01Who we are
BillingIQ is a claim recovery service operated by Radvix Solutions LLC ("Radvix", "we", "us"). This policy explains what we collect, what we deliberately refuse to collect, how long we keep it, and who else can touch it.
It covers billingiq.app, the customer portal, and the recovery work we perform for a practice. It does not change any Business Associate Agreement or services agreement we have signed with you — where this policy and a signed agreement disagree, the signed agreement wins.
02Our role under HIPAA
Your practice is the covered entity. We are your Business Associate. We execute a Business Associate Agreement before we are given access to any account or any claim data, and we use that data only to perform the recovery work you engaged us for, or as otherwise permitted by the BAA and required by law.
You remain the owner and the controller of your data. We process it on your instructions. We do not use it for our own purposes, we do not disclose it to anyone outside the subprocessors listed below, and we do not use it to build products for other customers.
Even without a name attached, a claim reference tied to a date of service and a procedure code can still be protected health information. We do not represent our data minimization as de-identification under 45 C.F.R. § 164.514. We treat everything in your account as PHI and apply HIPAA safeguards and the minimum necessary standard to all of it.
03The minimum necessary, and not one field more
A payer's appeals unit matches a submission on the patient's name, their member ID, and the date of service. Without those three, an appeal is returned unprocessed no matter how well argued it is. So we hold exactly those three, and we discard everything else at the point of ingestion — before anything reaches our database.
- We keep three identifiers. Patient name, member or subscriber ID, and date of service. These exist for one purpose: so the appeal we prepare can actually be processed by the payer. They are stored encrypted at rest and are visible only to your own practice's users and to the staff working your account.
- No identifier is ever sent to an AI model. When a letter is drafted, the model receives only the procedure codes, the denial reason, and the dollar amounts. The identifying block is assembled separately by our own code and merged into the document at print time. There is no path by which a patient identifier reaches a model provider.
- Everything else identifying is discarded. Dates of birth, Social Security numbers, addresses, phone numbers and email addresses are stripped at ingestion and never written to storage. Account and medical record numbers found in a patient field are replaced with a stable internal token.
- Pasted text is redacted. When your office pastes a payer letter or portal message into the portal, structured identifiers are redacted out of the text before it is stored or sent for drafting.
- Uploaded files are not retained. A remittance file or spreadsheet export is parsed in memory. We keep the fields the recovery engine needs and discard the file itself.
- We do not hold clinical records. No chart notes, no imaging, no diagnoses beyond the codes already on the claim. Where an appeal needs the operative note, your office attaches it to the filing directly — it never passes through us.
What we hold, then, is the billing skeleton of a claim plus the three fields a payer needs to find it: your practice's own claim reference, the payer, procedure and denial or remark codes, the state, service and submission and remittance dates, dollar amounts, the patient's name and member ID, and the recovery status our engine assigns.
An earlier version of BillingIQ pseudonymised the patient name and did not store a member ID at all. It protected privacy in a way we were proud of, and it produced letters that payers rejected on intake, which meant every office had to hand-complete each one. Holding three fields under a BAA is the honest trade: the appeal is filable, and the exposure is narrower than the practice management system the data already lives in.
04What we collect
- Claim and remittance data — the billing fields described above, either read from the clearinghouse access you grant us or parsed from a file your office uploads.
- Account data — the name, work email, role, and optional profile photo of each person you invite to your portal, plus which practices that person may see.
- Inquiry data — if you ask for a demo or a scan, the name, practice, work email, phone number, clearinghouse, and claim volume you choose to give us.
- Security and audit data — an activity log of who signed in, who uploaded what, who approved which appeal, and when. We also record request counts against an IP address to rate-limit our public forms against abuse.
We do not collect payment card data on this site. We do not buy data about you, and we do not enrich your record from third-party data brokers.
05How we use it
- To find denials, downcodes, underpayments, and unpaid claims in your remittance data and price what is recoverable.
- To draft appeals, reconsiderations, and status demands for your review and approval.
- To track appeal deadlines and payer responses, and to tell you what needs a decision.
- To operate your account: authentication, permissions, support, invoicing for recovered amounts.
- To keep the service secure and to meet our own legal, audit, and recordkeeping duties.
We do not sell personal information or PHI. We do not share it for cross-context behavioral advertising. We do not use your claim data to train, fine-tune, or improve any machine learning model, ours or anyone else's.
06Who else can touch it
We keep the vendor list deliberately short. Each provider below is bound by written terms, and where a provider may handle PHI we require a Business Associate Agreement or equivalent data protection commitments before it is used. All of them process data in the United States.
Where letter drafting is assisted by Anthropic, the model writes only the argument paragraphs and receives no identifier of any kind. Inputs are sent under commercial terms that prohibit training on them. If you would rather no third-party model be used at all, we can run your account on template-only drafting — ask us and we will turn it off.
We may also disclose data if the law compels it, to protect someone's safety, or to a successor in a merger or acquisition — in which case the successor inherits these commitments. We will tell you before your data moves for that reason unless we are legally barred from doing so.
07How we protect it
- Encryption in transit and at rest.
- Database-level isolation: every claim row is fenced to one practice, enforced by row-level security rather than by application code alone.
- Role-based access. Each person you invite sees only the practices you assign them.
- Access we hold on your clearinghouse is view-only where the payer or clearinghouse supports it, and you can revoke it at any time from your own account.
- An audit trail of access and actions, including when a Radvix administrator opens your portal to support you.
- Least-privilege internal access, limited to the people working your account.
- Rate limiting and request size limits on public endpoints.
08How long we keep it
- Claim records: for as long as your account is active, and afterwards only as long as needed to finish or document an appeal already in flight.
- On termination: at your written request we return or destroy the PHI we hold, on the timeline set in your BAA, and confirm when it is done.
- Audit and compliance logs: retained up to six years, which is the documentation period HIPAA requires of us.
- Inquiry data: kept while we are in contact and for a reasonable follow-up period, then deleted on request.
- Backups age out on our providers' standard cycles, so deletion may take a short period to propagate.
09If you are a patient
We have no direct relationship with patients. Where your provider has engaged us to recover a denied or underpaid claim, we may hold your name, your member ID, and the date of service on that claim, because a health plan will not process an appeal without them. We hold nothing clinical and nothing beyond what appears on the billing record.
If you have a question about your records, contact your provider — they are the covered entity, they hold your chart, and they control the request. We support them in responding to access, amendment, and accounting requests as our BAA requires.
10Your choices and rights
If you are a practice, your rights over your data are governed by your services agreement and BAA: you can export it, correct it, restrict our access, or require its return or destruction.
If you contacted us as an individual — a demo request, an inquiry, a portal login — you may ask us to give you a copy of what we hold about you, correct it, or delete it, and you may opt out of non-transactional email at any time. Depending on where you live, Florida and other state privacy laws may give you additional rights, including the right not to be discriminated against for exercising them. Write to privacy@billingiq.app and we will respond within the period the applicable law allows. We may need to verify who you are first.
12If something goes wrong
If we discover a breach of unsecured PHI, we notify the affected practice without unreasonable delay and no later than the deadline in our BAA and 45 C.F.R. § 164.410, with what we know about what happened, which records were involved, and what we are doing about it. You, as the covered entity, remain in control of any notice to patients or regulators, and we give you what you need to make it.
13Other disclosures
- United States only. Our providers store and process data in the US. We do not offer the service in the EU or UK and do not target it there.
- Not for children. The service is sold to healthcare businesses. We do not knowingly create accounts for anyone under 18.
- No automated decisions about people. Our engine scores claims, not patients, and every appeal goes out only after a person at your practice approves it.
14Changes to this policy
If we change this policy we update the effective date at the top, and for material changes we notify account holders by email or in the portal before the change takes effect. Continued use after that date means the updated policy applies.
15Contact us
Privacy questions, data requests, and HIPAA or BAA matters: privacy@billingiq.app. Legal notices: legal@billingiq.app.
Radvix Solutions LLC, operator of BillingIQ. See also our Terms of Service.