Soft Appeals · The Trust Room

Everything your reviewers ask, before they ask.

This is the due-diligence center for Soft Appeals. It covers privacy and PHI handling, the Business Associate Agreement process, access and authentication, how information moves, technology and AI use, third-party services, incident response, retention and disposition, and how an engagement ends. It is written to be forwarded to whoever at your organization has to sign off.

Every item carries its real status. Where something is established, it says so. Where it is decided in the agreement, it says that instead. Where it is not settled yet, it says that too, and names what settles it. Nothing here is dressed up to look more finished than it is.

How to read the labels

Four statuses, and they mean exactly what they say.

  • DocumentedAn established practice. It is written down, it is followed, and it can be described in writing to your reviewers.
  • In the agreementDecided contractually for your engagement rather than declared on a web page. The executed agreements govern, not this page.
  • On requestExists and can be provided to a reviewer with a legitimate need, but is not published publicly.
  • Under reviewNot settled yet. The entry says what settles it, and Soft Appeals will tell you where it stands rather than implying it is finished.

A vendor page that shows only green ticks tells a reviewer nothing, because no early-stage vendor is finished on every axis. The useful version is the one that separates what is true now from what is still being decided.

Section one

Privacy and PHI handling.

The questions a privacy officer or compliance reviewer asks first.

Privacy

For compliance, privacy and legal
Will Soft Appeals execute a Business Associate Agreement before PHI is exchanged?Documented

Yes. Where the engagement requires one, the applicable Business Associate Agreement is executed before protected health information is exchanged. That sequence is not negotiable and it is not an afterthought: the complimentary review is deliberately structured so the business-level conversation happens first, with no patient information involved at all.

Soft Appeals can work from your organization's BAA. If your legal team requires its own form, that is the normal case and it is usually faster.

What information does Soft Appeals actually need?Documented

The minimum necessary for the denied claims assigned to Soft Appeals. In practice that is claim-level information for the specific denials in scope: the denial notice and reason, claim and payer information, the amounts, dates of service, and the supporting documentation a particular denial requires.

What is not required: unrestricted access to your EHR, your full patient database, administrator credentials, shared staff logins, unrelated clinical records, or every denial in your organization. The initial review starts with an agreed set of 20 claims and expands only where there is a reason.

How is minimum necessary applied in practice?Documented

Scope is agreed at claim level before information moves, so what arrives is what the assigned claims need rather than whatever an export happened to include. Patient identifiers are kept out of working materials that do not require them, and where a document can do its job without an identifier, it does.

Does any public form on this website collect PHI?Documented

No. No public form on this site accepts a file upload, and none asks for patient-level information. The two forms that take free text run a check that blocks a submission carrying a pattern that looks like patient information, and tells the person what it caught.

Patient-level information is requested only after the privacy documentation and an agreed secure intake process are in place, and that instruction comes as its own explicit step.

What happens to information when the engagement ends?In the agreement

Return or disposition of protected health information at termination, and the treatment of any permitted retained copies, are governed by the executed Business Associate Agreement and service agreement rather than by a statement on a web page. Access to any client system provided to Soft Appeals is removed when the work concludes.

Business records of the engagement itself, such as invoices and correspondence about scope, are a separate category from PHI and are treated as such.

Who is the privacy and security contact?Documented

Privacy, security and vendor-review correspondence goes to support@frimpomaasync.com, which reaches Nana Frimpongmaa directly. Use it for questionnaires, contractual questions, or anything your review process requires in writing.

Do not send patient information to that address. It is a business contact, not an approved channel for protected health information. The secure channel for claim information is established separately, after the agreements are in place.

Retention periods for each category of recordUnder review

Retention periods are being set alongside the executed agreements and the applicable requirements, rather than published as a number that later turns out to conflict with a client's own contractual obligations. Where your organization requires specific retention or disposition terms, raise them before the agreement is signed and they can be addressed in it directly.

Section two

Access, authentication and incidents.

The questions an IT or security reviewer asks.

Security

For IT and information security
Who can access client information?Documented

Soft Appeals is founder-operated. Access to client claim information is limited to the people performing the recovery work for that client, which today means a small, named set rather than a department. If that ever changes, the answer to this question changes with it and this page changes on the same day.

Access is scoped to the purpose it was granted for, requested rather than assumed, and removed when the work concludes.

What authentication is used?Documented

Individual credentials, never shared logins. Where a system supports multi-factor authentication, it is enabled. Where a system cannot support it, client information does not go in that system.

That is a statement about how accounts are configured. It is deliberately not a claim about encryption standards, key management or any other technical control belonging to a service provider, because those are that provider's controls to attest to, not Soft Appeals'.

How is information shared securely?Documented

Through an agreed channel established before anything is sent, so your team knows where information is going before it goes. Ordinary email and open chat tools are not the channel for patient information, and Soft Appeals will not ask you to use them for it.

If your organization prefers its own secure system, portal or transfer method, that is usually the better answer, and Soft Appeals will work inside it.

What happens if there is a security incident?In the agreement

An incident-response process is documented and can be provided to your reviewers. The specific notification obligations, including timing, are set in the executed Business Associate Agreement, decided with counsel, for your engagement.

No notification timeframe is published on this page on purpose. A number posted on a marketing page is a commitment a vendor can be measured against before anyone has confirmed it is the right one, and your organization may require something stricter than a generic figure.

Incident-response documentationOn request

Available to a reviewer with a legitimate need as part of the due-diligence process. Request it below and say who is asking, so the response is written for the right audience.

Cyber liability and errors-and-omissions coverageUnder review

Coverage is being arranged. Until a policy is in force, no coverage or limit is stated here, and no certificate is offered. If your procurement process requires specific coverage or limits as a condition of engagement, raise it before the agreement is signed. Discovering a hard insurance requirement after a BAA is executed wastes everyone's month.

Section three

How technology and AI are used.

Increasingly the first question a health system asks a vendor, and the one most vendors answer vaguely.

AI use statement

For compliance, IT and clinical leadership
Is AI used in the recovery work?Documented

Yes, and Soft Appeals says so plainly rather than burying it. Technology assists with administrative preparation: organizing claim information, drafting documents from the applicable payer requirements, and keeping records consistent. That is where its role ends.

What does technology never decide?Documented

It does not decide whether a claim is appealed. It does not make clinical, coding, coverage or legal determinations. It does not submit anything to a payer. Every recommendation is reviewed by a person, and every submission is prepared for client approval before it goes anywhere.

The Recovery Lab demonstrates the same principle publicly: recommendations are explained through factors a reviewer can check, and no probability score appears anywhere in the method.

Is client data used to train models?Documented

No. Client information is not provided for training public or general-purpose models, and services whose terms would permit that use are not used for client information.

Which tools are permitted for client information?Documented

Only approved services, under the appropriate agreements, may touch client claim information. Open consumer chat tools are not among them, and patient information is not pasted into one. Where a tool has not been through that assessment, it does not get used for client work.

Do you name the specific AI vendor?On request

Not in public material, which is a general practice across everything frimpomaasync.com publishes rather than an evasion specific to this. Vendors are named to a reviewer conducting due diligence, alongside what function each performs, whether PHI is involved, and what agreements are in place.

Section four

Where information goes.

The high-level data flow for a Soft Appeals engagement, from first contact to closure. Note where protected health information does and does not appear.

01
Business-level inquiry

An intake form asking about denial volume, payers, and how denials are handled today. No patient information, no attachments, no file field.

No PHI
02
Fit and scope conversation

Whether the service fits, which claims would be in scope, who owns what, and what your organization requires contractually. Still entirely business-level.

No PHI
03
Agreements executed

The applicable Business Associate Agreement and service agreement are put in place, along with any requirements your organization raises.

No PHI
04
Secure intake established

The agreed channel for claim information is set up and confirmed with your team before anything is sent.

No PHI
05
Claim information received

The agreed claims arrive through that channel, limited to the minimum necessary for the denials in scope.

PHI
06
Review and preparation

Claims are reviewed, recommendations are made and documented, and appeal or correction materials are prepared using approved services under the appropriate agreements.

PHI
07
Client approval

Completed materials are presented to your team. Nothing is submitted in your organization's name without approval.

PHI
08
Submission and tracking

Approved materials go to the payer through the applicable channel, with the submission documented, and the payer response tracked against the claim.

PHI
09
Reconciliation and closure

Recovered reimbursement is paid by the payer directly to your organization and reconciled against the claim. Access and information handling at closure follow the executed agreements.

PHI

Third parties and subcontractors

For vendor management and procurement
Does anyone else handle client information?On request

Service providers supporting the work are assessed against the same six questions before anything client-related touches them: what function it performs, whether PHI is involved, where information is processed, what contractual protections apply, whether it uses subcontractors of its own, and what happens to information when the relationship ends.

The list of services that touch client claim information, and what is in place with each, is provided to a reviewer conducting due diligence rather than published. Request it below.

Is any of this work performed outside the United States?On request

Processing locations for the services involved are covered in the vendor disclosure provided during due diligence. Where your organization has a data-residency requirement, raise it before the agreement is signed so it can be addressed rather than discovered.

Section five

Controls inside the work itself.

The questions a billing lead or revenue-cycle director asks, which are usually about control rather than about security.

Operations

For billing, revenue cycle and leadership
Can anything be submitted in our name without our approval?Documented

No. Client approval before submission is a standing control, not a courtesy extended to careful clients. Prepared materials are presented in final form for approval, and your team can approve, request changes, or decline.

Where does recovered money go?Documented

The payer pays your organization directly. Soft Appeals does not receive, hold or route your reimbursement at any point.

Who owns the next action on a claim at any moment?Documented

Exactly one party, and it is recorded. Every claim in an engagement carries a status, an owner and a next action, so the question of where something sits has one answer rather than a conversation. The Recovery Lab shows this working on fictional claims.

Does this replace or interfere with our billing team?Documented

No. Your billing operation keeps the revenue cycle. Soft Appeals works the denied claims assigned to it, and where a claim needs something only your team can provide, that request is recorded against the claim with a named person rather than left in an inbox.

If a billing company currently owns your denial workflow, the appropriate representative can be brought into the process. Clear roles prevent two people working the same appeal.

How does an engagement end?In the agreement

Termination rights and notice are set in the service agreement, and information handling at termination follows the executed agreements. Work in progress at termination, and what happens to claims already submitted, are addressed there rather than left to be worked out at the time.

What happens to work already done if we stop?In the agreement

The assessment you receive is yours regardless of whether you continue, including after a complimentary review that leads to nothing. Treatment of in-flight recovery work is set in the agreement.

Section six

What Soft Appeals does not claim.

This section exists because a reviewer's real job is finding the overstatement, and it is faster for everyone if it is already listed.

Not claimed, not held, not implied

Soft Appeals will not represent a certification, audit result, security standard, insurance policy, technical control, testing regime or other credential as existing unless it actually applies to the Soft Appeals environment and can be supported. That includes the badges a vendor page is expected to wear:

HIPAA certified SOC 2 HITRUST Penetration tested Encryption specifications Uptime guarantees Cyber insurance limits

Two of those deserve a note rather than a line through them. There is no such thing as HIPAA certification, so any vendor displaying that badge is telling you something about their diligence before you read a word of their policy. And a technical control belonging to a service provider in the stack is that provider's control to attest to. Borrowing it to describe your own business is the most common way a small vendor overstates its security posture.

If your organization requires a particular certification, contractual provision, insurance level, security control or procurement step as a condition of engagement, ask now. Fit should be established before protected information enters the workflow.

Section seven

Request the documents.

Choose what your review needs. Each one opens the due-diligence request with that item already selected, so you are not filling in a form to explain which form you want. No patient information is requested, and the form accepts no attachments.

Requests are answered with what exists. Where something is under review, the answer says so and says what settles it, rather than producing a document written to look like an answer.

If your process needs a written exchange instead of a form, the privacy and security contact is support@frimpomaasync.com. Send questions and questionnaires there, never patient information.

A serious vendor should expect serious questions

Ask before anything is sent.

If your compliance, privacy, IT, legal, procurement or billing team has a question this page does not answer, ask it now rather than after the agreements are signed. No patient information is needed for any of it.

This page describes general practices and is not legal advice. The obligations for any engagement are governed by the executed agreements, the agreed scope of work, your organization's requirements and applicable law. Soft Appeals is a service of frimpomaasync.com.