Soft Appeals · data and security practices

Before you send a single claim.

Denied-claim recovery can require access to protected health information. Privacy, access and data handling should be understood before the work begins, not after information has already been exchanged. Soft Appeals uses a defined process for receiving, accessing, using, sharing, retaining and disposing of the information associated with a client engagement. This page sets out that process.

BAA before PHI Minimum-necessary approach No routine EHR access for the initial review Defined technology workflow Client approval before submission Data-disposition process
The operating principles

Three principles guide every engagement.

01

Agreement before PHI.

Where Soft Appeals will act as a business associate, the applicable Business Associate Agreement is executed before protected health information is exchanged for the engagement. The agreement defines permitted uses and disclosures of PHI, applicable safeguards, incident-reporting responsibilities, subcontractor requirements, termination provisions and the other responsibilities between the parties.

02

Minimum necessary information.

Soft Appeals does not request broad access simply because information may be available. Requests are limited to what is reasonably needed for the assigned denial-recovery work. The complimentary denial review starts from claim and denial information you provide securely, rather than routine access to your EHR.

03

Defined systems and responsibilities.

Before work begins, the engagement establishes how information will be exchanged, who is authorized to access it, what systems may be used, and what happens to the information when the engagement ends. Security should not rest on assumptions, so the process is documented before PHI is exchanged.

Data minimization

Start with what is needed, not everything available.

A denial may sit inside a large patient record. The recovery task may need only part of it. Soft Appeals limits information requests to what the work being performed actually requires.

For an initial review, that may include payer and plan information relevant to the denial, claim and remittance information, the denial reason or payer correspondence, the amount denied, service information relevant to the claim, submission or acknowledgement information where relevant, and the documentation needed to determine or support the appropriate recovery pathway.

Anything further is requested when a specific claim or recovery step needs it, with the reason attached to the request.

What we may need, and what we do not ask for.

The second list matters as much as the first. A vendor that wants more than the work requires is telling you something about how it handles patient information.

What we may need

Claim-specific information.

  • Denial and remittance information
  • Claim information
  • Payer correspondence
  • Submission acknowledgements
  • Relevant authorization information
  • Relevant supporting documentation
  • Other claim-specific evidence where a recovery step requires it
What we do not ask for by default

Broad access to your organization.

  • Full EHR access
  • Your entire patient database
  • Unrelated clinical records
  • Shared staff passwords
  • Broad administrative access
  • PHI sent through casual communication channels
Secure intake

You know where information is going before it is sent.

Once the applicable agreements are in place, claim information is exchanged through the process established for the engagement. Clients should not send PHI through unapproved channels.

If information arrives through an unintended channel anyway, Soft Appeals follows the applicable internal handling and incident procedures rather than treating the transmission as routine.

Where it is practical and appropriate, Soft Appeals can work with the secure workflow your organization already uses, instead of duplicating information into another system. Any system access needed beyond the initial review is discussed and authorized separately.

Where information goes

The whole path, start to disposition.

One diagram instead of another paragraph about security. Two points on this path belong to your organization rather than to us, and both are marked.

Your organization

You decide which claims are in scope and what information is provided.

Approved secure process
Secure claim intake

Claim and denial information arrives through the method agreed for the engagement.

After the BAA is executed
Minimum-necessary review

Each claim is evaluated on the information available, and nothing broader is requested.

If more is needed, the specific document is requested from your team, with the reason and the deadline it affects. Access is not widened to avoid asking.
For claims selected for appeal
Appeal preparation

Payer requirements are researched and the appeal package is assembled from the available documentation.

Nothing proceeds without this step
Client review and approval

Your organization approves the materials before anything is submitted in your name.

Through the appropriate channel
Payer submission

Submission dates and the available delivery or acknowledgement evidence are recorded.

Until the claim resolves
Tracking and payer response

Responses, requests for more information, deadlines and next actions are tracked against the claim.

Payer pays your organization directly
Resolution and reconciliation

The outcome is reconciled against the applicable remittance documentation.

At the end of the engagement
Return, destroy or retain under the agreement

Where required and feasible, PHI is returned or destroyed. Access that is no longer needed is removed.

Access

Access should be limited, intentional and removable.

Access to client information is limited to the people and services required to perform the agreed work. Where credentials or system access are necessary, these controls apply.

01

Authorization comes first

Authorization is established before access is granted, not alongside it.

02

Scoped to the purpose

Access is limited to the agreed purpose rather than to whatever the credential happens to permit.

03

Individual credentials

Individual credentials are used where the system supports them, so activity is attributable to a person.

04

Authentication controls

Available authentication and access controls are enabled where they are supported and appropriate.

05

No shared logins

Credentials are not shared between unrelated users, in either direction.

06

Removal when finished

Access that is no longer required is removed rather than left dormant.

Soft Appeals does not require routine EHR access for the complimentary denial review. If additional access later becomes necessary, the scope and the purpose are discussed with you before anything is granted.

Information handling

Patient identifiers stay out of places that do not need them.

Soft Appeals avoids putting unnecessary patient identifiers into operational areas that do not require them. Where it is practical, internal references use claim identifiers or other limited references instead of patient names.

PHI does not belong in ordinary task titles, calendar entries, casual text messages, public collaboration spaces, or any other channel that has not been approved for the engagement.

The goal is straightforward: fewer unnecessary copies, less unnecessary access, less unnecessary exposure.

Technology and AI

Technology supports the work. It does not replace responsibility.

Soft Appeals may use technology to assist with administrative tasks: organizing claim information, researching payer requirements, managing workflow, identifying items needing follow-up, preparing draft appeal materials, and tracking recovery activity.

What it does not do

Decide, code, or submit.

Technology does not independently authorize an appeal, make a clinical determination, change coding, or submit a claim in your organization's name. Those sit with people, inside the approval process agreed for the engagement.

When PHI is involved

Approved services only.

PHI is not intentionally entered into consumer-facing AI accounts or general-purpose tools that have not been approved for the engagement. Where a third-party service creates, receives, maintains or transmits PHI as part of the workflow, it is evaluated for the role it performs and handled under the contractual and security requirements that apply to that relationship. Where a Business Associate Agreement or another legally required downstream agreement applies, it is established before the service is used for PHI.

Model training

Not used to train public models.

Soft Appeals does not intentionally use client PHI to train public or general-purpose AI models. Technology use involving client information stays subject to the restrictions established for the engagement.

Human review

A tool does not make the final call.

Technology can assist with research and preparation. Human responsibility stays in the workflow. Before an appeal is presented for submission, the available claim information, the denial basis, the supporting documentation, the payer requirements and the proposed appeal materials are reviewed.

Nothing is submitted in your name outside the approval and authorization process established for the engagement.

Anything requiring clinical, coding, legal or other professional judgment outside the Soft Appeals scope is returned or escalated to the appropriate person at your organization rather than decided here.

Third-party services

A vendor's vendor matters too.

Some technology and communication services are necessary to support denial-recovery work. When a third party will handle PHI on behalf of Soft Appeals, its role is evaluated before that workflow is used, and the appropriate contractual restrictions and safeguards are required where they apply.

01

What function does it perform?

Ask what the service is actually for in the workflow, rather than accepting a product name.

02

Is PHI involved?

Some services in a workflow never touch patient information. The ones that do are a different conversation.

03

Where is information processed?

Where the information is processed or maintained, and under whose control.

04

What contractual protections apply?

What is in writing between Soft Appeals and that service for the information it handles.

05

Are subcontractors involved?

Whether the service passes information to anyone further down the chain.

06

What happens at the end?

How information is handled when that service relationship ends.

Soft Appeals can provide information about the relevant service providers and data-handling relationships during your due diligence. You do not have to become a client to ask.

Administrative, technical and operational safeguards

Security is more than a password.

The information-handling process is built around safeguards appropriate to the information and the work involved. Depending on the system and the workflow, those may include measures such as these.

01

Access controls

Limit access to authorized users and approved functions.

02

Authentication

Individual credentials and additional authentication controls where they are supported and appropriate.

03

Secure transmission

Designated methods for exchanging information, rather than casual or unapproved channels.

04

Information minimization

Limit the PHI requested, copied and retained to what the engagement reasonably needs.

05

Access management

Add, change and remove access as roles and engagement requirements change.

06

Documented procedures

Written processes for information handling, incidents and termination, rather than informal practice.

If something goes wrong

Security incidents require a defined response.

No responsible organization should promise that an incident can never occur. The question worth asking is what happens if one does. If Soft Appeals becomes aware of an impermissible use or disclosure, a suspected compromise, a security incident or another event involving client information, the event is evaluated and handled under the applicable Business Associate Agreement, internal procedures and legal requirements.

01

Contain

Stop the issue from continuing before anything else happens.

02

Preserve

Keep the information needed to understand the event, rather than overwriting it.

03

Determine what happened

Establish the facts of the event before drawing conclusions from them.

04

Identify what was involved

Which information and which individuals were potentially affected.

05

Assess the extent

How far the event reached, on the evidence available.

06

Mitigate

Reduce further exposure where it can be reduced.

07

Document

Record the response, so it can be reviewed rather than recalled.

08

Inform and correct

Provide the required information to the client, and put corrective action in place where it is appropriate.

The applicable agreement establishes the notification responsibilities between Soft Appeals and the client, including any reporting timeframe. That belongs in the agreement your attorney reads, not in a sentence on a marketing page.

When the engagement ends

Access does not stay open because the work is finished.

When information or system access is no longer required, Soft Appeals follows the termination and data-disposition requirements in the applicable agreement. Where it is required and feasible, PHI is returned or destroyed. Where return or destruction is not feasible, the protections and limitations the agreement requires continue to apply for as long as the information is retained. Client-issued access that is no longer necessary should be revoked.

Records that may remain

Patient data and business records are not the same thing.

Some records need to remain for legitimate business, contractual, accounting, legal or documentation purposes. Soft Appeals separates ordinary business records from unnecessary patient-level information, and retention is addressed through the applicable agreements and internal record-management practice. Patient information is not kept for future marketing, model training or unrelated business use.

Client control

Your organization stays in control of the engagement.

Before recovery work begins, you and Soft Appeals establish which claims are in scope, what information may be provided, which communication and transfer methods will be used, who is authorized to give instructions, what approval is required before payer submission, what system access is authorized if any, and how access and information are handled at termination.

Before PHI moves

Raise your own requirements.

Your organization can bring security or workflow requirements into onboarding before any protected health information is exchanged. That is the point at which changing the process costs nothing.

Special categories

Some records need more.

Certain categories of health information carry requirements beyond the standard workflow. Where a claim involves information needing additional legal, contractual, privacy or security controls, Soft Appeals may request additional safeguards, change the process, or decline that claim from the standard engagement until the right requirements are in place. Scope is settled before that information is processed.

Your documents

Read the agreements first.

The Business Associate Agreement and the recovery agreement come to you as documents, to read on your own time and send to your own attorney. Nothing is signed in a meeting.

Before you hire any denial-recovery vendor

Ask these seven questions. Ask us too.

Every one of them is answered somewhere on this page. Use the list on whoever else you are considering.

01

Will you execute the appropriate Business Associate Agreement before PHI is exchanged?

The answer should be clear before any claim information is sent.

02

What information do you actually need?

A vendor should be able to explain why it needs each thing it is asking for.

03

Where will our information be stored or processed?

Ask about the systems involved in receiving, maintaining, transmitting and working with your information.

04

Who else may handle PHI?

Ask about the subcontractors and technology providers inside the workflow, not only the company you are signing with.

05

How is AI or automation used?

If technology touches PHI, ask what information it receives, what contractual protections apply, and whether your information is used for model training.

06

What happens if there is a security incident?

Ask who contacts you, what information you receive, and what the applicable agreement requires of them.

07

What happens to our information and access when the work ends?

Termination should be settled before the relationship starts, not negotiated while you are leaving.

Security FAQ

What compliance and IT teams ask first.

Q1

Do you need access to our EHR?

Not for the initial complimentary denial review, which starts from claim and denial information you provide securely. If later recovery work needs additional system access, the purpose and the scope are discussed and authorized before anything is granted.

Q2

Will Soft Appeals sign a Business Associate Agreement?

Where Soft Appeals is performing work that requires one, the applicable agreement is executed before PHI is exchanged for that engagement.

Q3

Can we use our own secure system?

Where it is practical, yes. The information-transfer and access process is established during onboarding, based on your workflow and what the engagement requires.

Q4

Do you use AI?

Technology assists with research, organization, workflow and preparing draft materials. It does not authorize submissions on its own and it does not replace human review. PHI is not intentionally entered into unapproved consumer AI accounts, and third-party services that handle PHI are subject to the requirements applicable to their role in the engagement.

Q5

Is our patient information used to train AI?

Soft Appeals does not intentionally use client PHI to train public or general-purpose AI models.

Q6

Who can access our information?

Access is limited to the individuals and services needed for the authorized work, subject to the controls and agreements that apply to the engagement.

Q7

What happens if additional records are needed?

Soft Appeals identifies what is required and why. You then provide that information through the designated process, rather than granting broader access to save a step.

Q8

What happens when we stop working together?

Access and information are handled under the termination provisions in the applicable agreements. Where it is required and feasible, PHI is returned or destroyed, and access that is no longer needed is removed.

Q9

Can our compliance or IT team ask more questions?

Yes. Security, privacy, technology and workflow questions can be worked through during due diligence, before any PHI is exchanged. If your organization runs its own vendor-security review, bring it.

About this page. This page describes general Soft Appeals data and security practices.

The specific obligations for a client engagement are governed by the applicable agreements, the scope of work, client requirements and applicable law. Where an agreement establishes a different or more specific requirement, the agreement controls.

Due diligence

Review the process before sending anything.

You do not need to send patient information to start the conversation. Ask about the Business Associate Agreement, the information requirements, the technology workflow, the access model or the data-disposition process first. The point is to work out whether the relationship is appropriate before protected information enters the workflow.