How ClaimworksIQ handles protected health information: the role we play, the safeguards we apply, and the things we will never do with the records you entrust to us. Effective May 26, 2026.
ClaimworksIQ is a Business Associate under HIPAA, not a Covered Entity. We don't have a direct treatment, payment, or healthcare-operations relationship with patients. We process protected health information ("PHI") on behalf of attorneys, physicians, and the practices and firms that engage us, under a signed Business Associate Agreement.
This Notice describes, in plain English, how that processing works. It is a summary. The binding terms live in the BAA itself, in our Terms of Service, and in any signed customer agreement.
Depending on what you upload and what features you use, the Service may receive and process:
We use PHI only as necessary to deliver the Service to you and as expressly permitted by your BAA: intake and indexing of records, generating the outputs you request, supporting your users, securing the platform, and meeting legal obligations. We follow the principle of minimum necessary. Internal systems are scoped so that personnel can only access what is operationally required.
We apply administrative, physical, and technical safeguards consistent with the HIPAA Security Rule, including:
A more complete inventory of controls is on our security page.
To deliver the Service we rely on a small number of subprocessors: cloud infrastructure, AI inference, and authentication providers. Every subprocessor that may access PHI is bound by a downstream Business Associate Agreement with equivalent protections before any PHI is exchanged. A current categorical list is available to customers under NDA on request.
If we discover a breach of unsecured PHI as defined by HIPAA, we will notify the affected customer without unreasonable delay and within the timelines required by 45 CFR § 164.410, and typically much sooner. Our notice will include what was affected, what we know, what we've done, and what the customer needs in order to fulfill its own notification obligations to patients and regulators.
PHI is retained while your account is active and per the retention window configured for your environment. When you terminate, or when retention expires, PHI is returned or destroyed in accordance with the BAA. Backup expiration follows our documented retention policy, with the BAA's protections continuing to apply until backup data ages out.
If you are a patient whose records are being processed by ClaimworksIQ on behalf of your attorney, physician, or insurer, your HIPAA rights (to access your records, request amendments, request an accounting of disclosures, or file a complaint) are exercised through that Covered Entity, not directly with us. We will support that party in responding to your request. You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.
HIPAA, BAA, and PHI handling questions: privacy@claimworksiq.com.
Security disclosures and incident reports: security@claimworksiq.com.