Everything your reviewers ask, before they ask.
This is the due-diligence center for Soft Appeals. It covers privacy and PHI handling, the Business Associate Agreement process, access and authentication, how information moves, technology and AI use, third-party services, incident response, retention and disposition, and how an engagement ends. It is written to be forwarded to whoever at your organization has to sign off.
Every item carries its real status. Where something is established, it says so. Where it is decided in the agreement, it says that instead. Where it is not settled yet, it says that too, and names what settles it. Nothing here is dressed up to look more finished than it is.
Four statuses, and they mean exactly what they say.
- DocumentedAn established practice. It is written down, it is followed, and it can be described in writing to your reviewers.
- In the agreementDecided contractually for your engagement rather than declared on a web page. The executed agreements govern, not this page.
- On requestExists and can be provided to a reviewer with a legitimate need, but is not published publicly.
- Under reviewNot settled yet. The entry says what settles it, and Soft Appeals will tell you where it stands rather than implying it is finished.
A vendor page that shows only green ticks tells a reviewer nothing, because no early-stage vendor is finished on every axis. The useful version is the one that separates what is true now from what is still being decided.
Privacy and PHI handling.
The questions a privacy officer or compliance reviewer asks first.
Privacy
For compliance, privacy and legalYes. Where the engagement requires one, the applicable Business Associate Agreement is executed before protected health information is exchanged. That sequence is not negotiable and it is not an afterthought: the complimentary review is deliberately structured so the business-level conversation happens first, with no patient information involved at all.
Soft Appeals can work from your organization's BAA. If your legal team requires its own form, that is the normal case and it is usually faster.
The minimum necessary for the denied claims assigned to Soft Appeals. In practice that is claim-level information for the specific denials in scope: the denial notice and reason, claim and payer information, the amounts, dates of service, and the supporting documentation a particular denial requires.
What is not required: unrestricted access to your EHR, your full patient database, administrator credentials, shared staff logins, unrelated clinical records, or every denial in your organization. The initial review starts with an agreed set of 20 claims and expands only where there is a reason.
Scope is agreed at claim level before information moves, so what arrives is what the assigned claims need rather than whatever an export happened to include. Patient identifiers are kept out of working materials that do not require them, and where a document can do its job without an identifier, it does.
No. No public form on this site accepts a file upload, and none asks for patient-level information. The two forms that take free text run a check that blocks a submission carrying a pattern that looks like patient information, and tells the person what it caught.
Patient-level information is requested only after the privacy documentation and an agreed secure intake process are in place, and that instruction comes as its own explicit step.
Return or disposition of protected health information at termination, and the treatment of any permitted retained copies, are governed by the executed Business Associate Agreement and service agreement rather than by a statement on a web page. Access to any client system provided to Soft Appeals is removed when the work concludes.
Business records of the engagement itself, such as invoices and correspondence about scope, are a separate category from PHI and are treated as such.
Privacy, security and vendor-review correspondence goes to support@frimpomaasync.com, which reaches Nana Frimpongmaa directly. Use it for questionnaires, contractual questions, or anything your review process requires in writing.
Do not send patient information to that address. It is a business contact, not an approved channel for protected health information. The secure channel for claim information is established separately, after the agreements are in place.
Retention periods are being set alongside the executed agreements and the applicable requirements, rather than published as a number that later turns out to conflict with a client's own contractual obligations. Where your organization requires specific retention or disposition terms, raise them before the agreement is signed and they can be addressed in it directly.
Access, authentication and incidents.
The questions an IT or security reviewer asks.
Security
For IT and information securitySoft Appeals is founder-operated. Access to client claim information is limited to the people performing the recovery work for that client, which today means a small, named set rather than a department. If that ever changes, the answer to this question changes with it and this page changes on the same day.
Access is scoped to the purpose it was granted for, requested rather than assumed, and removed when the work concludes.
Individual credentials, never shared logins. Where a system supports multi-factor authentication, it is enabled. Where a system cannot support it, client information does not go in that system.
That is a statement about how accounts are configured. It is deliberately not a claim about encryption standards, key management or any other technical control belonging to a service provider, because those are that provider's controls to attest to, not Soft Appeals'.
Through an agreed channel established before anything is sent, so your team knows where information is going before it goes. Ordinary email and open chat tools are not the channel for patient information, and Soft Appeals will not ask you to use them for it.
If your organization prefers its own secure system, portal or transfer method, that is usually the better answer, and Soft Appeals will work inside it.
An incident-response process is documented and can be provided to your reviewers. The specific notification obligations, including timing, are set in the executed Business Associate Agreement, decided with counsel, for your engagement.
No notification timeframe is published on this page on purpose. A number posted on a marketing page is a commitment a vendor can be measured against before anyone has confirmed it is the right one, and your organization may require something stricter than a generic figure.
Available to a reviewer with a legitimate need as part of the due-diligence process. Request it below and say who is asking, so the response is written for the right audience.
Coverage is being arranged. Until a policy is in force, no coverage or limit is stated here, and no certificate is offered. If your procurement process requires specific coverage or limits as a condition of engagement, raise it before the agreement is signed. Discovering a hard insurance requirement after a BAA is executed wastes everyone's month.
How technology and AI are used.
Increasingly the first question a health system asks a vendor, and the one most vendors answer vaguely.
AI use statement
For compliance, IT and clinical leadershipYes, and Soft Appeals says so plainly rather than burying it. Technology assists with administrative preparation: organizing claim information, drafting documents from the applicable payer requirements, and keeping records consistent. That is where its role ends.
It does not decide whether a claim is appealed. It does not make clinical, coding, coverage or legal determinations. It does not submit anything to a payer. Every recommendation is reviewed by a person, and every submission is prepared for client approval before it goes anywhere.
The Recovery Lab demonstrates the same principle publicly: recommendations are explained through factors a reviewer can check, and no probability score appears anywhere in the method.
No. Client information is not provided for training public or general-purpose models, and services whose terms would permit that use are not used for client information.
Only approved services, under the appropriate agreements, may touch client claim information. Open consumer chat tools are not among them, and patient information is not pasted into one. Where a tool has not been through that assessment, it does not get used for client work.
Not in public material, which is a general practice across everything frimpomaasync.com publishes rather than an evasion specific to this. Vendors are named to a reviewer conducting due diligence, alongside what function each performs, whether PHI is involved, and what agreements are in place.
Where information goes.
The high-level data flow for a Soft Appeals engagement, from first contact to closure. Note where protected health information does and does not appear.
An intake form asking about denial volume, payers, and how denials are handled today. No patient information, no attachments, no file field.
No PHIWhether the service fits, which claims would be in scope, who owns what, and what your organization requires contractually. Still entirely business-level.
No PHIThe applicable Business Associate Agreement and service agreement are put in place, along with any requirements your organization raises.
No PHIThe agreed channel for claim information is set up and confirmed with your team before anything is sent.
No PHIThe agreed claims arrive through that channel, limited to the minimum necessary for the denials in scope.
PHIClaims are reviewed, recommendations are made and documented, and appeal or correction materials are prepared using approved services under the appropriate agreements.
PHICompleted materials are presented to your team. Nothing is submitted in your organization's name without approval.
PHIApproved materials go to the payer through the applicable channel, with the submission documented, and the payer response tracked against the claim.
PHIRecovered reimbursement is paid by the payer directly to your organization and reconciled against the claim. Access and information handling at closure follow the executed agreements.
PHIThird parties and subcontractors
For vendor management and procurementService providers supporting the work are assessed against the same six questions before anything client-related touches them: what function it performs, whether PHI is involved, where information is processed, what contractual protections apply, whether it uses subcontractors of its own, and what happens to information when the relationship ends.
The list of services that touch client claim information, and what is in place with each, is provided to a reviewer conducting due diligence rather than published. Request it below.
Processing locations for the services involved are covered in the vendor disclosure provided during due diligence. Where your organization has a data-residency requirement, raise it before the agreement is signed so it can be addressed rather than discovered.
Controls inside the work itself.
The questions a billing lead or revenue-cycle director asks, which are usually about control rather than about security.
Operations
For billing, revenue cycle and leadershipNo. Client approval before submission is a standing control, not a courtesy extended to careful clients. Prepared materials are presented in final form for approval, and your team can approve, request changes, or decline.
The payer pays your organization directly. Soft Appeals does not receive, hold or route your reimbursement at any point.
Exactly one party, and it is recorded. Every claim in an engagement carries a status, an owner and a next action, so the question of where something sits has one answer rather than a conversation. The Recovery Lab shows this working on fictional claims.
No. Your billing operation keeps the revenue cycle. Soft Appeals works the denied claims assigned to it, and where a claim needs something only your team can provide, that request is recorded against the claim with a named person rather than left in an inbox.
If a billing company currently owns your denial workflow, the appropriate representative can be brought into the process. Clear roles prevent two people working the same appeal.
Termination rights and notice are set in the service agreement, and information handling at termination follows the executed agreements. Work in progress at termination, and what happens to claims already submitted, are addressed there rather than left to be worked out at the time.
The assessment you receive is yours regardless of whether you continue, including after a complimentary review that leads to nothing. Treatment of in-flight recovery work is set in the agreement.
What Soft Appeals does not claim.
This section exists because a reviewer's real job is finding the overstatement, and it is faster for everyone if it is already listed.
Soft Appeals will not represent a certification, audit result, security standard, insurance policy, technical control, testing regime or other credential as existing unless it actually applies to the Soft Appeals environment and can be supported. That includes the badges a vendor page is expected to wear:
Two of those deserve a note rather than a line through them. There is no such thing as HIPAA certification, so any vendor displaying that badge is telling you something about their diligence before you read a word of their policy. And a technical control belonging to a service provider in the stack is that provider's control to attest to. Borrowing it to describe your own business is the most common way a small vendor overstates its security posture.
If your organization requires a particular certification, contractual provision, insurance level, security control or procurement step as a condition of engagement, ask now. Fit should be established before protected information enters the workflow.
Request the documents.
Choose what your review needs. Each one opens the due-diligence request with that item already selected, so you are not filling in a form to explain which form you want. No patient information is requested, and the form accepts no attachments.
What the agreement covers, how it is executed, and whether your own form can be used.
Request → Security questionnaire responseWritten answers for your reviewer, or responses against your organization's own questionnaire.
Request → Data-flow informationThe detailed version of the flow above, including where PHI does and does not appear.
Request → Access-control approachHow access is granted, scoped, authenticated and removed.
Request → AI use informationThe written AI use statement, including what technology never decides.
Request → Subcontractor informationThe services that touch client claim information and what is in place with each.
Request → Incident-response informationThe documented process, for a reviewer with a legitimate need.
Request → Retention and dispositionHow information is handled during and at the end of an engagement.
Request → Recovery workflowThe operational detail behind the workflow, for a billing or revenue-cycle reviewer.
Request → Service agreement and pricingEngagement terms, how a fee is calculated, and what falls outside the standard model.
Request →Requests are answered with what exists. Where something is under review, the answer says so and says what settles it, rather than producing a document written to look like an answer.
If your process needs a written exchange instead of a form, the privacy and security contact is support@frimpomaasync.com. Send questions and questionnaires there, never patient information.
Ask before anything is sent.
If your compliance, privacy, IT, legal, procurement or billing team has a question this page does not answer, ask it now rather than after the agreements are signed. No patient information is needed for any of it.
This page describes general practices and is not legal advice. The obligations for any engagement are governed by the executed agreements, the agreed scope of work, your organization's requirements and applicable law. Soft Appeals is a service of frimpomaasync.com.