existing unless it actually applies to the Soft Appeals environment and can be supported.

That includes the badges a vendor page is expected to wear:

HIPAA certified SOC 2 HITRUST Unverified technical claims

If your organization requires a particular certification, contractual provision, insurance level, security control or procurement step, ask before the engagement begins. Fit should be established before protected information is exchanged, and a vendor who discovers a hard requirement after the BAA is signed has wasted everyone's month.

PHI does not belong on this page

Keep patient information inside the approved intake workflow.

Neither form on this page accepts a file, and neither one should carry patient detail in its text. If the service moves forward, the appropriate information-sharing process is established separately.

Not through this page
  • Patient names
  • Dates of birth
  • Medical record numbers
  • Member or subscriber IDs
  • Claim attachments
  • Explanations of benefits carrying patient information
  • Remittance files carrying patient information
  • Clinical records
  • Denial letters carrying patient information
  • Screenshots carrying patient information
  • Patient-level spreadsheets
Billing companies and revenue-cycle partners

Already supporting the organization?

Soft Appeals does not need to cast an existing billing company as the problem to add denial-recovery capacity. With client authorization, the workflow can establish five things up front.

01

Which claims belong with Soft Appeals

Only the agreed denied claims enter the recovery scope.

02

Which actions stay with billing

Corrections, resubmissions, coding review and other existing responsibilities can stay exactly where they are.

03

What Soft Appeals needs from billing

Claim history, denial information, submission evidence or clarification, requested when a specific claim needs it.

04

Who owns the next action

Each active claim should have one visible next step and one accountable owner.

05

How outcomes come back

Recovery activity should return useful information to the organization rather than creating another disconnected workflow.

Billing partners are welcome to use this page to ask questions before a client authorizes any claim-level information exchange. Ask about billing coordination.

Procurement and contracting

Need the business details first? That is fine.

Some organizations need more review before recovery work can begin. Availability and applicability of any requested document or contractual provision is confirmed during due diligence, and Soft Appeals will not claim that a certification, policy, insurance limit, contractual term or document exists until it has been verified.

Questions this usually covers
  • service scope
  • pricing
  • Business Associate Agreement requirements
  • service agreement terms
  • invoicing
  • information-security requirements
  • insurance requirements
  • vendor registration
  • payment setup
  • tax documentation
  • subcontractor requirements
  • termination provisions
Questions for Soft Appeals

A serious vendor should expect serious questions.

These are the ones worth asking, listed here so nobody has to work out what they are allowed to ask. Many are already answered on the full questions page. Ask the rest directly.

  • What information will you need from us?
  • Do you need EHR access?
  • Will you sign a BAA?
  • Which services may handle PHI?
  • How is AI used?
  • Does client PHI train public AI models?
  • How do you handle subcontractors?
  • What happens if there is a security incident?
  • How is access removed after the engagement?
  • How is PHI returned or destroyed?
  • How will our billing company work with you?
  • Who approves payer submissions?
  • How do you verify a recovery?
  • What happens if a claim is already being appealed?
  • Which claims qualify for contingency pricing?
  • How do government-program claims differ?
  • What happens if we stop the engagement?
Already ready to start?

A due-diligence request is not a prerequisite.

If your next step is the complimentary assessment, go straight to the denial-review intake. You provide business-level information first. If the review looks appropriate, Soft Appeals establishes the privacy and secure-intake process before any patient-level claim information is exchanged.

Contact Soft Appeals

Start with the question that matters to your organization.

A recovery question, a security question, a billing question, a contracting question. Ask it. Patient information can wait until the appropriate process is established, and no answer on this page depends on seeing a single claim.